Skip to main content
SSO is available on Enterprise plans.
Corridor supports SSO with Microsoft Entra ID (formerly Azure Active Directory) for customers on an enterprise plan. Corridor connects to Entra ID over OpenID Connect.

How users are managed

  • Users sign in with Entra ID. Corridor creates their account on first sign-in.
  • If you invited someone, they get the role you chose. Everyone else on your verified domain joins as a Standard User.
  • When someone leaves, remove them on the Corridor Teams page too. Removing them in Entra ID alone keeps them on your team.

Prerequisites

  • An Entra ID role that can register applications and grant admin consent, such as Application Administrator or Cloud Application Administrator.
  • The email domains your users sign in with (for example, example.com).

Setup

To set up Corridor SSO with Microsoft Entra ID for your organization, follow these steps:
1

Register an application

In the Microsoft Entra admin center, go to Identity > Applications > App registrations and click New registration.
  • Name: Corridor (or any name your users will recognize).
  • Supported account types: Accounts in this organizational directory only (Single tenant).
  • Redirect URI: select Web and enter:
Click Register.
2

Copy the application details

On the app’s Overview page, copy the Application (client) ID. Also note your directory’s primary domain (for example, example.com or example.onmicrosoft.com), shown on the Overview page of Entra ID.
3

Create a client secret

Go to Certificates & secrets > Client secrets and click New client secret. Copy the secret’s Value right away. Entra ID shows it only once. The Secret ID is not needed by Corridor.
The secret Value is sensitive. Don’t store it in plain text, or share it over email, chat, or tickets. Keep it in a password manager or secrets vault until you send it to Corridor in the last step.
Note the secret’s expiry date. Send Corridor a new secret before it expires, or your users can’t sign in.
4

Grant API permissions

Go to API permissions. Confirm that Microsoft Graph > User.Read (delegated) is listed. Then click Grant admin consent for <your organization>, so users don’t see a consent prompt on first sign-in.
5

Check user email addresses

Corridor identifies users by email address. Make sure each user has the Email property set to their work address in Entra ID. It must match the address you invite them with in Corridor.
6

Control who can sign in (optional)

By default, any user in your directory can sign in. To limit access, go to Enterprise applications, open the Corridor app, and set Assignment required? to Yes under Properties. Then add the users or groups under Users and groups.
7

Complete setup with Corridor

Contact the Corridor team to finish enabling SSO and share your credentials over a secure channel.
Never send your Client Secret over email, chat, or any other unencrypted channel. Email inboxes are not secure storage, and secrets shared this way can be retained indefinitely and later exposed.
  1. Email support@corridor.dev to start the SSO setup. Include your Entra ID domain and the email domains your users sign in with. Do not include your Client ID or Client Secret in the email.
  2. The Corridor team will arrange a secure, encrypted channel (for example, a one-time secret-sharing link) for you to send your Application (client) ID and Client Secret.
  3. Share your Application (client) ID and Client Secret only through that secure channel to complete the setup.

Additional resources

You can also view Microsoft’s documentation for full instructions on registering an application.