> ## Documentation Index
> Fetch the complete documentation index at: https://docsy3.mile.app/llms.txt
> Use this file to discover all available pages before exploring further.

# SSO with Azure AD (Entra)

This documentation outlines the steps to integrate Single Sign-On (SSO) using Microsoft Azure Active Directory (AD) with the platform. This integration allows users to authenticate using their Azure AD credentials.

<Note>
  Required permission:

  * View integration
  * Create integration
</Note>

Before you begin, ensure you have the following:

1. **Azure AD Subscription**: A valid Azure AD account with administrator privileges.
2. **Platform access**: Access to the administration settings.
3. **Application Registration**: An application registered in Azure AD for the platform.

## Step 1: Register the application in Azure AD

1. **Log into the Azure Portal**: Navigate to [Azure Portal](https://portal.azure.com/).

<div align="center">
  <img src="https://mintcdn.com/mile-app/WLXNrGtWP2NU1tMt/images/integration/sso-azure-portal.png?fit=max&auto=format&n=WLXNrGtWP2NU1tMt&q=85&s=9421dc7ca1471c104a3b6608d14758ff" alt="Azure Portal homepage" width="600" data-path="images/integration/sso-azure-portal.png" />
</div>

2. **Create a New Application**:
   * Go to **Azure Active Directory ➝ All aplication ➝ New application**.

<div align="center">
  <img src="https://mintcdn.com/mile-app/WLXNrGtWP2NU1tMt/images/integration/sso-new-application.png?fit=max&auto=format&n=WLXNrGtWP2NU1tMt&q=85&s=48a498461903db71af47b4b24925af63" alt="New application menu" width="600" data-path="images/integration/sso-new-application.png" />
</div>

* Enter the following details:
  * **Name**: Acme Logistics
  * Select the (**Non-gallery) option from the radio box** and click **Create**.

<div align="center">
  <img src="https://mintcdn.com/mile-app/WLXNrGtWP2NU1tMt/images/integration/sso-non-gallery.png?fit=max&auto=format&n=WLXNrGtWP2NU1tMt&q=85&s=fb31840fdd4f1318f760a7420bd5517c" alt="Create non-gallery application" width="600" data-path="images/integration/sso-non-gallery.png" />
</div>

3. **Register**: Click on **Create** to create the application.

## Step 2: Configure SSO in Azure AD

1. **Navigate to the Registered Application**:
   * Find and select the application from the **App registrations** list.

2. **Set Up SSO**:
   * In the left menu, click on **Single sign-on**.
   * Select **SAML** as the SSO method.

<div align="center">
  <img src="https://mintcdn.com/mile-app/WLXNrGtWP2NU1tMt/images/integration/sso-saml-selection.png?fit=max&auto=format&n=WLXNrGtWP2NU1tMt&q=85&s=b130dde39d0e32001e5e21d17251a560" alt="SAML SSO selection" width="600" data-path="images/integration/sso-saml-selection.png" />
</div>

3. **Basic SAML Configuration**:
   * In the **Basic SAML Configuration** section, click on **Edit** and provide the following information:

<div align="center">
  <img src="https://mintcdn.com/mile-app/WLXNrGtWP2NU1tMt/images/integration/sso-saml-config.png?fit=max&auto=format&n=WLXNrGtWP2NU1tMt&q=85&s=94393a3cb64b85835ae7d46893e572c1" alt="Basic SAML Configuration" width="600" data-path="images/integration/sso-saml-config.png" />
</div>

4. Enter a unique ID. Note: This ID will be used in the saml.config file for the service provider name. Therefore, note the ID. For e.g: you can enter the ID as `https://your-app-url.com`

5. Next, click **Add reply URL**.

6. Enter the application **callback URL** where the response will be posted. For now, you can enter a dummy URL e.g. `https://your-app-url.com/auth/sso`

7. Select **Save**. Close the Basic SAML Configuration page.

8. Now scroll down to the "Set up" section for your app. Copy the Login URL. You will need this URL in the web portal.

9. **SAML Signing Certificate**:
   * Download the **Certificate (Base64)** by clicking on the **Download** button. This certificate will be used in the platform for SSO configuration.

