- 
                Select Onboarding.
                
The
                        Welcome window displays.
             - 
                Select Secure Hybrid
                        Access [Secure Application
                        Access or Secure Network
                        Access].
                
The system displays the
                        Identity
                        Provider window with ExtremeCloud
                    Universal ZTNAselected.
             - 
                Select Next.
                
The Onboarding window displays.
             - 
                Select the Link to review the comprehensive
                    tutorial on creating a SAML-based SSO in Microsoft AD FS.
            
 - 
                Copy and paste the Identifier and
                        Reply
                        URL links in Entra ID as per instructions in the tutorial.
                
Entra ID creates a Login
                    URL and Microsoft AD FS Identifier. 
             - 
                Paste the Login URL and Microsoft AD FS
                        Identifier into their Universal ZTNA fields.
            
 - 
                Upload the SAML Signing
                        Certificate you downloaded from Entra ID
                
                     The UI instructions explain how to upload the certificate.
                 
             - Optional: 
                Select All Domains or Custom  and enter the
                    domain.
                
If you select Custom, fill in the
                    approved domains. Applicable for network and application access.
             - 
                Select Secure Network Access network.
            
 - 
                Select Update.
                
                    Update Identity
                        Provider
                    pop-up window displays. This message cautions you that the
                    Identity Provider change logs out current users.
             - 
                If you decide to continue,
                    select Confirm.
            
 - 
                Select Next.
                
The Onboarding - Access
                        Groups window displays.
             - 
                Configure Users and Devices.
            
 - 
                Configure Resources.
            
 - 
                Configure Applications and Application Groups.
                
 You can skip this step if you
                    are using Secure Network Access.
             - 
                Configure Policies.