Skip to main content

Single Sign-On (SSO) with Microsoft Entra ID

Let your team members sign in to Prduct with their Microsoft work accounts and control which role each Entra group gets.

Written by Bjarke Guldager

With single sign-on your members do not need a separate Prduct password. They sign in with the Microsoft account they already use at work, and the role they get in Prduct follows the Entra groups they are in.

Before you start

  • You are the owner or an administrator of your company in Prduct.

  • You have a Microsoft work account in your organisation. If your organisation restricts app approvals, use an account that can approve apps (for example a Global Administrator).

  • The roles you want to hand out already exist in Prduct under Company settings → Members & roles.

You do not need to copy any IDs, secrets or certificates from the Azure portal. Prduct reads your organisation's tenant ID automatically when you connect.

Set up the connection

Everything happens on Company settings → Single sign-on.

  1. Choose a role for unmapped people. This is the role given to anyone who signs in with a group you have not mapped yet. It is required before the connection can go live, so nobody gets full access by accident.

  2. Click "Connect Microsoft Entra ID". Your settings are saved and you are sent to Microsoft. Sign in with your own work account and accept the approval prompt (first time only).

  3. Done — the connection is active. Your tenant ID is filled in automatically from the sign-in. If a step is still missing, the screen tells you exactly what remains.

  4. Map your groups to roles. Groups appear under Your provider groups after somebody in them signs in — your own sign-in is usually enough. Give each group a name and choose which role(s) it grants. You can also add a group in advance by its Object ID (in Entra: Groups → your group → Overview).

  5. Test with one member. Ask one person from a mapped group to sign in through the direct sign-in link shown at the top of the screen, and check they get the intended role.

Settings explained

Email domains

Optional. Restricts which email addresses can get an account, and puts your company on the sign-in page for those domains — typing [email protected] then sends her straight to Microsoft. Leave empty to allow any address from your organisation.

Create accounts automatically

On by default. A member's first sign-in creates their Prduct account. Turn it off to require an invitation first.

Companies this covers

Other Prduct companies you own that should share this sign-in. One Microsoft sign-in then grants membership of all of them, each with its own roles.

Status

Active — members can sign in. Not in use / Disabled — sign-in is off, settings are kept. A connection can only be set to Active after the connect sign-in has confirmed your organisation.

How your members sign in

  • "Sign in with Microsoft" on the Prduct login page — works for everyone once the connection is active.

  • Your company's direct link, shown on the Single sign-on screen — useful for bookmarks and onboarding emails.

  • Typing their work email on the login page — only when email domains are filled in.

Good to know

  • Only your organisation can sign in. Every sign-in is verified against your organisation's own Microsoft keys — email domains are an extra filter, not the security boundary.

  • One organisation, one connection. A Microsoft organisation connects to one Prduct company. To reach more of your companies, add them under Companies this covers instead of connecting them separately.

  • Existing accounts are never taken over. Someone who already has a Prduct password keeps using it, and can connect Microsoft themselves under Profile.

  • Several matching groups combine. A person in two mapped groups gets both roles — anything either role allows is allowed.

  • Role changes apply at the next sign-in. A sign-in that carries no group information never removes access.

  • The company owner is not affected. Group mappings can never restrict or lock out the owner.

  • Offboarding is two steps. Removing someone in Entra stops their Microsoft sign-in — also remove them from your member list in Prduct.

  • Disconnecting keeps everything. Accounts, memberships and roles stay — only the Microsoft sign-in stops.

Troubleshooting

Message

What to do

"Your Microsoft sign-in is already connected to [company]."

Your organisation is already connected to that company. Open its Single sign-on settings and add this company under Companies this covers, or disconnect it there first.

"Sign in with the button above to confirm your organisation first, then set this to Active."

Click Connect Microsoft Entra ID once — the connection activates automatically when a role for unmapped people is chosen.

"An account already exists for this email address."

The person already has a Prduct password. They sign in with it, then connect Microsoft under Profile.

"You do not have an account here yet."

Automatic account creation is off. Invite the person first, or turn it on.

"Your email domain is not permitted to sign in to this organisation."

Add their domain under Email domains, or clear the field to allow any address from your organisation.

"Your organisation has not enabled single sign-on here yet."

The connection is not Active, or the person signed in with an account from a different organisation.

A group does not appear in the list

Nobody in it has signed in yet — one sign-in is enough. You can also add it by its Object ID. For people in more than 200 groups, Microsoft leaves the group list out; map an app role for them instead.

Changing Microsoft organisation? If your company moves to a new tenant, connect again — the previous confirmation does not carry over, and sign-in stays off until the new organisation is confirmed.

Did this answer your question?