## Step 3: Configure the platform for SSO

1. **Log into the web portal**: Access the settings menu.

2. **Navigate to SSO Settings**:
   * Go to **Setting ➝ Integration ➝ Azure SSO Configuration**.

3. **Enter SSO Details:**
   1. Paste the **Login URL** that you copied from Azure.
   2. Upload the .cer file that you downloaded from Azure

<div align="center">
  <img src="https://mintcdn.com/mile-app/WLXNrGtWP2NU1tMt/images/integration/sso-mileapp-config.png?fit=max&auto=format&n=WLXNrGtWP2NU1tMt&q=85&s=8e333afef187aaf91e2c966934b90385" alt="SSO configuration" width="600" data-path="images/integration/sso-mileapp-config.png" />
</div>

4. After entering the required details, click on **Save** to apply the settings.

## Step 4: Registering Users from Azure

<div align="center">
  <img src="https://mintcdn.com/mile-app/WLXNrGtWP2NU1tMt/images/integration/sso-users-groups.png?fit=max&auto=format&n=WLXNrGtWP2NU1tMt&q=85&s=606bc655e439449e10084af2fd126b4e" alt="Users and Groups menu" width="600" data-path="images/integration/sso-users-groups.png" />
</div>

### Steps:

1. Open the **Users and Groups** menu.
2. Click **Add User/Group** to register users who can access the platform.
3. Only registered users in Azure can log in to the platform using their Azure accounts.

## Login via Microsoft Account with Azure SSO

### 1. Complete the Setup Process

After successfully completing the setup steps for Azure SSO, you can proceed to log in to the platform using your Microsoft account.

### 2. Access the Office Portal

<div align="center">
  <img src="https://mintcdn.com/mile-app/WLXNrGtWP2NU1tMt/images/integration/sso-office-login.png?fit=max&auto=format&n=WLXNrGtWP2NU1tMt&q=85&s=9c13acc82c9bc8b097f7c70dd5df8d64" alt="Office portal login" width="600" data-path="images/integration/sso-office-login.png" />
</div>

<div align="center">
  <img src="https://mintcdn.com/mile-app/WLXNrGtWP2NU1tMt/images/integration/sso-office-dashboard.png?fit=max&auto=format&n=WLXNrGtWP2NU1tMt&q=85&s=5a3283849df3f88081986ec76f011ff7" alt="Office portal dashboard" width="600" data-path="images/integration/sso-office-dashboard.png" />
</div>

1. Open the Microsoft Office web portal at [https://www.office.com/](https://www.office.com/).
2. Log in with your Microsoft account credentials.

### 3. Navigate to the web portal

<div align="center">
  <img src="https://mintcdn.com/mile-app/WLXNrGtWP2NU1tMt/images/integration/sso-app-launcher.png?fit=max&auto=format&n=WLXNrGtWP2NU1tMt&q=85&s=e3d9fcacf3dc749b9864e80a51b74512" alt="App launcher with the application" width="600" data-path="images/integration/sso-app-launcher.png" />
</div>

1. Once logged in, click on the **App Launcher** (the grid icon) on the left-hand side of the screen.
2. Select **Acme Logistics** from the list of available applications to access the web platform.

By following these steps, you will be successfully logged into the platform through your Microsoft account integrated with Azure SSO.

## Notes

1. If you already have an account and want to integrate it with Azure SSO, ensure that the email registered in Azure AD matches the email used in your account.
2. If the email registered in Azure AD differs from the email registered in the platform, it will be considered a separate account.
3. If a user has been invited through the platform but has not completed the verification process via email and is then registered in Azure using the same email, they cannot log in to the platform until the verification is complete. You can complete the verification process via email or delete the unverified user in the **User Settings** menu to allow access.

## Tips

1. Ensure you have **View** and **Create Integration** permissions to configure the integration.
2. You can still set a password in the platform even after your account is registered in Azure. The password can be used for logging in through the login page.
