Set up SSO with Microsoft Entra ID
Connect Microsoft Entra ID to Tinct with OpenID Connect or SAML 2.0: what to set on each side.
Last updated 11 days ago
Part of Single sign-on (SSO) for your workspace: step 2 of 3, on Microsoft Entra ID.
Microsoft Entra ID (formerly Azure Active Directory) speaks both protocols Tinct accepts. Choose OpenID Connect unless your organisation has standardised on SAML: it takes fewer steps. Its client secret expires, 24 months at most after it is created, and renewing it is a matter of minutes with no interruption: see When the client secret expires.
You must be an admin of the workspace, and the workspace must be entitled to single sign-on. The screens below are those of the Microsoft Entra admin center as of 2026.
Before you start
- Verify at least one email domain: Verify your email domain. You can describe the connection first, but you cannot enable it until a domain is verified.
- Have an Entra ID role that can register applications (Application Administrator or Cloud Application Administrator), and a user whose email address is on a verified domain, to run the test sign-in with.
- Check that your users have an Email in Entra ID (the user's Properties → Contact information): it is the address Tinct receives, and it is empty for users with no mailbox. Their user principal name is not sent in its place.
Option A: OpenID Connect
💡 Planning to add automatic provisioning too? Entra ID cannot provision from an application registered this way. Choose SAML (Option B), which does both, or add a second application for provisioning only, as Set up automatic provisioning (SCIM) explains.
1. Register the application
- In the Microsoft Entra admin center, go to Entra ID → App registrations and click New registration.
- Name:
Tinct. - Supported account types: Accounts in this organizational directory only (single tenant).
- Leave Redirect URI empty for now: Tinct gives it to you in step 3. Click Register.
- On the Overview page, copy the Application (client) ID and the Directory (tenant) ID.
2. Create a client secret and grant the permissions
- Go to Certificates & secrets → Client secrets and click New client secret. Choose an expiry, and click Add.
- Copy the secret's Value right away: Entra ID shows it only once. Not the Secret ID, which Tinct cannot use.
- Go to API permissions, click Add a permission → Microsoft Graph → Delegated permissions, tick
openid,profileandemailunder OpenId permissions, and click Add permissions. - Click Grant admin consent for your organisation, so that your users are not asked to consent themselves.
3. Describe Entra ID in Tinct
- In Tinct, go to Settings → Security, to the Identity provider card, and keep OpenID Connect.
- Fill in:
- Issuer:
https://login.microsoftonline.com/<Directory (tenant) ID>/v2.0, with the tenant ID from step 1. Use the ID, not a domain name such ascontoso.onmicrosoft.com, and notcommonororganizations: Entra ID announces its issuer with the ID, and Tinct requires the exact same address. - Client ID: the Application (client) ID
- Client secret: the secret's Value
- Issuer:
- Click Save identity provider.
4. Register the redirect URI
- Copy the Redirect URI the card now shows.
- In Entra ID, open the app registration, go to Authentication, click Add a platform → Web (or Add Redirect URI if the Web platform is already there), paste it, and click Configure (or Save).
5. Choose who can sign in
By default, every user of your directory can sign in to a new application. To limit it, go to Entra ID → Enterprise applications, open Tinct, and in Properties set Assignment required? to Yes. Then assign the users or groups that use Tinct under Users and groups.
Then go to Test, then enable.
Option B: SAML 2.0
1. Get Tinct's values
- In Tinct, go to Settings → Security, to the Identity provider card.
- Under Protocol, choose SAML 2.0. If no connection exists yet, click Get the values for my provider.
- Next to Service provider metadata, click Download.
2. Create the enterprise application
- In the Microsoft Entra admin center, go to Entra ID → Enterprise applications and click New application.
- Click Create your own application, name it
Tinct, choose Integrate any other application you don't find in the gallery (Non-gallery), and click Create. Not Register an application to integrate with Microsoft Entra ID: that option creates an OpenID Connect registration, whose Single sign-on page offers no SAML. - In the application, go to Single sign-on and choose SAML.
- At the top of the page, click Upload metadata file, pick the file you downloaded, and click Add. Entra ID fills in Identifier (Entity ID) and Reply URL (Assertion Consumer Service URL) from it. Leave Sign on URL, Relay State and Logout Url empty, and click Save.
If you cannot upload a file, click Edit in Basic SAML Configuration instead, and paste Tinct's Service provider entity ID into Identifier (Entity ID) and its Single sign-on URL (ACS) into Reply URL.
