Single Sign-On

Single Sign-On (Microsoft Entra ID)

Overview

DigiUsher supports Single Sign-On (SSO) with Microsoft Entra ID. It uses OpenID Connect, a standard that lets your users sign in with the account of another identity provider. To enable SSO, register an application in Entra ID. Then send three values to DigiUsher: the Application (client) ID, the Directory (tenant) ID, and a client secret.

SSO is optional. If you do not want SSO, your users can continue with the DigiUsher login.


Prerequisites

You need an account that can register applications in Microsoft Entra ID. If your tenant restricts consent, you also need the right to grant admin consent. Read the note in Admin consent.


Manual Setup

Register a new application

  1. Go to Microsoft Entra ID → App registrations → New registration.
  2. Enter DigiUsher as the Name, or another name that your team knows.
  3. Select "Accounts in this organizational directory only" as the Supported account types.
  4. Select Web as the Redirect URI platform.
  5. Enter the Redirect URI value. The template is:
https://<your-digiusher-auth-domain>/realms/DigiUsher/broker/<your-broker-id>/endpoint
  1. Click Register.

DigiUsher provides your exact redirect URI

The redirect URI is specific to your account. It changes with the region and the instance, and a regional deployment uses a regional auth domain. DigiUsher gives you the exact redirect URI during onboarding. Use that value in place of the template.

Make sure that the platform is Web, and not SPA

Azure sometimes selects the Single-page application platform for the redirect URI. DigiUsher needs the Web platform.

  1. Open the Authentication blade.
  2. If the page shows a Single-page application platform, remove it.
  3. Click Add a platform → Web, and enter the redirect URI from step 1.

Add Microsoft Graph permissions

  1. Go to API permissions → Add a permission → Microsoft Graph → Delegated permissions.
  2. Add email, openid, profile, and User.Read.
  3. If your tenant needs admin consent, click Grant admin consent for <your directory>.

Create a client secret

  1. Go to Certificates & secrets → New client secret.
  2. Copy the Value of the secret immediately. Entra ID shows it one time only.

Copy the Value, not the Secret ID

CAUTION: Copy the Value before you leave the page. You cannot read the Value again. If you lose it, create a new secret.

Collect the IDs

Open the Overview page and note these two values:

  • Application (client) ID
  • Directory (tenant) ID

Send the details to DigiUsher

Send these three values to DigiUsher:

  • Application (client) ID
  • Directory (tenant) ID
  • Client secret

Share the secret securely

CAUTION: Do not send the client secret in a plain email. Use a one-time secret service such as Onetimesecret to create a link that destroys itself. Then send that link to DigiUsher.


What to Send DigiUsher

FieldWhere to Find
Application (client) IDApp registration → Overview
Directory (tenant) IDApp registration → Overview
Client SecretThe Value copied in Create a client secret

Restricted tenants

Some tenants restrict user consent. This is common in regulated environments. In such a tenant, a user can get a "Need admin approval" prompt at the first sign-in. An Entra admin must then grant admin consent one time for the application, in Enterprise applications → DigiUsher → Permissions → Grant admin consent.

The application asks only for sign-in and for read access to the basic profile (email, openid, profile, User.Read). It has no write access.


Need Help?

If this page does not answer your question, write to DigiUsher support at support@digiusher.com. The team will help you.

On this page