> ## Documentation Index
> Fetch the complete documentation index at: https://docsv4.mile.app/llms.txt
> Use this file to discover all available pages before exploring further.

# Microsoft Entra ID SSO

> Let people sign in to the web app with their Microsoft Entra ID (Azure AD) account through SAML single sign-on.

With **Microsoft Entra ID** (formerly Azure Active Directory) connected, people in your Microsoft directory sign in to the web app with their Microsoft account. The connection uses SAML single sign-on: you register the app in Entra ID, then give the web app the **Login URL** and **Signing certificate** that Entra ID creates.

<Note>
  Required permission:

  * View integration
  * Create integration (to connect)
  * Edit integration (to change the Login URL or certificate)
  * Delete integration (to disconnect)
</Note>

## Before you begin

1. **A Microsoft Entra ID subscription** with an administrator account.
2. **Access to Settings › Integration** in the web app, with the permissions above.
3. **An enterprise application registered in Entra ID** for the web app. Step 1 below creates it.

## Step 1: Register the app in Entra ID

1. Sign in to the [Azure portal](https://portal.azure.com/).
2. Go to **Microsoft Entra ID › Enterprise applications › All applications** and click **New application**.
3. Click **Create your own application**, enter a name (for example, the name your team knows the app by), choose **Integrate any other application you don't find in the gallery (Non-gallery)**, and click **Create**.

## Step 2: Set up SAML in Entra ID

1. Open the application you just created from **Enterprise applications**.
2. In the left menu click **Single sign-on**, then choose **SAML**.
3. In **Basic SAML Configuration**, click **Edit**.
4. Enter an **Identifier (Entity ID)**, for example `https://your-app-url.com`. Note it down; it identifies the app as the service provider.
5. Click **Add reply URL** and enter the **Reply URL (Assertion Consumer Service URL)** where the sign-in response is posted, for example `https://your-app-url.com/auth/sso`.
6. Click **Save** and close **Basic SAML Configuration**.
7. Scroll down to the **Set up** section for your application and copy the **Login URL**. You paste it into the web app in Step 3.
8. In **SAML Signing Certificate**, download **Certificate (Base64)**. You upload it in Step 3.

## Step 3: Connect Entra ID in the web app

Open **Settings › Integration** and click **Connect** on the **Microsoft Entra ID** card.

<div align="center">
  <img src="https://mintcdn.com/mileappv4/Xul_B0hUk35UiMLk/images/v4/settings/integration-sso.png?fit=max&auto=format&n=Xul_B0hUk35UiMLk&q=85&s=404f2627574ff42bff44aa735000353f" alt="The Microsoft single sign-on dialog" width="600" data-path="images/v4/settings/integration-sso.png" />
</div>

1. **Login URL**: paste the Login URL you copied from Entra ID. It must be the full `https://` address, for example `https://login.microsoftonline.com/...`; otherwise you see *Write the full https address your directory gave you.*
2. **Signing certificate**: choose the certificate file you downloaded, as a `.cer`, `.pem` or `.crt` file. It's required when you connect for the first time.

Click **Save**. The card shows **Connected** and the toast *Microsoft Entra ID connected*.

To change the settings later, click **Edit** on the card. Leave **Signing certificate** empty to keep the current one, or choose a new file to replace it, for example when the certificate in Entra ID is renewed.

## Step 4: Give people access in Entra ID

Only people assigned to the application in Entra ID can sign in with it.

1. In the application in Entra ID, open **Users and groups**.
2. Click **Add user/group** and pick the people or groups who should be able to sign in.

## Signing in with Microsoft

Once the setup is done, people sign in through their Microsoft portal:

1. Open [office.com](https://www.office.com/) and sign in with the Microsoft account.
2. Click the **App launcher** (the grid icon).
3. Choose the application you registered in Step 1. The web app opens, signed in.

## Good to know

* **Accounts are matched by email.** If someone already has an account in the web app, the email in Entra ID must be the same for SSO to sign them in to that account. A different email in Entra ID is treated as a different account.
* **Invited but not verified.** If someone was invited in the web app but hasn't finished the email verification, they can't sign in through Entra ID with the same email until they do. Either finish the verification from the invitation email, or delete the unverified user on [Settings › User](/pages/settings/user/introduction) so Entra ID sign-in can create the account.
* **Passwords still work.** People who sign in with Entra ID can still set a password in the web app and use it on the normal sign-in page.
* **Disconnecting** stops Microsoft sign-in at once. Accounts stay, and people with a password can still sign in with it.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.