> ## Documentation Index
> Fetch the complete documentation index at: https://docs.sprig.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Microsoft Entra ID

To enable SSO with Microsoft Entra ID, complete the following:

1. Contact [support@sprig.com](mailto:sso@sprig.com) to claim the email domain(s) that your SSO users will use to sign in.
2. Log into your Sprig account and navigate to **Settings >** [**Single Sign-On**](https://app.sprig.com/settings/sso).
3. Select the **SSO Enabled** option, and click **Save**.
4. An **Important Values** section should appear. Copy the value of the **Entity URI** field into the **Issuer URL** field in the **Your Identity Provider** section, and click **Save**. Take note of the Entity URI and the ACS URL values provided by the **Important Values** section, as you will use them in your Microsoft Entra ID client configuration.
5. Log into your Microsoft Entra admin center. Navigate to the Enterprise app page. Click “+ New application” at the top of the page and then “+ Create your own application” in the window that opens on the right.

<img align="center" src="https://mintcdn.com/sprig/_1uWncsTBTa1sJbM/images/c82d36c082338d4fc3a109d34fa5b43623f6c9737fbd4c7783879b5a6378e470-Screenshot_2026-01-15_at_1.21.58_PM.png?fit=max&auto=format&n=_1uWncsTBTa1sJbM&q=85&s=c85511828f2ab862e1cb603a4935b982" width="2572" height="968" data-path="images/c82d36c082338d4fc3a109d34fa5b43623f6c9737fbd4c7783879b5a6378e470-Screenshot_2026-01-15_at_1.21.58_PM.png" />

<img align="center" src="https://mintcdn.com/sprig/_1uWncsTBTa1sJbM/images/ee2402ef15afd094cf91d8dac26df1354e4f86e2609f52fe5040a976536fa5a6-Screenshot_2026-01-15_at_2.37.16_PM.png?fit=max&auto=format&n=_1uWncsTBTa1sJbM&q=85&s=071004194a653504d26efacc9700b3a6" width="2062" height="376" data-path="images/ee2402ef15afd094cf91d8dac26df1354e4f86e2609f52fe5040a976536fa5a6-Screenshot_2026-01-15_at_2.37.16_PM.png" />

6. In the “What’s the name of your app?” field, enter “Sprig” or whatever you would like the application to be called, and select “Integrate any other application you don’t find in the gallery (Non-gallery)” and click Create.

<img align="center" src="https://mintcdn.com/sprig/IibAYOcivdkTylH0/images/39b556c555c634cf9307ca353726b3f939e2c3ff6ba947b2facfc20647c0662a-Screenshot_2026-01-15_at_2.58.42_PM.png?fit=max&auto=format&n=IibAYOcivdkTylH0&q=85&s=eeb711f3a5f9a759338b76628ed5d389" width="1136" height="720" data-path="images/39b556c555c634cf9307ca353726b3f939e2c3ff6ba947b2facfc20647c0662a-Screenshot_2026-01-15_at_2.58.42_PM.png" />

7. Under “Set up single sign on,” click “Get started” and choose SAML.

<img align="center" src="https://mintcdn.com/sprig/IibAYOcivdkTylH0/images/7569482ea168edeb8ab7f3e02bab586c6771ab1c4347daa80eda9d15d00a8cd3-Screenshot_2026-01-15_at_3.00.51_PM.png?fit=max&auto=format&n=IibAYOcivdkTylH0&q=85&s=84a0aabad912d17ae8f356ac1e7da58f" width="732" height="308" data-path="images/7569482ea168edeb8ab7f3e02bab586c6771ab1c4347daa80eda9d15d00a8cd3-Screenshot_2026-01-15_at_3.00.51_PM.png" />

<img align="center" src="https://mintcdn.com/sprig/IibAYOcivdkTylH0/images/6aecb5bd5b652ab03c37c32b65f53d0bba4c978d90bbfad78776d51d78ef5827-Screenshot_2026-01-15_at_3.01.22_PM.png?fit=max&auto=format&n=IibAYOcivdkTylH0&q=85&s=d2c621043bdb1fece218fa0fbd361c61" width="730" height="378" data-path="images/6aecb5bd5b652ab03c37c32b65f53d0bba4c978d90bbfad78776d51d78ef5827-Screenshot_2026-01-15_at_3.01.22_PM.png" />

8. In the Basic SAML Configuration section, click Edit, and:
   1. Paste the Entity URI from the Sprig dashboard into the Identifier (Entity ID) field
   2. Paste the ACS URL into the Reply URL (Assertion Consumer Service URL) field.

