---
title: "SSO: Microsoft Entra ID"
slug: "sso-microsoft-entra-id"
tags: ["single sign-on"]
updated: 2025-01-02T21:29:59Z
published: 2025-01-02T21:29:59Z
canonical: "support.smarteru.com/sso-microsoft-entra-id"
---

> ## Documentation Index
> Fetch the complete documentation index at: https://support.smarteru.com/llms.txt
> Use this file to discover all available pages before exploring further.

# SSO: Microsoft Entra ID

Integrating SmarterU with Microsoft Entra ID (formerly Azure Active Directory) allows you to:

- Control who has access to SmarterU from Microsoft Entra ID
- Automatically sign users into SmarterU using their Microsoft Entra accounts (i.e. single sign-on)
- Manage your accounts from the Microsoft Entra admin center

If you want to integrate Azure Active Directory (AD) B2C using OpenID, refer to [Setting Up Azure Active Directory B2C](/v1/docs/sso-azure-active-directory-b2c).

Be sure you have a Microsoft Entra ID subscription. You can create a free account by visiting [https://azure.microsoft.com/en-us/free/entra-id](https://azure.microsoft.com/en-us/free/entra-id).

To set up Microsoft Entra ID with SmarterU:

1. [Add SmarterU as a managed app](/v1/docs/sso-microsoft-entra-id#adding-smarteru-as-a-managed-app).
2. [Configure single sign-on in Microsoft Entra ID.](/v1/docs/sso-microsoft-entra-id#configuring-single-signon-in-microsoft-entra-id)
3. [Determine the URL users will use to log in](/v1/docs/sso-microsoft-entra-id#determining-the-url-users-will-use-to-log-in).
4. [Configure single sign-on in SmarterU.](/v1/docs/sso-microsoft-entra-id#configuring-single-signon-in-smarteru)
5. [Create a user in Microsoft Entra ID.](/v1/docs/sso-microsoft-entra-id#creating-a-user-in-microsoft-entra-id) See note about creating a test user, below this list.
6. [Assign the SmarterU app to the user.](/v1/docs/sso-microsoft-entra-id#assigning-the-smarteru-app-to-the-user) See note about creating a test user, below this list.
7. [Add the user to SmarterU.](/v1/docs/sso-microsoft-entra-id#adding-the-user-to-smarteru) See note about creating a test user, below this list.

For single sign-on to work, you need to create a relationship between a Microsoft Entra ID user and the related SmarterU user. We recommend completing steps 5-7 for a test user before creating additional user accounts to ensure that you've properly established the relationship between Microsoft Entra ID and SmarterU. After you've tested single sign-on for your test user, you'll need to complete steps 4-6 for each user.

## Adding SmarterU as a Managed App

To add SmarterU as a managed app in Microsoft Entra ID:

1. From the left menu in Microsoft Entra ID, select **Microsoft Entra ID**.

![Azure Active Directory Menu Option 20240812](https://cdn.document360.io/7efaadab-fef6-4186-806a-2ca14c9ce9ea/Images/Documentation/Azure%20Active%20Directory%20Menu%20Option%2020240812.png)

1. From the sub-menu, select **Enterprise Applications**.

![Azure - Enterprise Applications Menu Option 20240812](https://cdn.document360.io/7efaadab-fef6-4186-806a-2ca14c9ce9ea/Images/Documentation/Azure%20-%20Enterprise%20Applications%20Menu%20Option%2020240812.png)

1. Ensure **All Applications** is selected.
2. Click **New Application**.

![Azure - New Application Button 20240812](https://cdn.document360.io/7efaadab-fef6-4186-806a-2ca14c9ce9ea/Images/Documentation/Azure%20-%20New%20Application%20Button%2020240812.png)

1. Enter *SmarterU* in the search field.

![Azure - Search for SmarterU App 20240812](https://cdn.document360.io/7efaadab-fef6-4186-806a-2ca14c9ce9ea/Images/Documentation/Azure%20-%20Search%20for%20SmarterU%20App%2020240812.png)

The SmarterU application displays in the search results.

1. Click **SmarterU**.
2. Click **Create**.

![Azure - Add SmarterU App 20240812](https://cdn.document360.io/7efaadab-fef6-4186-806a-2ca14c9ce9ea/Images/Documentation/Azure%20-%20Add%20SmarterU%20App%2020240812.png)

**NEXT STEP:** [Configure single sign-on in Microsoft Entra ID.](/v1/docs/sso-azure-active-directory#configuring-single-signon-in-azure-ad)

## Configuring Single Sign-On in Microsoft Entra ID

To configure single sign-on in Microsoft Entra ID:

1. From the SmarterU - Overview page's menu, select **Single Sign-On**.

![Azure - SU Menu - Single Sign On 20240812](https://cdn.document360.io/7efaadab-fef6-4186-806a-2ca14c9ce9ea/Images/Documentation/Azure%20-%20SU%20Menu%20-%20Single%20Sign%20On%2020240812.png)

1. Select **SAML**.
2. From the Basic SAML Configuration section, click ![Icon Description automatically generated](https://cdn.document360.io/7efaadab-fef6-4186-806a-2ca14c9ce9ea/Images/Documentation/sso-azure-active-directory-image-8qlgy7d1.png). The Basic SAML Configuration workscreen displays.
3. From the Basic SAML Configuration workscreen:
  1. In the **Identifier** field, be sure the identifier is https://integrations.smarteru.com/<accountID>, where you replace <accountID> with your account's ID.

