Support Support PRONOTE
  • Delegate teacher and student authentication to the portal Entra ID (formerly Azure AD)

Users who log in to their web space must authenticate with a username and password. This step can be delegated to the single sign-on service built into Entra ID.

Case No. 1: User authentication has been delegated to the portal Entra ID (formerly Azure AD)

  1. From the panel PRONOTE.net of the console, click on the tab Delegate the authentication.
  2. You can enter several configurations per protocol, but only one is activatable. Click in the column Active to activate the protocol of the delegation to be used.
  3. In the table, tick the Webspaces concerned by the delegation.



  1. Publish the base.

Case No. 2: User authentication is not delegated to the portal Entra ID (formerly Azure AD)

Create an institutional application on the portal Entra ID 

  1. Access your Entra ID portal.
  2. Select Institution's applications > All the applications.
  3. Click on New application.
  4. Click on Create your own application.
  5. Give your app a name and choose Integrate another application that you can't find in the gallery (not gallery).
  6. In the pop-up window, choose Configure the unique authentication.
  7. Choose the protocol SAML.
  8. In part 3, SAM Certificates, copy the URL of metadata of the federation application.
  9. Go to the PRONOTE hosting console to recover the delegation information.

Delegate authentication to the Client via a SAML2 server

  1. From the panel PRONOTE.net of the console, click on the tab Delegate the authentication.
  2. On the line Protocol SAML2, click on the button Ajouter un protocole d'authentification to enter a new configuration.



  1. In the pop-up window, enter:
    • a name for the delegation configuration,
    • the SAML server URL recovered from the portal Entra ID in the previous step by pressing the key Enter don your keyboard (recovery of the configuration XML file).
  2. If you want users to also be able to access PRONOTE without going through the SAML server, tick Authorize direct authentication by PRONOTE ((without querying the Saml server). In this case, users will be able to log in with their PRONOTE username and password from the specified URL.



  1. Copy the PRONOTE.net URL for the SAML server and get the XML configuration file to use on the Entra ID portal.
  2. Click on the button Validate.
  3. In the table, tick the Webspaces concerned by the delegation.
  4. Click in the column Active to activate the protocol and publish the database.

Configure the institution's application on the Entra ID portal (formerly Azure AD)

  1. Go back to the unique authentication configuration in the Entra ID portal.
  2. Click on Load the metadata file and select the file configurationSaml.XML that you recovered in the previous step.
  3. In the pop-up window, click on Save.

Reconcile Entra ID (formerly Azure AD) users with PRONOTE users

  1. Go to the Entra ID portal Entra ID > Users.
  2. Click Download the users.
  3. Edit the *.csv file downloaded to replace commas with semicolons.
  4. Go to the display Communication > Identity management > Authentication delegation in Client PRONOTE.
  5. Select Saml in the top drop-down menu.
  6. Select the user category from the drop-down menu below.



  1. Click on the button Importer la liste to select the *.csv file recovered in the last step.
  2. In the pop-up window, click on Browse to identify the *.csv. file.
  3. Select Semicolon as a field separator.
  4. Reconcile the fields in the csv file with the fields available in PRONOTE Campus:
    • userPrincipalName corresponds to Identifiant Partenaire;
    • surname corresponds to Nom;
    • givenName corresponds to Prénom.
  5. Select at least the fields Nom and Identifiant Partenaire. The field Prénom is necessary in case of homonymy.
  6. Click on the button Import.
Was this content useful to you ?

Can't find an answer to your question ?

Contact our support

INDEX ÉDUCATION | © 2026 - B