> For the complete documentation index, see [llms.txt](https://doc.wearepatchworks.com/product-documentation/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://doc.wearepatchworks.com/product-documentation/registration/sso/azure-ad-entra.md).

# Azure AD / Entra

## Introduction

With an `Azure AD / Entra` SSO integration, users log into the Patchworks dashboard from Azure AD / Entra. Your Azure AD / Entra administrator determines who has access to Patchworks and these users will see a Patchworks app in their Azure AD / Entra dashboard.

Selecting this app directs the authenticated user to the Patchworks dashboard, where they are logged in directly. Azure AD / Entra users never see or require a password to access the Patchworks dashboard.

{% hint style="info" %}
Your Azure AD / Entra administrator requires a Patchworks account with administrator permissions to complete this setup.
{% endhint %}

This guide details the setup required to integrate Patchworks with Azure AD / Entra. For clarity, the setup is documented in five stages:

* [Stage 1: Patchworks - add Azure AD / Entra provider & generate URLs](#stage-1-patchworks-add-azure-a-d-entra-provider-and-generate-urls)
* [Stage 2: Azure AD / Entra - add new app registration & apply URLs](#stage-2-azure-a-d-entra-add-new-app-registration-and-apply-urls)
* [Stage 3: Patchworks - apply Azure AD / Entra credentials & enable](#stage-3-patchworks-apply-azure-a-d-entra-credentials-and-enable)
* [Stage 4: Azure AD / Entra - API permissions](#stage-4-azure-a-d-entra-api-permissions)
* [Stage 5: Test the connection](#stage-5-test-the-connection)

## Demo

The steps detailed in this guide are shown in this demonstration video:

<figure><img src="https://2440044887-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FLYNcUBVQwSkOMG6KjZfz%2Fuploads%2F3ex5uenQUAcMMS6O7hBY%2FAzure%20setup%20demo.gif?alt=media&amp;token=f024d760-7047-405c-b138-067459bb1052" alt=""><figcaption></figcaption></figure>

## Prerequisites

* Your Patchworks user account must be associated with [administrator permissions](/product-documentation/users-roles-and-permissions/roles-and-permissions-summary.md).
* You must have administrator access to your Azure dashboard.
* The Azure AD / Entra tenant ID for your organisation.

## Stage 1: Patchworks - add Azure AD / Entra provider & generate URLs

In this stage, we add a new SSO provider in Patchworks using your Azure AD / Entra `tenant ID` . This generates a set of URLs that we'll go on to apply in Azure AD / Entra.

**Step 1**\
In a new browser tab or window, log into the [Patchworks dashboard](https://app.wearepatchworks.com/) and select `my company admin` from general settings:

<div align="left"><figure><img src="https://2440044887-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FLYNcUBVQwSkOMG6KjZfz%2Fuploads%2FVug9swL4CvhMUF8Z7q86%2Fsso%201.png?alt=media&amp;token=62dce850-0191-4356-aa77-a24bbf8602e7" alt=""><figcaption></figcaption></figure></div>

{% hint style="info" %}
If you don't see this option, it's most likely that your user account is not associated with administrator permissions. In this case, please contact your system administrator.
{% endhint %}

**Step 2**\
Click the `Azure AD / Entra` button:

<div align="left"><figure><img src="https://2440044887-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FLYNcUBVQwSkOMG6KjZfz%2Fuploads%2FiBYMTTHZo504psXuKtUl%2Fazure%201.png?alt=media&amp;token=e2c46204-01ba-4175-aba7-bf7ca1eab6cd" alt=""><figcaption></figcaption></figure></div>

**Step 3**\
Paste your Azure AD / Entra `tenant ID` into the `base URL` field:

<div align="left"><figure><img src="https://2440044887-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FLYNcUBVQwSkOMG6KjZfz%2Fuploads%2FPN6cLKYhm4fQLYlzY6Bp%2Fazure%202.png?alt=media&amp;token=fa90e7f0-2053-438b-bf9c-e5f45d97dd12" alt="" width="563"><figcaption></figcaption></figure></div>