3. Send a persistent NameID
Entra ID sends the email address, the first name and the last name under the claim names Tinct reads by default: nothing to change there. The identifier needs one change.
- In Attributes & Claims, click Edit, then click the Unique User Identifier (Name ID) claim.
- Name identifier format: Persistent. Source attribute:
user.objectid. - Click Save.
The object ID never changes for a user, unlike their user principal name (the default), which changes when they are renamed. Tinct recognises a person by the NameID, so a changed NameID means Tinct no longer recognises their account.
Leave SAML Certificates as it is: Entra ID signs the assertion with SHA-256. If you turn on Token encryption, also set the Signing Option to Sign SAML response and assertion: Tinct only accepts an encrypted assertion inside a signed response. Entra ID encrypts with RSA-OAEP and AES-256, which Tinct accepts.
4. Assign the users
New enterprise applications only let in the users assigned to them. Go to Users and groups, click Add user/group, and assign the users or groups that use Tinct.
To keep the Tinct tile out of your users' My Apps portal, set Visible to users? to No in Properties, unless you turn on sign-in from the provider in Tinct (see Sign-in started from your provider).
5. Describe Entra ID in Tinct
- In Entra ID, back on the application's Single sign-on page, copy the App Federation Metadata Url from the SAML Certificates section (the third card).
- Back in Tinct, under Values from your identity provider, choose Metadata URL, and paste it.
- Click Save identity provider. Tinct reads Entra ID's entity ID, sign-on URL and signing certificate from it.
Leave Attribute names empty.
Test, then enable
- In the Status card, click Test sign-in. A pop-up opens on Microsoft's sign-in page.
- Sign in as a user of your directory whose email address is on one of your verified domains.
- The result page shows the email address and the names Tinct received. Entra ID never says whether an address is verified, so the page reads the provider does not say whether it is verified: that is expected, Tinct relies on your verified domains.
- Back on the Security page, click Enable.
Tinct only lets in addresses on your verified domains, and, when Create accounts at first sign-in is off, only people you invited.
When you are confident, go on to Require SSO in your workspace.
If something goes wrong
Microsoft's error pages start with a code:
- AADSTS50011: the redirect URI (OpenID Connect) or the reply URL (SAML) does not match Tinct's exactly.
- AADSTS50105: the user is not assigned to the application.
- AADSTS700016: the application was not found. OpenID Connect: the client ID or the tenant ID in the issuer is wrong. SAML: Identifier (Entity ID) is not exactly Tinct's entity ID.
- AADSTS7000215: the client secret is wrong. The usual cause is the Secret ID pasted instead of the Value.
- AADSTS7000222: the client secret has expired: see below.
- AADSTS65001: consent is missing. Grant admin consent (OpenID Connect, step 2).
And on Tinct's side:
- Tinct says the issuer could not be used (OpenID Connect). The issuer must end in
/<tenant ID>/v2.0, with the ID, not a domain name,commonororganizations. - Tinct says no email address was sent. The user has no Email in Entra ID: add it to their contact information. Check also which account Microsoft signed in: it may reuse the session of an account already signed in in the browser, often your administrator account. Test in a private window, or pick Use another account. On SAML, you can instead send the user principal name as the email: edit the
emailaddressclaim and set its source attribute touser.userprincipalname, if your user principal names are real addresses on your verified domains. - Tinct says the address is not on a verified domain. The user's email is on another domain, often
….onmicrosoft.com: verify the domain, or give the user an address on a verified one.
When the client secret expires
OpenID Connect only. Entra ID secrets expire, 24 months at most after they are created, and Tinct cannot see when. Put a reminder in your calendar before the expiry date shown in Certificates & secrets.
Nobody is interrupted during the renewal: Entra ID accepts the old and the new secret side by side, and a new secret keeps the connection in Tinct as it is.
- In Entra ID, create a new client secret, and copy its Value.
- In Tinct, paste it into Client secret and click Save identity provider.
- Click Test sign-in to check it.
- Delete the old secret in Entra ID.
When Entra ID's SAML certificate expires
SAML only. The certificate is valid three years, and Entra ID emails the address given under SAML Certificates → Notification Email before it expires. Tinct also emails your admins 30, 14, 7 and 1 day before.
- Under SAML Certificates, click Edit, then New Certificate, and Save. The new certificate is inactive.
- Download it (Certificate (Base64)) and add it in Tinct's Signing certificates card as the second certificate.
- In Entra ID, make the new certificate active.
- Remove the old certificate in Tinct.