diff --git a/vorgang-manager-server/src/main/resources/bayernid/keycloak-saml-metadata.xml b/vorgang-manager-server/src/main/resources/bayernid/keycloak-saml-metadata.xml
index b5746cf909d209910496f9ffef142f748c9378e9..ad97ace9c70ed45face203919ef15dd0be855cb0 100644
--- a/vorgang-manager-server/src/main/resources/bayernid/keycloak-saml-metadata.xml
+++ b/vorgang-manager-server/src/main/resources/bayernid/keycloak-saml-metadata.xml
@@ -1,3 +1,5 @@
+<?xml version="1.0" encoding="UTF-8"?>
+<md:EntitiesDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata">
 <md:EntityDescriptor xmlns="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" entityID="https://sso.dev.by.ozg-cloud.de/realms/by-antragsraum-idp">
 <md:IDPSSODescriptor WantAuthnRequestsSigned="true" protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol">
 <md:KeyDescriptor use="signing">
@@ -22,4 +24,5 @@
 <md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://sso.dev.by.ozg-cloud.de/realms/by-antragsraum-idp/protocol/saml"/>
 <md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="https://sso.dev.by.ozg-cloud.de/realms/by-antragsraum-idp/protocol/saml"/>
 </md:IDPSSODescriptor>
-</md:EntityDescriptor>
\ No newline at end of file
+</md:EntityDescriptor>
+</md:EntitiesDescriptor>
\ No newline at end of file