{% hint style="info" %}
You'll find the `tenant ID` for your organisation in the Azure AD / Entra admin portal, under `identity` | `overview`.
{% endhint %}

**Step 4**\
Click the `create` button to confirm.

**Step 5**\
An Azure AD / entra provider is added - click this entry:

<div align="left"><figure><img src="https://2440044887-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FLYNcUBVQwSkOMG6KjZfz%2Fuploads%2FGVc9aKPMfmaNJ4JBsmGl%2Fazure%203.png?alt=media&amp;token=b5d426ed-537a-4fd7-8c01-d6da1837f89e" alt=""><figcaption></figcaption></figure></div>

...you'll see that three Patchworks URLs have been generated - for example:

<div align="left"><figure><img src="https://2440044887-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FLYNcUBVQwSkOMG6KjZfz%2Fuploads%2FlNOoN96FMCLDf05mKSTs%2Fazure%203.png?alt=media&amp;token=1bdebe35-c87a-43ce-8b93-05897a9de1c0" alt=""><figcaption></figcaption></figure></div>

These URLs are needed to complete your Azure AD / Entra setup in the next stage. For reference, these are:

| Patchworks URL          | Azure AD / Entra usage                     |
| ----------------------- | ------------------------------------------ |
| Initiate sign-in url    | `Branding & properties` \| `Home page URL` |
| Callback url (auth url) | `App registration` \| `Redirect URIs`      |
| Logout url              | Not required for Azure AD / Entra          |

{% hint style="info" %}
Note that URLs shown in our screenshots are for a development environment -`dev.app.wearepatchworks.com`. Yours will always be for a production environment -`app.wearepatchworks.com`.
{% endhint %}

**Step 6**\
Optionally, you can click the `edit` option here and set a specific name for this implementation:

<div align="left"><figure><img src="https://2440044887-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FLYNcUBVQwSkOMG6KjZfz%2Fuploads%2FJdm5eJJPPhJwWeQ0zyN2%2Fazure%20name.png?alt=media&amp;token=ceb0430d-7dff-4e05-8333-534a82b3e292" alt=""><figcaption></figcaption></figure></div>

{% hint style="info" %}
This isn't mandatory but using specific names can be useful if you're adding multiple implementations of the same type. Remember to save your change if you do update the name.
{% endhint %}

**Step 7**\
Leave this page open and switch to your Azure AD / Entra admin portal for the next stage.

## Stage 2: Azure AD / Entra - add new app registration & apply URLs

In this stage, we register a Patchworks app in the Azure AD / Entra admin portal and apply Patchworks URLs generated for this provider at the end of the previous stage.

**Step 1**\
In your Azure AD / Entra admin portal, navigate to `identity` | `app registrations` and select the `new registration` option:

<div align="left"><figure><img src="https://2440044887-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FLYNcUBVQwSkOMG6KjZfz%2Fuploads%2FdHmdWK4JqFSoCXkzbZTs%2Fazure%208.png?alt=media&amp;token=1fcbc546-671b-4c29-ac85-bc82115f8f60" alt=""><figcaption></figcaption></figure></div>

**Step 2**\
Enter a `name` for this registration (we recommend `Patchworks` or similar):

<div align="left"><figure><img src="https://2440044887-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FLYNcUBVQwSkOMG6KjZfz%2Fuploads%2FniFwyxAISWkGp2kpDDci%2Fazure%209.png?alt=media&amp;token=aa9682fb-d756-44f5-adfb-5338708586d0" alt=""><figcaption></figcaption></figure></div>

**Step 3**\
Move down to the `redirect URI (optional)` section and set the `platform` to `web`:

<div align="left"><figure><img src="https://2440044887-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FLYNcUBVQwSkOMG6KjZfz%2Fuploads%2F3ZagaPMpMDsryIhdG3Ni%2Fazure%2010.png?alt=media&amp;token=e63f6c3c-8b56-49b5-ada7-755552e208fe" alt=""><figcaption></figcaption></figure></div>

For the URL, paste the `callback URL` value from your Azure AD / Entra provider setup in Patchworks.

