Skip to main content

SSO (Single Sign On) - Entra ID / Azure / Microsoft

Enabling you to login to SameSystem through Entra ID

Written by Amanda

SameSystem has a 2-tier integration to Entra ID:

  • SSO - enabling you to login to SameSystem through Entra ID

  • Employee sync - push employees created and updated in SameSystem to Entra ID

This article is on how to set up SSO. To see the setup for employee sync, go to this article: https://helpapp.samesystem.com/en/articles/10697437-employee-sync-entra-id-azure-microsoft

Enabling it for the client

The functionality is enabled from the client list by adding a business email domain as shown below. For instance for SameSystem, the domain would be @samesystem.com.

When the feature is enabled, a new field will appear in the general tab for all employees called "Business email". This exists alongside the standard email field.

The standard email will still be used for all communication, while the business email purely will be for SSO and for employee sync.

SameSystem will automatically generate new business emails for each employee based on their first name and last name. And if there's duplicates, it'll add a number in the end. If the employee already have a company email in Entra ID, then it's possible for admins to overwrite the automated business email to that.

An employee named Lars Larsen from @samesystem.com would get the following email lars.larsen@samesystem.com. If there's two with identical names, the next one would be lars.larsen2@samesystem.com.

Enabling it from Entra ID

Next step is to enable it from Entra ID. Go to the login screen and click the "Login with Microsoft". You must have sufficient permissions/accesses in Entra ID.

Whereafter you'll be asked to login with your Entra ID credentials. This will give you a prompt, where you'll be asked to give permission for SameSystem to access Entra ID. SameSystem asks for the minimum access right to deliver SSO. It's important that you mark the checkbox before proceeding, as that ensures that all employees with SSO enabled will have the right permissions.

After clicking accept you'll either be logged in to SameSystem or logged out of SameSystem if your business email is not added to any employees in SameSystem.

It's perfectly fine not to have a SameSystem user as long as the user you login with through SSO has the right permissions/accesses in Entra ID.

You can can validate that the permission has been given by going to Entra ID (Also called "Identify" from Microsoft 365 Admin Center) and then to Applications -> Enteprise Applications.

Enabling it on the titles

Final step is to enable it for the titles that must login through SSO. This is done through title-based settings and the tab called "Azure", as seen below.

Without additional configuration, you're only able to enable SSO at this point. Mark the roles that must login through SSO. These employees will no longer be able to use the normal login flow. However, those not marked will still be able to login as normal.

Welcome emails and password change

The logic around welcome emails and password changes depends on the configuration of SSO and Employee Sync.

SSO enabled + Employee Sync disabled:

  • No "Welcome" emails

  • No "Reset password" emails

  • Hides "Change password" for employee

  • Hides "Reset password" for manager

SSO enabled + Employee Sync enabled:

  • New "Welcome" email (contains business email and temporary password).

  • New "Reset password" email (contains temporary password).

  • Hides "Change password" for employee

  • Displays "Reset password" for manager

SSO disabled + Employee sync enabled:

  • Normal "Welcome" email

  • Normal "Reset password" emails

  • Displays "Change password" for employee

  • Displays "Reset password" for manager

Do you want to use employee sync too?

Did this answer your question?