<img align="center" src="https://mintcdn.com/sprig/_1uWncsTBTa1sJbM/images/bf33f3953d6e72e4aab9e5ce934ccd52249f20f6a87b3b78d4f7eb38aab2c95d-Screenshot_2026-01-15_at_3.09.24_PM.png?fit=max&auto=format&n=_1uWncsTBTa1sJbM&q=85&s=78fca4487e5bcd33b9b698fd5ef1e587" width="1482" height="412" data-path="images/bf33f3953d6e72e4aab9e5ce934ccd52249f20f6a87b3b78d4f7eb38aab2c95d-Screenshot_2026-01-15_at_3.09.24_PM.png" />

9. Copy the Login URL from section 4 in the Microsoft Entra admin center and paste it into the Entry Point URL field in the Sprig dashboard.
   1. Then, click download next to Certificate (Base64) from section 3 in the Microsoft Entra admin center to download the X.509 certificate.
   2. Open the downloaded certificate in a text editor.
   3. Copy the contents of the certificate, paste it into the X.509 Certificate field in the Sprig dashboard, and click Save.

<img align="center" src="https://mintcdn.com/sprig/8rOBJC6NeyY76ru8/images/9f62fb46600c9e28ea5966927bb748b3c1ba8e3cca2983b151a469315902fc39-Screenshot_2026-01-16_at_10.52.55_AM.png?fit=max&auto=format&n=8rOBJC6NeyY76ru8&q=85&s=f74cc2137d1a0462fbefc5418fbeac7b" width="1418" height="1154" data-path="images/9f62fb46600c9e28ea5966927bb748b3c1ba8e3cca2983b151a469315902fc39-Screenshot_2026-01-16_at_10.52.55_AM.png" />

<img align="center" src="https://mintcdn.com/sprig/IibAYOcivdkTylH0/images/4bd5dd9ac27f7ce9b13c4acd204eec53c51168a3f9567e5b6aab59b6716f5b6a-Screenshot_2026-01-15_at_3.21.24_PM.png?fit=max&auto=format&n=IibAYOcivdkTylH0&q=85&s=ee015ba44be0eaeacfc59b27344c72b6" width="1582" height="1532" data-path="images/4bd5dd9ac27f7ce9b13c4acd204eec53c51168a3f9567e5b6aab59b6716f5b6a-Screenshot_2026-01-15_at_3.21.24_PM.png" />

10. Back in the Microsoft Entra admin center, navigate to the “Users and groups” page to add users or groups to the application. The users or groups that you add will determine which users will be able to use SSO to login to Sprig.

<img align="center" src="https://mintcdn.com/sprig/_1uWncsTBTa1sJbM/images/cb54a51e82b2aa9d44cfa9626ca8d87c4a43f44f4caa60de08f5ac1619a644e7-Screenshot_2026-01-15_at_3.32.17_PM.png?fit=max&auto=format&n=_1uWncsTBTa1sJbM&q=85&s=d6785678fb0cbd3f76fabd5a9dd4f92b" width="2056" height="780" data-path="images/cb54a51e82b2aa9d44cfa9626ca8d87c4a43f44f4caa60de08f5ac1619a644e7-Screenshot_2026-01-15_at_3.32.17_PM.png" />

Users that are assigned to the Microsoft Entra ID application integration will now be able to sign in using the Sprig [SSO login page](https://app.sprig.com/login/sso).
