Skip to navigation
Single-sign onSet up SSO with Microsoft Entra ID

Set up SSO with Microsoft Entra ID

This guide walks through enabling single sign-on (SSO), so your Workspace can access the emnify Portal using your Microsoft Business credentials.

Prerequisites

  • A Microsoft Entra ID (formerly Azure Active Directory) tenant and an account with at least the Application Developer role
  • An emnify account using the same email address as the one used to sign in to Microsoft Entra ID

If your email address used in the emnify Portal differs from the one used to log in to Microsoft Entra ID, this setup won’t work. You can verify your email in User Settings.

Instead, add an additional user with the Administrator role. To do this, go to Workspace settings > Users.

Register emnify in Microsoft Entra ID

2

Go to Entra ID > App registrations and click New registration.

3

Enter a Name for the app, for example emnify.

4

Under Supported account types, select Multiple Entra ID tenants. This setting makes Microsoft show a consent screen when you verify the integration in the emnify Portal later.

5

Under Redirect URI, select the Web platform and enter https://prod-e5.okta.com/oauth2/v1/authorize/callback.

6

Click Register. Microsoft Entra ID opens the app’s Overview page.

7

In the left sidebar, click Authentication.

8

Under Implicit grant and hybrid flows, select Access tokens and ID tokens, then click Save.

9

In the left sidebar, click Token configuration, then click Add optional claim.

10

Select the SAML token type, select the upn claim, and click Add. If Microsoft asks whether to turn on the Microsoft Graph profile permission, leave the option cleared.

11

In the left sidebar, click API permissions. Check that Microsoft Graph lists the email and profile permissions.

12

If either permission is missing, click Add a permission > Microsoft Graph > Delegated permissions. Under OpenId permissions, select email and profile, then click Add permissions.

13

In the left sidebar, click Expose an API.

14

Next to Application ID URI, click Add, then click Save.

15

In the left sidebar, click Certificates & secrets. On the Client secrets tab, click New client secret.

16

Enter a Description for the secret, for example emnify SSO, choose an expiration, and click Add. Set a reminder to create and configure a new secret before this one expires.

17

Copy the secret’s Value and save it in a secure location.

Microsoft shows this value only once.

18

In the left sidebar, click Overview and copy the Application (client) ID. You need it, along with the secret, to configure the emnify Portal.

Configure the emnify Portal

2

Go to Workspace settings (building icon) in the top-level navigation and click Single Sign-On.

3

If you need SSO enabled for your account, contact emnify support. Otherwise, click Add under the Microsoft SSO provider.

4

Enter the Client ID and Client Secret you copied earlier, then click Create and Activate.

5

Once you’re back on Single Sign-On, you should see Microsoft listed as a Provider.

6

Finally, click Verify Integration and follow the prompts.

You must complete the final step and verify the provider to configure SSO.

Refer to the Troubleshooting page if you encounter issues while setting up SSO.