{% hint style="info" %}
When copying URLs from your Patchworks provider details, click anywhere on the required link to copy it to your clipboard:

<img src="https://2440044887-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FLYNcUBVQwSkOMG6KjZfz%2Fuploads%2F3va4Np8FXBPvMqhPdSnt%2Fazure%20callback%20select.png?alt=media&amp;token=b07236f9-3225-44d0-9a01-eb929ffad9d4" alt="" data-size="original">
{% endhint %}

**Step 4**\
Click `register`:

<div align="left"><figure><img src="https://2440044887-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FLYNcUBVQwSkOMG6KjZfz%2Fuploads%2FINrkFEefAfn9E5GZmp73%2Fazure%2011.png?alt=media&amp;token=822661ba-6fa8-4b31-a6ec-5fcf3a834362" alt=""><figcaption></figcaption></figure></div>

**Step 5**\
Select `branding & properties` from the navigation menu. For the `home page URL`, paste the `initiate sign-in URL` value from your Azure AD / Entra provider setup in Patchworks:

<div align="left"><figure><img src="https://2440044887-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FLYNcUBVQwSkOMG6KjZfz%2Fuploads%2Fgw5P3BM6AmSV4zbBM305%2Fazure%2012.png?alt=media&amp;token=40d6097a-8fb2-42d4-87e0-837dc91dd897" alt=""><figcaption></figcaption></figure></div>

{% hint style="info" %}
When copying URLs from your Patchworks provider details, click anywhere on the required link to copy it to your clipboard:

<img src="https://2440044887-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FLYNcUBVQwSkOMG6KjZfz%2Fuploads%2FHAL5reKVBZp7vkyQmCso%2Fazure%20initiate%20select.png?alt=media&amp;token=08751976-5511-47e2-86a0-d1b1e7057707" alt="" data-size="original">
{% endhint %}

**Step 6**\
Save changes.

## Stage 3: Patchworks - apply Azure AD / Entra credentials & enable

In this stage, we take client credentials generated in Azure AD / Entra, apply them to our Azure AD / Entra provider setup in Patchworks, and enable this SSO implementation.

**Step 1**\
Still in the Azure AD / Entra admin portal, select `overview` from the navigation bar, then copy the `application (client) ID`:

<div align="left"><figure><img src="https://2440044887-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FLYNcUBVQwSkOMG6KjZfz%2Fuploads%2FNvTZsERGWy3r1AYnxeR9%2Fazure%2013.png?alt=media&amp;token=bb4dbfd6-19f3-4615-a858-bf11b405fd02" alt=""><figcaption></figcaption></figure></div>

**Step 2**\
Switch to Patchworks and select the `edit` option for your Azure AD / Entra provider setup:

<figure><img src="https://2440044887-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FLYNcUBVQwSkOMG6KjZfz%2Fuploads%2F4LXSYGMgS5z23attGbmQ%2Fazure%2015.png?alt=media&amp;token=f754c8f9-acb5-4964-b3ca-fab32e82eb0e" alt=""><figcaption></figcaption></figure>

**Step 3**\
Paste the `application (client) ID` into the `client ID` field:

<div align="left"><figure><img src="https://2440044887-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FLYNcUBVQwSkOMG6KjZfz%2Fuploads%2FOoxFDJhN6orqaC0btTd2%2Fazure%2016.png?alt=media&amp;token=865d39dd-8473-4bf5-8262-b21db84fbddd" alt=""><figcaption></figcaption></figure></div>

**Step 4**\
Back in the Azure AD / Entra admin portal, select `certificates & secrets` from the navigation bar and then select `new client secret`:

<div align="left"><figure><img src="https://2440044887-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FLYNcUBVQwSkOMG6KjZfz%2Fuploads%2Fl8Mzk3ThJSJeIp9bgCtN%2Fazure%2014.png?alt=media&amp;token=bf2363f3-36fb-4b45-902a-8ae25e724d97" alt=""><figcaption></figcaption></figure></div>

**Step 5**\
Enter a `description` to identify this secret, set the `expiry` according to your organisational policies and click `add`:

