> This page is for Portal.

> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.emnify.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.emnify.com/_mcp/server.

# Set up SSO with Microsoft Entra ID

> Set up SSO for your emnify account with Microsoft Entra ID (formerly Azure Active Directory)

This guide walks through enabling single sign-on (SSO), so your Workspace can access the emnify Portal using your Microsoft Business credentials.

## Prerequisites

* A Microsoft Entra ID (formerly Azure Active Directory) tenant and an account with at least the Application Developer role
* An [emnify account](/quickstart) using the same email address as the one used to sign in to Microsoft Entra ID

> **Warning**
>
> If your email address used in the emnify Portal differs from the one used to log in to Microsoft Entra ID, this setup won't work.
> You can verify your email in [**User Settings**](https://portal.emnify.com/user-settings).
>
> Instead, add an additional user with the **Administrator** role.
> To do this, go to **Workspace settings** > [**Users**](https://portal.emnify.com/organisation-settings/users).

## Register emnify in Microsoft Entra ID

Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com).

Go to **Entra ID** > **App registrations** and click **New registration**.

Enter a **Name** for the app, for example `emnify`.

Under **Supported account types**, select **Multiple Entra ID tenants**.
This setting makes Microsoft show a consent screen when you verify the integration in the emnify Portal later.

Under **Redirect URI**, select the **Web** platform and enter `https://prod-e5.okta.com/oauth2/v1/authorize/callback`.

Click **Register**.
Microsoft Entra ID opens the app's **Overview** page.

In the left sidebar, click **Authentication**.

Under **Implicit grant and hybrid flows**, select **Access tokens** and **ID tokens**, then click **Save**.

In the left sidebar, click **Token configuration**, then click **Add optional claim**.

Select the **SAML** token type, select the `upn` claim, and click **Add**.
If Microsoft asks whether to turn on the Microsoft Graph profile permission, leave the option cleared.

In the left sidebar, click **API permissions**.
Check that **Microsoft Graph** lists the `email` and `profile` permissions.

If either permission is missing, click **Add a permission** > **Microsoft Graph** > **Delegated permissions**.
Under **OpenId permissions**, select `email` and `profile`, then click **Add permissions**.

In the left sidebar, click **Expose an API**.

Next to **Application ID URI**, click **Add**, then click **Save**.

In the left sidebar, click **Certificates & secrets**.
On the **Client secrets** tab, click **New client secret**.

Enter a **Description** for the secret, for example `emnify SSO`, choose an expiration, and click **Add**.
Set a reminder to create and configure a new secret before this one expires.

Copy the secret's **Value** and save it in a secure location.

> **Error**
>
> Microsoft shows this value only once.

In the left sidebar, click **Overview** and copy the **Application (client) ID**.
You need it, along with the secret, to configure the emnify Portal.

## Configure the emnify Portal

[Log in to the emnify Portal](https://portal.emnify.com/sign/).

Go to **Workspace settings** (building icon) in the top-level navigation and click [**Single Sign-On**](https://portal.emnify.com/organisation-settings/federation).

If you need SSO enabled for your account, [contact emnify support](https://support.emnify.com/hc/en-us/requests/new).
Otherwise, click **Add** under the Microsoft SSO provider.

Enter the **Client ID** and **Client Secret** you copied earlier, then click **Create and Activate**.

Once you're back on **Single Sign-On**, you should see Microsoft listed as a **Provider**.

Finally, click **Verify Integration** and follow the prompts.

> **Warning**
>
> You must complete the final step and verify the provider to configure SSO.

> **Tip**
>
> Refer to the [Troubleshooting page](/portal/sso/troubleshooting) if you encounter issues while setting up SSO.