How to Configure Azure AD SSO

Leeroy Steele Updated by Leeroy Steele

PERMISSION REQUIRED: Prompt Admin, Admin
The Azure AD SSO section is independent from the Email Autocomplete section.
Single Sign On only impacts General Users, Admins, Prompt Admins and Super Users. Any user accessing Prompt via your organisations unique read-only URL does not require SSO as it is an auto-login user profile that does not require credentials.

The following steps to grant Application Consent are intended to be actioned by an I.T. team who have the correct administrator level permissions for your Azure tenancy. It is common that a Prompt Admin will not have the appropriate level of permissions to complete this section.

  1. Browse to Prompt and select Login With SSO from the options provided:

  1. Authenticate with the appropriate Microsoft Administrator account
  2. Select Consent on behalf of your organisation and Accept on the permissions requested Microsoft prompt.
  1. Note: At this point of the configuration, receiving an error message that SSO Login Failed is expected as we have not completed the configuration

  1. Note: If you have received the following prompt, you do not have the appropriate level of permissions to grant application consent on behalf of your organisation:

Lancom is an organisation that provides support and development services for Prompt.

Confirming Tenant ID

The following steps to confirm your Tenant ID are intended to be actioned by an I.T. team who have the correct administrator level permissions for your Azure tenancy. It is common that a Prompt Admin will not have the appropriate level of permissions to complete this section.

  1. Browse to the Azure Portal and authenticate with an appropriate Microsoft Administrator account
  2. Search and select the Microsoft Entra ID service from the top of the page:
  1. From the Microsoft Entra ID module, your Tenant ID is available to view/copy from the Overview landing page:
  1. Provide the Tenant ID value to the Prompt Admin or Admin completing the Azure SSO configuration

Enable Azure SSO in Prompt

The Granting Application Consent in Azure and Confirming Tenant ID sections are pre-requisites of enabling this feature.

  1. Log in to Prompt as Prompt Admin or Admin.
  2. Navigate to Admin -> Manage Organisation, select Edit on the Organization you want to enable SSO on.
  3. On the Edit Organization page, Click on the Azure AD tab.
  4. Toggle Azure SSO on.
  5. Enter the Tenancy ID provided from the Confirming Tenant ID section under Azure Active Directory Details
  6. Click Save at the bottom of the page to save the information.

  1. Users from your Azure tenancy can now login to Prompt using their Microsoft 365 accounts.

Validating Azure SSO

After completing the above steps, you can validate Azure SSO by:

  1. Browsing to Prompt
  2. If you are currently logged in, select the Logout option from your user profile dropdown:

  1. Once presented with the login page, select Login with SSO.

  1. Login with your Microsoft 365 details
  2. If successful, you will be logged into your Prompt profile
User account status needs to be active in Azure in order to successfully login with SSO. The email address you use to login with SSO with needs to match your Prompt user email address.

Optional 1 - Enable SSO User Creation

Prompt can add new users from your azure tenancy when they first login to Prompt if they are not currently a Prompt user.
  1. Navigate to Admin -> Manage Organisation, select Edit on the Organization you want to enable SSO user creation on.
  2. On the Edit Organization page, Click on the Azure AD tab.
  3. Toggle User Creation on Login on.
  4. Specify the Default Department and Section for newly created Users. These can be changed later by Prompt Admin but are required for the initial creation.
  5. Click Save at the bottom of the page to save the information.

Optional 2 - Enable Automated User Provisioning in Prompt

User Provisioning is adding, editing and disabling Prompt users directly from your Azure Portal
Please note: This article only covers how to enable or disable it. The entire setup process is covered in this article:
How to Setup Automatic User Provisioning (AzureAD).

To toggle Automatic User Provisioning On / Off in Prompt:

  1. Navigate to Admin -> Manage Organisation, select Edit on the Organization you want to enable SSO user creation on.
  2. On the Edit Organization page, Click on the Azure AD tab.
  3. Toggle Automated User Provisioning On / Off.
  4. (If you are turning it on for the first time) Specify the Default Department and Section for newly created Users. These can be changed later by Prompt Admin but are required for the initial creation.
  5. Click Save at the bottom of the page to save the information.

How did we do?

How to assign Standards, Legislation, Executive Sponsors and Risk Rating

How to configure an Organisation

Contact