After the SMA application has been configured to use Azure AD as an SAML-based Identity Provider, then it is almost ready to test. As a security control, Azure AD will not issue a token allowing users to sign into the SMA application until they have been granted access using Azure AD, either directly or through a group.
To assign a user or group to the SMA application
In Azure AD, click the Assign Users button.
Select the user or group you wish to assign, and then select the Assign button.