> ## Documentation Index
> Fetch the complete documentation index at: https://docs.corridor.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# SSO & Microsoft Entra ID

> Set up single sign-on with Microsoft Entra ID (formerly Azure AD) for your Corridor enterprise account.

<Note>
  SSO is available on **Enterprise** plans.
</Note>

Corridor supports SSO with Microsoft Entra ID (formerly Azure Active Directory) for customers on an enterprise plan. Corridor connects to Entra ID over OpenID Connect.

## How users are managed

* Users sign in with Entra ID. Corridor creates their account on first sign-in.
* If you invited someone, they get the role you chose. Everyone else on your [verified domain](/onboarding/adding-team-members#domain-verification) joins as a **Standard User**.
* When someone leaves, remove them on the Corridor **Teams** page too. Removing them in Entra ID alone keeps them on your team.

## Prerequisites

* An Entra ID role that can register applications and grant admin consent, such as **Application Administrator** or **Cloud Application Administrator**.
* The email domains your users sign in with (for example, `example.com`).

## Setup

To set up Corridor SSO with Microsoft Entra ID for your organization, follow these steps:

<Steps>
  <Step title="Register an application">
    In the [Microsoft Entra admin center](https://entra.microsoft.com), go to **Identity** > **Applications** > **App registrations** and click **New registration**.

    * **Name:** `Corridor` (or any name your users will recognize).
    * **Supported account types:** **Accounts in this organizational directory only (Single tenant)**.
    * **Redirect URI:** select **Web** and enter:

    ```text theme={null}
    https://auth.corridor.dev/login/callback
    ```

    Click **Register**.
  </Step>

  <Step title="Copy the application details">
    On the app's **Overview** page, copy the **Application (client) ID**. Also note your directory's primary domain (for example, `example.com` or `example.onmicrosoft.com`), shown on the **Overview** page of Entra ID.
  </Step>

  <Step title="Create a client secret">
    Go to **Certificates & secrets** > **Client secrets** and click **New client secret**. Copy the secret's **Value** right away. Entra ID shows it only once. The **Secret ID** is not needed by Corridor.

    <Warning>
      The secret **Value** is sensitive. Don't store it in plain text, or share it over email, chat, or tickets. Keep it in a password manager or secrets vault until you send it to Corridor in the last step.
    </Warning>

    <Tip>
      Note the secret's expiry date. Send Corridor a new secret before it expires, or your users can't sign in.
    </Tip>
  </Step>

  <Step title="Grant API permissions">
    Go to **API permissions**. Confirm that **Microsoft Graph** > **User.Read** (delegated) is listed. Then click **Grant admin consent for \<your organization>**, so users don't see a consent prompt on first sign-in.
  </Step>

  <Step title="Check user email addresses">
    Corridor identifies users by email address. Make sure each user has the **Email** property set to their work address in Entra ID. It must match the address you invite them with in Corridor.
  </Step>

  <Step title="Control who can sign in (optional)">
    By default, any user in your directory can sign in. To limit access, go to **Enterprise applications**, open the Corridor app, and set **Assignment required?** to **Yes** under **Properties**. Then add the users or groups under **Users and groups**.
  </Step>

  <Step title="Complete setup with Corridor">
    Contact the Corridor team to finish enabling SSO and share your credentials over a secure channel.

    <Warning>
      Never send your **Client Secret** over email, chat, or any other unencrypted channel. Email inboxes are not secure storage, and secrets shared this way can be retained indefinitely and later exposed.
    </Warning>

    1. Email [support@corridor.dev](mailto:support@corridor.dev) to start the SSO setup. Include your **Entra ID domain** and the email domains your users sign in with. Do **not** include your Client ID or Client Secret in the email.
    2. The Corridor team will arrange a secure, encrypted channel (for example, a one-time secret-sharing link) for you to send your **Application (client) ID** and **Client Secret**.
    3. Share your **Application (client) ID** and **Client Secret** only through that secure channel to complete the setup.
  </Step>
</Steps>

## Additional resources

You can also view [Microsoft's documentation](https://learn.microsoft.com/en-us/entra/identity-platform/quickstart-register-app) for full instructions on registering an application.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.