Set up SSO with Microsoft Entra ID
This guide walks through enabling single sign-on (SSO), so your Workspace can access the emnify Portal using your Microsoft Business credentials.
Prerequisites
- A Microsoft Entra ID (formerly Azure Active Directory) tenant and an account with at least the Application Developer role
- An emnify account using the same email address as the one used to sign in to Microsoft Entra ID
If your email address used in the emnify Portal differs from the one used to log in to Microsoft Entra ID, this setup won’t work. You can verify your email in User Settings.
Instead, add an additional user with the Administrator role. To do this, go to Workspace settings > Users.
Register emnify in Microsoft Entra ID
Sign in to the Microsoft Entra admin center.
Under Supported account types, select Multiple Entra ID tenants. This setting makes Microsoft show a consent screen when you verify the integration in the emnify Portal later.
Under Redirect URI, select the Web platform and enter https://prod-e5.okta.com/oauth2/v1/authorize/callback.
Select the SAML token type, select the upn claim, and click Add.
If Microsoft asks whether to turn on the Microsoft Graph profile permission, leave the option cleared.
In the left sidebar, click API permissions.
Check that Microsoft Graph lists the email and profile permissions.
If either permission is missing, click Add a permission > Microsoft Graph > Delegated permissions.
Under OpenId permissions, select email and profile, then click Add permissions.
In the left sidebar, click Certificates & secrets. On the Client secrets tab, click New client secret.
Configure the emnify Portal
Go to Workspace settings (building icon) in the top-level navigation and click Single Sign-On.
If you need SSO enabled for your account, contact emnify support. Otherwise, click Add under the Microsoft SSO provider.
You must complete the final step and verify the provider to configure SSO.
Refer to the Troubleshooting page if you encounter issues while setting up SSO.