Skip to content

Configure Single Sign-On (SSO) for Microsoft Entra ID

Single sign-on (SSO) lets ALTR administrators sign into the ALTR platform with their Microsoft Entra ID credentials instead of a separate ALTR username, password, and two-factor authentication method. ALTR supports SSO with Microsoft Entra ID through Security Assertion Markup Language (SAML) 2.0. For what SSO controls at the platform level, see SSO and SCIM.

SSO authenticates existing ALTR administrators; it does not create them. Add your administrators in ALTR before you enable SSO.

When enabling SSO, make sure you have:

  • Administrator access to your identity provider.
  • Super Administrator access to your ALTR account. To check your role, see Administrators.

By default, Microsoft Entra ID and ALTR match users on UserPrincipalName and Username. SSO can be configured to match on another field, such as email; for help customizing the identifier, contact ALTR Support.

To configure SSO with Microsoft Entra ID:

  1. Sign into Microsoft Entra ID as an administrator.
  2. Select Add > Enterprise application to create a new enterprise application. Microsoft Entra ID Enterprise applications page with the Add menu open and Enterprise application highlighted
  3. Click Create your own application. Assign a name to your application (for example, “ALTR”) and select the Non-gallery application option. Create your own application panel in Microsoft Entra ID with an application name entered and the Non-gallery option selected
  4. Once the application is created, go to its Overview page. Select Set up single sign-on. Application Overview page in Microsoft Entra ID with the Set up single sign-on option highlighted
  5. Select SAML from the list of single sign-on methods. Single sign-on method selection page in Microsoft Entra ID with SAML highlighted
  6. Sign into your ALTR account. Select Settings > Preferences in the navigation menu. Click the SSO/SCIM tab. Click Download. SSO/SCIM tab on the ALTR Preferences page with the metadata Download option
  7. Return to Microsoft Entra ID and click Upload metadata file. Upload the file you downloaded from ALTR. Click Add. Upload metadata file option in the Microsoft Entra ID SAML configuration
  8. Provision your ALTR administrators to your Microsoft Entra ID application.
    1. In Microsoft Entra ID, go to your ALTR enterprise application.
    2. Go to the Users and groups section.
    3. Search for and select your user.
    4. Identify your UserPrincipalName.
    5. In ALTR, select Settings > Administrators in the navigation menu.
    6. Ensure your ALTR Username exactly matches your UserPrincipalName in Microsoft Entra ID. The match is case-sensitive. If your ALTR Username does not exactly match your UserPrincipalName, you will not be able to sign into ALTR.
  9. Go to the SAML Certificates section in Microsoft Entra ID. Click the Copy to clipboard icon in the App Federation Metadata URL field. Paste this URL into the Provider URL field in ALTR. SAML Certificates section in Microsoft Entra ID with the App Federation Metadata URL copy icon highlighted
  10. Return to ALTR. Select Microsoft Entra ID. Click Enable SSO. SSO/SCIM tab on the ALTR Preferences page with the identity provider selection and Enable SSO button
  11. After ALTR configures SSO, keep your current window open, open an incognito window or a different browser, and sign into your ALTR account. Do not sign out of ALTR in your main window until you have confirmed you can sign into ALTR in the second window.