How to Configure Azure AD SSO
Updated by Leeroy Steele
Granting Application Consent in Azure
The following steps to grant Application Consent are intended to be actioned by an I.T. team who have the correct administrator level permissions for your Azure tenancy. It is common that a Prompt Admin will not have the appropriate level of permissions to complete this section.
- Browse to Prompt and select Login With SSO from the options provided:
- Authenticate with the appropriate Microsoft Administrator account
- Select Consent on behalf of your organisation and Accept on the permissions requested Microsoft prompt.
- Note: At this point of the configuration, receiving an error message that SSO Login Failed is expected as we have not completed the configuration
- Note: If you have received the following prompt, you do not have the appropriate level of permissions to grant application consent on behalf of your organisation:
Confirming Tenant ID
The following steps to confirm your Tenant ID are intended to be actioned by an I.T. team who have the correct administrator level permissions for your Azure tenancy. It is common that a Prompt Admin will not have the appropriate level of permissions to complete this section.
- Browse to the Azure Portal and authenticate with an appropriate Microsoft Administrator account
- Search and select the Microsoft Entra ID service from the top of the page:
- From the Microsoft Entra ID module, your Tenant ID is available to view/copy from the Overview landing page:
- Provide the Tenant ID value to the Prompt Admin or Admin completing the Azure SSO configuration
Enable Azure SSO in Prompt
The Granting Application Consent in Azure and Confirming Tenant ID sections are pre-requisites of enabling this feature.
- Log in to Prompt as Prompt Admin or Admin.
- Navigate to Admin -> Manage Organisation, select Edit on the Organization you want to enable SSO on.
- On the Edit Organization page, Click on the Azure AD tab.
- Toggle Azure SSO on.
- Enter the Tenancy ID provided from the Confirming Tenant ID section under Azure Active Directory Details
- Click Save at the bottom of the page to save the information.
- Users from your Azure tenancy can now login to Prompt using their Microsoft 365 accounts.
Validating Azure SSO
After completing the above steps, you can validate Azure SSO by:
- Browsing to Prompt
- If you are currently logged in, select the Logout option from your user profile dropdown:
- Once presented with the login page, select Login with SSO.
- Login with your Microsoft 365 details
- If successful, you will be logged into your Prompt profile
Optional 1 - Enable SSO User Creation
- Navigate to Admin -> Manage Organisation, select Edit on the Organization you want to enable SSO user creation on.
- On the Edit Organization page, Click on the Azure AD tab.
- Toggle User Creation on Login on.
- Specify the Default Department and Section for newly created Users. These can be changed later by Prompt Admin but are required for the initial creation.
- Click Save at the bottom of the page to save the information.
Optional 2 - Enable Automated User Provisioning in Prompt
How to Setup Automatic User Provisioning (AzureAD).
To toggle Automatic User Provisioning On / Off in Prompt:
- Navigate to Admin -> Manage Organisation, select Edit on the Organization you want to enable SSO user creation on.
- On the Edit Organization page, Click on the Azure AD tab.
- Toggle Automated User Provisioning On / Off.
- (If you are turning it on for the first time) Specify the Default Department and Section for newly created Users. These can be changed later by Prompt Admin but are required for the initial creation.
- Click Save at the bottom of the page to save the information.