Microsoft Entra ID SSO: Setup guide and FAQ

Modified on Thu, 8 Oct at 11:49 AM

With Microsoft Entra ID SSO, your organization's users sign in to Systam Studio with their own Microsoft account instead of a separate password. SSO doesn't create or remove users. The user has to already exist in Studio before their first SSO sign-in.

Important: you need admin consent on the Microsoft side. SSO won't work until a Microsoft Entra admin in your organization approves the Systam application for the whole tenant. Consent can be granted by a user with one of these Entra roles: Global Administrator, Privileged Role Administrator, Cloud Application Administrator, or Application Administrator. The Studio owner and the Entra admin are often different people, so agree on a time with your admin before you start.

Before you start

  • If Microsoft Entra ID SSO isn't shown as enabled on the Extensions page in Studio, contact Systam support. We need to enable it for your organization first.
  • You need organization owner rights in Studio.
  • A Microsoft Entra admin who can grant admin consent is available (see above).
  • Users already exist in Studio, either created manually or through SCIM sync. SSO doesn't create accounts at sign-in.
  • Your Studio users' email addresses must match the ones they use to sign in to Microsoft. Otherwise SSO can't find the user.

Setting up SSO in Studio

  1. Open Extensions → Microsoft Entra ID SSO.
  2. Copy your Directory (tenant) ID from the Microsoft Entra admin center and enter it in the Tenant ID field.
  3. Click Verify metadata. This confirms your tenant is reachable and its sign-in settings are available. It doesn't test an actual sign-in yet.
  4. Click Grant tenant admin consent. Your Microsoft Entra admin signs in and approves the permissions for the whole tenant. Once consent is granted, the Admin consent required warning disappears.
  5. Test sign-in with at least two existing users. Keep password sign-in available as a fallback during this step.
  6. Once testing looks good, turn on Require single sign-on. The switch becomes available only after admin consent has been granted. Password sign-in is disabled after this, so Studio asks for a separate confirmation.

Changing your mind: turning Require single sign-on off allows password sign-in again right away, and keeps your tenant and other SSO settings. Reset SSO configuration clears your entire SSO configuration, but doesn't touch your SCIM/Entra sync settings.

What users see when signing in

  • Sign-in always starts with an email address.
  • When SSO is optional, users see both the password field and a Log in with Microsoft button.
  • When SSO is enforced, users are sent straight to Microsoft after entering their email.
  • If something goes wrong with optional SSO, password sign-in works as a fallback. If it goes wrong with enforced SSO, the user is sent back to the email step. Since password sign-in is blocked, your organization owner is locked out too. Contact Systam support and we'll restore access.

Account linking and what data updates

On the first SSO sign-in, the email or username confirmed by Microsoft is matched to an existing Studio user, and the account is linked from then on.

  • Email and name update based on what Microsoft sends. A missing or empty value never erases data that's already stored.
  • SSO doesn't bring in phone numbers, groups, roles, job title, department, or workspace assignments.

SSO and user provisioning (SCIM)

SSO and SCIM handle different things, and turning one on or off doesn't change the other's settings:

  • SSO handles sign-in and confirms who the user is.
  • SCIM (Entra sync) handles creating, updating, and removing users, workspace assignment, and contact details.

Most organizations get the best result from using both: SSO for sign-in and SCIM for keeping the user directory current.

Bringing in phone numbers with SCIM

The SSO sign-in token isn't a reliable source for phone numbers, since it's built for sign-in, not ongoing directory sync. SCIM updates user data continuously and supports phone numbers directly.

If you want phone numbers synced, map the relevant Entra field to phoneNumbers[type eq "work"].value or phoneNumbers[type eq "other"].value in your SCIM provisioning setup. The field is optional, and Systam converts the number to international format automatically.

Changing your Tenant ID or turning off SSO

Changing the Tenant ID breaks existing Microsoft account links. The new tenant needs to be verified, consented, and tested from scratch, the same as the first setup. Turning off SSO restores password sign-in but doesn't sign out users who are already logged in.

Checklist before requiring SSO

  • Admin consent has been granted.
  • Pilot users already exist in Studio, and their emails match their Microsoft accounts.
  • Sign-in has been tested with at least two regular users.
  • Everyone knows SSO doesn't create users or bring in phone numbers. SCIM handles those.
  • There's a plan for what to do if something goes wrong. If SSO stops working after it's required, no one can sign in with a password, and Systam support restores access.
  • Your organization is ready for the moment password sign-in gets disabled.

Microsoft's documentation

That covers setting up SSO. Reach out to support if any step needs more detail.

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article