You can find your account's ID by logging into SmarterU and looking at the URL.  
  
![](https://cdn.document360.io/7efaadab-fef6-4186-806a-2ca14c9ce9ea/Images/Documentation/Account%20ID%20in%20URL%2020211115.png)

1. Click **Save**.
2. Click ![](https://cdn.document360.io/7efaadab-fef6-4186-806a-2ca14c9ce9ea/Images/Documentation/sso-azure-active-directory-image-d6nw4yrm.png) to close the Basic SAML Configuration workscreen.

![](https://cdn.document360.io/7efaadab-fef6-4186-806a-2ca14c9ce9ea/Images/Documentation/Azure%20-%20SU%20Basic%20SAML%20Config%20Buttons%2020220202.png)

1. On the SmarterU - SAML-Based Sign On page, scroll down to the SAML Certificates section.
2. From the SAML Signing Certificate section, click the **Download** link beside Federation Metadata XML.

![Azure - SU Download Federation Metadata XML Certificate 20240812](https://cdn.document360.io/7efaadab-fef6-4186-806a-2ca14c9ce9ea/Images/Documentation/Azure%20-%20SU%20Download%20Federation%20Metadata%20XML%20Certificate%2020240812.png)

1. Save the file to your computer. You'll need this file in the [Configuring Single Sign-On in SmarterU](/v1/docs/sso-azure-active-directory#configuring-single-signon-in-smarteru) step.

**NEXT STEP:** [Determine the URL users will use to log in.](/v1/docs/sso-microsoft-entra-id#determining-the-url-users-will-use-to-log-in)

## Determining the URL Users Will Use to Log In

To determine the URL that users will use to log in:

1. From the left menu in Microsoft Entra ID, select **Microsoft Entra ID**.
2. Select **Enterprise Applications**.
3. From the list of applications, select **SmarterU**.
4. Select **Properties**.
5. Locate the User Access URL. This is the URL that users will use to log in.

![Azure - SU Properties - User Access URL 20240812](https://cdn.document360.io/7efaadab-fef6-4186-806a-2ca14c9ce9ea/Images/Documentation/Azure%20-%20SU%20Properties%20-%20User%20Access%20URL%2020240812.png)

**NEXT STEP:** [Configure single sign-on in SmarterU.](/v1/docs/sso-azure-active-directory#configuring-single-signon-in-smarteru)

## Configuring Single Sign-On in SmarterU

To configure single sign-on in SmarterU:

1. [Enable external authorization](/v1/docs/account-external-authorization-sso#enable-external-authorization) for your SmarterU account.
2. Specify the following settings:

| Setting | Value |
| --- | --- |
| [**Master Login Control**](/v1/docs/account-external-authorization-sso#master-login-control) | Select the *SmarterU* option. |
| [**User Default Login**](/v1/docs/account-external-authorization-sso#user-default-login) | Select the *SmarterU* option. |
| [**Enable SAML**](/v1/docs/sso-saml-20#enable-saml) | Check the Enable SAML checkbox. |
| [**IdP Metadata**](/v1/docs/sso-saml-20#idp-metadata) | Use Notepad to open the Federation Metadata XML certificate that you downloaded in the [Configuring Single Sign-On in Microsoft Entra ID section](/v1/docs/sso-azure-active-directory#configuring-single-signon-in-entra-id). Copy the contents of the certificate file and paste it into the IdP Metadata field. |
| [**Identifier Attribute/Claim**](/v1/docs/sso-saml-20#identifier-attributeclaim) | Select the identifier you want to use for log in. |
| [**Identifier Type**](/v1/docs/sso-saml-20#identifier-type) | Select the identifier type. |

![Graphical user interface, text, application, email, website Description automatically generated](https://cdn.document360.io/7efaadab-fef6-4186-806a-2ca14c9ce9ea/Images/Documentation/sso-azure-active-directory-image-r1jaursl.png)

1. Click **Save**.

**NEXT STEP:** [Create a user in Microsoft Entra ID.](/v1/docs/sso-azure-active-directory#creating-a-user-in-azure-ad)

## Creating a User in Microsoft Entra ID

To create a user in Microsoft Entra ID:

1. From the left menu in Microsoft Entra ID, select **Microsoft Entra ID**.
2. Select **Users**.

![Azure - Users Menu Option 20240812](https://cdn.document360.io/7efaadab-fef6-4186-806a-2ca14c9ce9ea/Images/Documentation/Azure%20-%20Users%20Menu%20Option%2020240812.png)

1. Ensure **All Users** is selected.
2. Click **New User**.

![Azure - New User Button 20240812](https://cdn.document360.io/7efaadab-fef6-4186-806a-2ca14c9ce9ea/Images/Documentation/Azure%20-%20New%20User%20Button%2020240812.png)

1. Select **Create New User**.

![Entra ID - Create New User 20240819](https://cdn.document360.io/7efaadab-fef6-4186-806a-2ca14c9ce9ea/Images/Documentation/Entra%20ID%20-%20Create%20New%20User%2020240819.png)

The Create New User workscreen displays.

![Entra ID - Create New User - Basics 20240819](https://cdn.document360.io/7efaadab-fef6-4186-806a-2ca14c9ce9ea/Images/Documentation/Entra%20ID%20-%20Create%20New%20User%20-%20Basics%2020240819.png)

1. Specify the following settings in the Create New User workscreen.

| Setting | Value |
| --- | --- |
| **User Principal Name** | The user's email address. NOTE: If you're using the user's email address to link Microsoft Entra ID to SmarterU, make note of the user's email address. You will need to use this email address when you create the user in SmarterU. |
| **Display Name** | The user's full name. |
| **Password** | Do one of the following: - Enter the user's password. - To auto-generate a password, select the Auto-Generate Password checkbox. You can click the eye icon in the Password field to view the password. Make note of the password as you'll need it [when you create the user's SmarterU user account](/v1/docs/sso-azure-active-directory#adding-the-user-to-smarteru). |

1. Click **Review + Create**.
2. Click **Create**.

**NEXT STEP:** [Assign the SmarterU app to the user.](/v1/docs/sso-azure-active-directory#assigning-the-smarteru-app-to-the-user)

## Assigning the SmarterU App to the User

You must assign the SmarterU app to the user in order for it to display in the user's Microsoft Entra Access Panel.

To assign the SmarterU app to the Microsoft Entra ID user:

1. From the left menu in Microsoft Entra ID, select **Microsoft Entra ID**.
2. Select **Enterprise Applications**.

![Azure - Enterprise Applications Menu Option 20240812](https://cdn.document360.io/7efaadab-fef6-4186-806a-2ca14c9ce9ea/Images/Documentation/Azure%20-%20Enterprise%20Applications%20Menu%20Option%2020240812.png)

1. Select **All Applications**.
2. From the list of applications, select **SmarterU**.
3. Select **Users and Groups**.
4. Click **Add User/Group**. The Add Assignment workscreen displays.
5. Click **Users**.

![Azure - Add Assignment 20240812](https://cdn.document360.io/7efaadab-fef6-4186-806a-2ca14c9ce9ea/Images/Documentation/Azure%20-%20Add%20Assignment%2020240812.png)

The Users panel displays.

1. Select the checkbox beside the user's name. The user's name displays in the Selected section of the panel.

![Azure - Add Assignment - Selected Users 20240812](https://cdn.document360.io/7efaadab-fef6-4186-806a-2ca14c9ce9ea/Images/Documentation/Azure%20-%20Add%20Assignment%20-%20Selected%20Users%2020240812.png)

1. Click **Select**. The Add Assignment workscreen reflects the number of users that were selected.
2. Click **Assign**.

**NEXT STEP:** [Adding the user to SmarterU.](/v1/docs/sso-azure-active-directory#adding-the-user-to-smarteru)

## Adding the User to SmarterU

To add the user to SmarterU:

1. Follow the steps detailed on the [Adding a User Manually](/v1/docs/adding-a-user-manually) page.
2. Be sure that the email address specified matches the user's Microsoft Entra ID email address.
3. [Determine the URL users will use to log in.](/v1/docs/sso-azure-active-directory#determining-the-url-users-will-use-to-log-in)
4. Log in with single sign-on using the [test user](/v1/docs/sso-azure-active-directory).

## Troubleshooting

If your users are having trouble logging in, refer to our [Troubleshooting User Accounts](/v1/docs/troubleshooting-user-accounts) page for common issues.

## Related

- [Account: External Authorization (SSO)](/account-external-authorization-sso.md)
- [External Authorization (SSO)](/external-authorization-sso.md)
- [SSO: Azure Active Directory B2C](/sso-azure-active-directory-b2c.md)
- [Troubleshooting User Accounts](/troubleshooting-user-accounts.md)
- [User Sync Integrations](/user-sync-integrations.md)
