---
title: Configuring SSO with Azure/EntraID
description: "Follow these 3 Steps The following information are need to be documented/saved for later. note: if you use an existing app with &quot;API Permissions&quot; you must ensure that any required Admin Grant's are ap"
---

[Skip to content](https://support.preludesecurity.com/docs/azure#main-content)

English

Show submenu for translations

[Contact support](https://support.preludesecurity.com/kb-tickets/new?hsLang=en)

![Prelude\_Wordmark\_Black\_Transparent.png\]](https://support.preludesecurity.com/hs-fs/hubfs/Prelude_Wordmark_Black_Transparent.png?height=50&name=Prelude_Wordmark_Black_Transparent.png)

Open main navigation

Close main navigation

- English
  
  Show submenu for translations
- [Contact support](https://support.preludesecurity.com/kb-tickets/new)
- [Visit the website](https://www.preludesecurity.com/)

[Visit the website](https://www.preludesecurity.com/)

 Find what you're looking for

- There are no suggestions because the search field is empty.

1. [Knowledge Base](https://support.preludesecurity.com/?hsLang=en)
2. [Account](https://support.preludesecurity.com/account?hsLang=en)
3. [SSO](https://support.preludesecurity.com/account?hsLang=en#sso)

# Configuring SSO with Azure/EntraID

Follow these 3 Steps

1. [Create an App Registration](https://support.preludesecurity.com/docs/azure#app-registration)
2. [Configure Authentication Settings](https://support.preludesecurity.com/docs/azure#authentication-settings)
3. [Enable OIDC in Prelude](https://support.preludesecurity.com/docs/azure#oidc)
4. [Configure Prelude User Acccounts to use SSO](https://support.preludesecurity.com/docs/azure#Invite)

### 1. Create an App Registration

1. Navigate to the [App registrations section](https://portal.azure.com/#view/Microsoft_AAD_RegisteredApps/ApplicationsListBlade) in the **Azure Portal**.
2. Select "**+ New registration**" toward the top of the page.
3. Enter a name for your application
4. Choose **Single tenant** as the supported account type (*Accounts in this organizational directory only*). Click Register.
5. Leave **Redirect URI (optional)** as it is for now and click **Register**
6. After registration: 
     1. Copy/Save the **Application (client) ID** and **Directory (tenant) ID** from the app's **Overview page**.
7. In the left menu, expand the **Manage** section and select **Certificates & secrets** and create a **new Client Secret**: 
     1. Click **New client secret**, enter a description, and set an expiration period.
     2. Copy/Save the generated **Client Secret Value** (you won’t be able to view it later).

The following information are need to be documented/saved for later.

- **APP ID** (*Application (client) ID*) from step 6
- **TENANT ID** (*Directory (tenant) ID*) from step 6
- **APP SECRET** (*Client Secret Value*) from step 7

***note**: if you use an existing app with "API Permissions" you must ensure that any required Admin Grant's are approved. If you have not configured any API Permissions, this is not required*

### 2. Configure Authentication Settings

1. Navigate to your App in the [App registrations section](https://portal.azure.com/#view/Microsoft_AAD_RegisteredApps/ApplicationsListBlade) of the **Azure Portal**.
2. In the left menu, expand the **Manage** section and select **Authentication**
3. Under **Platform configurations** select "**+ Add a platform**" 
     1. Select "Web" in the "Configure Platforms" slide-out
     2. Enter the appropriate Redirect URI of the application: 
            1. US1: https://platform-auth.us1.preludesecurity.com/oauth2/idpresponse
            2. EU1: https://platform-auth.eu1.preludesecurity.com/oauth2/idpresponse
     3. Enter the appropriate Front-channel logout URL: 
            1. US1: [https://platform.us1.preludesecurity.com/sign-out](https://platform.us1.preludesecurity.com/sign-out)
            2. EU1: [https://platform.eu1.preludesecurity.com/sign-out](https://platform.eu1.preludesecurity.com/sign-out)
4. Ensure "ID Tokens" is selected
5. Click **Token Configuration** 
     1. Click **+ Add optional claim**
     2. **Select token type of ID**
     3. Add checkbox next to **upn** for claim and click **add  
        ![](https://support.preludesecurity.com/hs-fs/hubfs/screenshot_2476-png.png?width=688&height=289&name=screenshot_2476-png.png)**

