Skip to main content
Question

SAML SSO – Erro de certificado de assinatura no Figma com Microsoft Entra ID

  • September 4, 2026
  • 1 reply
  • 8 views

Djalma Gabriel

Hello Figma Support Team, We need assistance with a SAML SSO configuration for one of our Figma Enterprise organizations. Our customer currently has two independent Figma Enterprise contracts/organizations. SAML SSO and SCIM are already configured and working correctly in the first organization. We recently configured SAML SSO and SCIM for the second Enterprise organization. For this second environment, we created a separate Enterprise Application in Microsoft Entra ID and configured it using the Tenant ID, Entity ID and ACS URL provided by Figma. However, when an existing Figma user attempts to authenticate by selecting "Use single sign-on (SSO)", the authentication fails with the following error: "The certificate configured in Figma does not match the IdP's signing certificate." Error details: HTTP Status: 422 Error ID: auth.error.saml_invalid_signature Message: The certificate configured in Figma does not match the IdP's signing certificate. The first Figma Enterprise organization continues to work normally with SAML SSO using its own Microsoft Entra ID application. We would like Figma Support to help us investigate the configuration of the second organization and confirm whether there is any limitation or conflict when configuring two independent Figma Enterprise organizations using separate Microsoft Entra ID Enterprise Applications. Could you please help us with the following questions? 1. Is it fully supported to configure SAML SSO and SCIM for two independent Figma Enterprise organizations using separate Microsoft Entra ID Enterprise Applications? 2. Is there any known limitation or restriction when the same Microsoft Entra ID tenant is used for multiple Figma Enterprise organizations? 3. Could the SAML signing certificate used by the first Figma application affect or conflict with the second Figma organization? 4. Does each Figma organization/tenant require a different SAML signing certificate, or can the same Microsoft Entra ID signing certificate be used for multiple Figma applications? 5. Could you please verify whether the SAML configuration associated with the second Figma Tenant ID is correctly associated with the expected IdP signing certificate? 6. Is there any specific configuration that we should review in Microsoft Entra ID regarding the SAML Signing Certificate, Entity ID, Reply URL (ACS), Sign-on URL, or federation metadata? We can provide the following information if required: - Figma Tenant ID - Microsoft Entra Enterprise Application configuration - SAML metadata - SAML signing certificate details - SAML authentication/error logs - Screenshots of the configuration and error We have attached a screenshot showing the error encountered during authentication. Thank you for your assistance.

1 reply

adamsmasher
Figmate
  • Figmate
  • September 5, 2026

Hi ​@Djalma Gabriel! Thanks for the post and appreciate the detail - happy to help clarify this for you.

 

To answer the biggest two questions for you first, yes, running two independent Figma Enterprise orgs with separate Microsoft Entra ID Enterprise Applications is fully supported. This is common even when both apps are under the same Entra tenant, so you can use the same tenant across multiple Figma orgs without restriction. Regarding the certificate, each Figma org should have its own, fully independent SAML configuration that is tied to a unique tenant-specific Entity ID and ACS URL. Figma resolves and validates each org's SAML response using only that org's stored certificate, so your first org's setup can't conflict with (or affect) the second org. Because of that, I’m wondering if it’s a certificate/metadata mismatch with the second org’s config. 

 

Could you check the following?

  • In the second Entra Enterprise Application's SAML SSO page, check that the current Signing Certificate matches what you have in Figma's SAML SSO settings for that org.
  • Confirm the Entity ID and Reply URL (ACS) in that Entra app match the values Figma generated specifically for this second org's tenant (rather than the first org).
  • If the certificate still isn't working correctly:
    • In Figma Admin, edit the SAML SSO configuration, select "Other" as the identity provider, re-enter the IdP Entity ID and SSO URL, and manually upload the current signing certificate (Base64 format) from Entra.
    • This should pick up the correct certificate rather than relying on automatic metadata retrieval.
  • Be sure to test using an incognito window just to make sure it’s a clean test.

 

If it's still not resolving after that, I’ll help create a ticket for you with our support team so they can look more directly at your setup.