# Set up SSO with Microsoft Entra ID (/docs/support/security/single-sign-on/set-up-sso-with-microsoft-entra-id)

You can connect Microsoft Entra ID to Circleback by creating a custom SAML application in the Entra admin center.

You need access to manage enterprise applications in Entra and to be an admin of your Circleback workspace. Before you start, check the requirements in [Set up single sign-on](/docs/support/security/single-sign-on/sso).

1\. In Circleback, go to Settings → General (under Workspace).

2\. Under **Single sign-on**, select **Connect**. Choose **SAML**, then select **Continue**. Keep this form open.

3\. In another tab, open the Entra admin center and go to **Enterprise applications**.

Microsoft Entra ID: Enterprise applications

4\. Select **New application** → **Create your own application**.

Microsoft Entra ID: New application

5\. Enter **Circleback** as the name and choose to integrate an application you don't find in the gallery.

6\. Select **Create**.

Microsoft Entra ID: Create your own application

7\. Open the application, select **Single sign-on** under **Manage**, then choose **SAML**.

Microsoft Entra ID: choose SAML single sign-on

8\. In Entra, under **Basic SAML Configuration**, select **Edit**. Copy the **Entity ID** and **ACS URL** from the open Circleback form into the fields below:

Microsoft Entra ID: edit Basic SAML Configuration

| Field                                      | Value                                      |
| ------------------------------------------ | ------------------------------------------ |
| Identifier (Entity ID)                     | `https://circleback.ai/api/sso/metadata`   |
| Reply URL (Assertion Consumer Service URL) | `https://circleback.ai/api/sso/oauth/saml` |

9\. Select **Save**.

Microsoft Entra ID: Identifier and Reply URL fields; use the Circleback URLs above

10\. Under **Attributes & Claims**, select **Edit**.

Microsoft Entra ID: edit Attributes and Claims

11\. Set **Unique User Identifier (Name ID)** to the email your team member uses in Circleback, with the **Email address** format. Use `user.mail` if it contains that email for each assigned user. Only use `user.userprincipalname` if it matches their Circleback email.

12\. Check these claims and add any that are missing:

| Claim                                                                | Source attribute |
| -------------------------------------------------------------------- | ---------------- |
| `http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress` | `user.mail`      |
| `http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname`    | `user.givenname` |
| `http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname`      | `user.surname`   |

The email claim must also match the member's Circleback email. If you use a different source attribute for their email, use it for both the email claim and Name ID.

13\. Save your changes.

Microsoft Entra ID: example attribute claims; follow the email mapping instructions above

14\. Return to **Single sign-on** in Entra. Under **SAML Signing Certificate**, download **Federation Metadata XML**.

Microsoft Entra ID: download Federation Metadata XML

15\. In the open Circleback form, under **Metadata source**, choose **Upload XML file** and upload the file you downloaded.

16\. In Entra, open **Users and groups** in the application.

17\. Select **Add user/group** and choose the people or groups that should use Circleback.

18\. Select **Assign**.

19\. Return to Circleback and select **Continue**. Leave **No directory sync** selected for sign-in only, or select **Microsoft Entra ID** if you plan to set up SCIM provisioning. Select **Connect**.

If you selected Microsoft Entra ID for directory sync, use the credentials shown in Circleback to [set up directory sync](/docs/support/security/single-sign-on/sso).

To require everyone in your workspace to log in with SSO, follow [Enforce SSO for your workspace](/docs/support/security/single-sign-on/sso).