Prompt
Azure AD SSO setup
Latest observation
Here’s a practical checklist to set up Azure AD (Microsoft Entra ID) SSO for an application.
1) Decide the SSO protocol
Most common options:
- SAML 2.0 – common for enterprise SaaS apps
- OpenID Connect / OAuth 2.0 – preferred for modern web apps and APIs
- WS-Fed – legacy
If you’re not sure, use SAML for enterprise app integrations, or OIDC for custom apps.
2) Register the app in Microsoft Entra ID
Go to: Entra admin center → Applications → App registrations → New registration
Set:
- Name: app name
- Supported account types: usually “Single tenant” unless you need external users
- Redirect URI:
- OIDC/web app:
https://yourapp.com/auth/callback - SPA:
https://yourapp.com/ - Mobile/native: depends on platform
- OIDC/web app:
After creating the app, note:
- Application (client) ID
- Directory (tenant) ID
3) Configure authentication
In the app registration: Authentication → add platform(s)
For OIDC/Web app:
- Add Web
- Set Redirect URI
- Add Front-channel logout URL if needed
For SPA:
- Add Single-page application
- Set redirect URI
For mobile/native:
- Add Mobile and desktop applications
4) Create credentials
If your app needs a secret or certificate: Certificates & secrets → New client secret
- Copy the secret value immediately
- Prefer certificates for production if possible
5) Configure permissions
If the app needs user profile/basic sign-in:
- API permissions → Microsoft Graph
- Add:
openidprofileemailUser.Read
Then click:
- Grant admin consent if required
6) Set up SSO in the enterprise app
If you’re integrating a SaaS app or want SAML-based SSO: Enterprise applications → New application or select existing app → Single sign-on
For SAML:
You’ll need:
- Identifier (Entity ID)
- Reply URL (ACS URL)
- Sign-on URL (optional)
- Logout URL (optional)
Then configure:
- Basic SAML Configuration
- User Attributes & Claims
- Download:
- Federation Metadata XML
- Certificate (Base64)
For OIDC:
Use:
- Issuer:
https://login.microsoftonline.com/{tenant-id}/v2.0 - Authorize endpoint
- Token endpoint
- JWKS URI
7) Assign users/groups
In Enterprise applications:
- Go to Users and groups
- Assign who can access the app
If you enable:
- Assignment required? = Yes then only assigned users can sign in.
8) Test sign-in
Use:
- Test this application
- Or open the app and initiate sign-in
Check:
- Redirect URIs match exactly
- Tenant ID/client ID are correct
- Secret/certificate is valid
- User is assigned
- Conditional Access policies aren’t blocking access
9) Optional advanced settings
- Conditional Access: MFA, device compliance, location-based access
- Token claims: roles, group membership, email, etc.
- App roles: role-based authorization
- Provisioning: SCIM user provisioning if needed
Common issues
- AADSTS50011: Redirect URI mismatch
- AADSTS65001: Consent required
- AADSTS50020: User not in tenant / account type mismatch
- AADSTS7000215: Invalid client secret
- SAML invalid audience: Entity ID mismatch
If you want a quick start
Tell me:
- SAML or OIDC?
- What app type? (web app, SPA, mobile, SaaS)
- Are you configuring Azure AD as the IdP for a custom app or a third-party app?
And I can give you exact step-by-step settings and example config values.