SSO is available on Enterprise plans.
How users are managed
- Users sign in with Entra ID. Corridor creates their account on first sign-in.
- If you invited someone, they get the role you chose. Everyone else on your verified domain joins as a Standard User.
- When someone leaves, remove them on the Corridor Teams page too. Removing them in Entra ID alone keeps them on your team.
Prerequisites
- An Entra ID role that can register applications and grant admin consent, such as Application Administrator or Cloud Application Administrator.
- The email domains your users sign in with (for example,
example.com).
Setup
To set up Corridor SSO with Microsoft Entra ID for your organization, follow these steps:1
Register an application
In the Microsoft Entra admin center, go to Identity > Applications > App registrations and click New registration.Click Register.
- Name:
Corridor(or any name your users will recognize). - Supported account types: Accounts in this organizational directory only (Single tenant).
- Redirect URI: select Web and enter:
2
Copy the application details
On the app’s Overview page, copy the Application (client) ID. Also note your directory’s primary domain (for example,
example.com or example.onmicrosoft.com), shown on the Overview page of Entra ID.3
Create a client secret
Go to Certificates & secrets > Client secrets and click New client secret. Copy the secret’s Value right away. Entra ID shows it only once. The Secret ID is not needed by Corridor.
4
Grant API permissions
Go to API permissions. Confirm that Microsoft Graph > User.Read (delegated) is listed. Then click Grant admin consent for <your organization>, so users don’t see a consent prompt on first sign-in.
5
Check user email addresses
Corridor identifies users by email address. Make sure each user has the Email property set to their work address in Entra ID. It must match the address you invite them with in Corridor.
6
Control who can sign in (optional)
By default, any user in your directory can sign in. To limit access, go to Enterprise applications, open the Corridor app, and set Assignment required? to Yes under Properties. Then add the users or groups under Users and groups.
7
Complete setup with Corridor
Contact the Corridor team to finish enabling SSO and share your credentials over a secure channel.
- Email support@corridor.dev to start the SSO setup. Include your Entra ID domain and the email domains your users sign in with. Do not include your Client ID or Client Secret in the email.
- The Corridor team will arrange a secure, encrypted channel (for example, a one-time secret-sharing link) for you to send your Application (client) ID and Client Secret.
- Share your Application (client) ID and Client Secret only through that secure channel to complete the setup.