 8\. Configuration is complete

### 3. Enable OIDC in Prelude

1. In the Prelude UI, click your name/id in the top right corner, then select Account Settings then **OpenID Connect Settings** 
     1. or select the appropriate link
     2. US1: [https://platform.us1.preludesecurity.com/account/oidc](https://platform.us1.preludesecurity.com/account/oidc)
     3. EU1: [https://platform.eu1.preludesecurity.com/account/oidc](https://platform.eu1.preludesecurity.com/account/oidc)
2. Enter the OIDC Information 
     1. Organizational Slug: You can change this to be something indicative of your organization
     2. Provider: Azure
     3. Client ID: APP ID recorded in step 1 ([Create an App Registration](https://markdowntohtml.com/#1_create_an_app_registration))
     4. Client Secret: Client Secret recorded in step 1 ([Create an App Registration](https://markdowntohtml.com/#1_create_an_app_registration))
     5. Configuration URL: 
            1. [https://login.microsoftonline.com/{TENANT\_ID}/v2.0/](https://login.microsoftonline.com/%7BTENANT_ID%7D/v2.0/.well-known/openid-configuration)
            2. replace {TENANT\_ID} with TENANT ID recorded in step 1 ([Create an App Registration](https://markdowntohtml.com/#1_create_an_app_registration)).
     6. Click **Save**

 

### 4. Configure Prelude User accounts to use SSO

**Note**: After configuring Entra SSO above you have to specify which user accounts will use SSO explicitly.  Additionally, you cannot update an existing user using password authentication to SSO currently.  Instead you must delete the user and recreate with SSO auth.

 

1. In the Prelude UI, click your name/id in the top right corner, then select **Account Users**
2. Select Invite a User to invite a new user and specify OpenID Connect to use Entra SSO

- [Monitor](https://support.preludesecurity.com/monitor?hsLang=en#main-content)

    - [Introduction to Control Monitor](https://support.preludesecurity.com/monitor?hsLang=en#introduction-to-control-monitor)
    - [Configuration](https://support.preludesecurity.com/monitor?hsLang=en#configuration)
    - [Client Hardware Security Integrations](https://support.preludesecurity.com/monitor?hsLang=en#client-hardware-security-integrations)
    - [Device Discovery Integrations](https://support.preludesecurity.com/monitor?hsLang=en#device-discovery-integrations)
    - [EDR Integrations](https://support.preludesecurity.com/monitor?hsLang=en#edr-integrations)
    - [Email Integrations](https://support.preludesecurity.com/monitor?hsLang=en#email-integrations)
    - [Identity Management Integrations](https://support.preludesecurity.com/monitor?hsLang=en#identity-management-integrations)
    - [Endpoint Management Integrations](https://support.preludesecurity.com/monitor?hsLang=en#endpoint-management-integrations)
    - [Vulnerability Management Integrations](https://support.preludesecurity.com/monitor?hsLang=en#vulnerability-management-integrations)
    - [Reporting](https://support.preludesecurity.com/monitor?hsLang=en#reporting)
    - [Troubleshooting](https://support.preludesecurity.com/monitor?hsLang=en#troubleshooting)
- [Detect](https://support.preludesecurity.com/detect?hsLang=en#main-content)

    - [Basics](https://support.preludesecurity.com/detect?hsLang=en#basics)
    - [Integrations](https://support.preludesecurity.com/detect?hsLang=en#integrations)
    - [Probe deployment](https://support.preludesecurity.com/detect?hsLang=en#probe-deployment)
    - [Security tests](https://support.preludesecurity.com/detect?hsLang=en#security-tests)
    - [Alert suppression](https://support.preludesecurity.com/detect?hsLang=en#alert-suppression)
    - [Assurance](https://support.preludesecurity.com/detect?hsLang=en#assurance)
- [Integrations](https://support.preludesecurity.com/integrations?hsLang=en#main-content)

    - [SASE](https://support.preludesecurity.com/integrations?hsLang=en#sase)
- [Account](https://support.preludesecurity.com/account?hsLang=en#main-content)

    - [SSO](https://support.preludesecurity.com/account?hsLang=en#sso)
- [CLI](https://support.preludesecurity.com/cli?hsLang=en)
- [Release Notes](https://support.preludesecurity.com/release-notes?hsLang=en)

[![Origin Technology Logo](https://support.preludesecurity.com/hs-fs/hubfs/origin_logo_inverse_000000.png?width=5000&height=5000&name=origin_logo_inverse_000000.png "Origin Technology Logo")](http://originhq.com)

Prelude Security Knowledge Base

Copyright © 2026, Origin Technology