<div align="left"><figure><img src="https://2440044887-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FLYNcUBVQwSkOMG6KjZfz%2Fuploads%2FTAla7IknHSeIX0MbKWul%2Fazure%2017.png?alt=media&amp;token=6ad0c6c2-f5b4-449a-ae3e-afc6368cd197" alt="" width="563"><figcaption></figcaption></figure></div>

**Step 6**\
Copy the value for the new secret:

<div align="left"><figure><img src="https://2440044887-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FLYNcUBVQwSkOMG6KjZfz%2Fuploads%2FEEzrsQ92m6BKvoAAsHEQ%2Fazure%2018.png?alt=media&amp;token=5b4612ea-78af-40d1-89b6-af41b988d85d" alt=""><figcaption></figcaption></figure></div>

**Step 7**\
Switch to Patchworks and paste the secret into the `client secret` field:

<div align="left"><figure><img src="https://2440044887-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FLYNcUBVQwSkOMG6KjZfz%2Fuploads%2FGeuBxMEIYeaNScCA6jeP%2Fazure%2019.png?alt=media&amp;token=4e097cc8-b680-448b-b49c-e8f67e7e0e45" alt=""><figcaption></figcaption></figure></div>

**Step 8**\
Toggle the `enable` option to `on`:

<div align="left"><figure><img src="https://2440044887-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FLYNcUBVQwSkOMG6KjZfz%2Fuploads%2Fu4TAvGakKtsChsVYqH7F%2Fazure%2020.png?alt=media&amp;token=34a611bb-259e-45ee-8e05-08d769fa7bbc" alt=""><figcaption></figcaption></figure></div>

{% hint style="warning" %}
The SSO implementation won't be operational until this setup is enabled.
{% endhint %}

**Step 9**\
Save changes:

<div align="left"><figure><img src="https://2440044887-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FLYNcUBVQwSkOMG6KjZfz%2Fuploads%2Fqwe0ABEeH2XKFRam3lge%2Fazure%2021.png?alt=media&amp;token=0c63aed0-962d-4a2a-ab87-032833882828" alt=""><figcaption></figcaption></figure></div>

## **Stage 4: Azure AD / Entra - API permissions**

In this stage, we define the required API permissions for the new Azure AD / Entra app.

**Step 1**\
Switch back to the Azure AD / Entra admin portal, select `API permissions` from the navigation bar, then select `add a permission`:

<div align="left"><figure><img src="https://2440044887-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FLYNcUBVQwSkOMG6KjZfz%2Fuploads%2Fe6DQ7Rus06gWYGDCeATQ%2Fazure%2023.png?alt=media&amp;token=726f57c9-5891-490b-ba3c-bfa19a81f6e2" alt=""><figcaption></figcaption></figure></div>

**Step 2**\
Select Microsft Graph, then delegated permissions:

<div align="left"><figure><img src="https://2440044887-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FLYNcUBVQwSkOMG6KjZfz%2Fuploads%2FKbimrHlxztDvIXHzosrS%2Fazure%2024.png?alt=media&amp;token=890cb99e-58e9-4f62-a8fe-b7571c6531d4" alt=""><figcaption></figcaption></figure></div>

**Step 3**\
Add the following `openid` permissions:

* `email`
* `offline access`
* `openid`
* `profile`

For example:

<div align="left"><figure><img src="https://2440044887-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FLYNcUBVQwSkOMG6KjZfz%2Fuploads%2FGG0mOFdb9mytorpblol5%2Fazure%2025.png?alt=media&amp;token=86233925-0496-47d6-966b-26fe1b21d623" alt="" width="563"><figcaption></figcaption></figure></div>

## Stage 5: Test the connection

To quickly test that a successful connection has been made between Patchworks and Azure AD / Entra, switch back to the Patchworks dashboard, and copy the `initiate sign-in URL` value:

<figure><img src="https://2440044887-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FLYNcUBVQwSkOMG6KjZfz%2Fuploads%2FJWKoOaMcHSpzc7QhSSpX%2Fazure%2026.png?alt=media&amp;token=26ed1037-be56-49b0-b6f1-8f99350c18d0" alt=""><figcaption></figcaption></figure>

Now log out of Patchworks and paste the `initiate sign-in URL` value into your browser - this should log straight into the Patchworks dashboard.
