Before you start
You need:- An Entra role of Application Administrator, Cloud Application Administrator, or Global Administrator, to create the app registration and grant admin consent
- Workspace owner access in Corsa, to invite users
- The email domains your users sign in with (for example,
yourcompany.com) - Your Corsa region: US (
app.corsa.finance) or EU (app.eu.corsa.finance) - A secure channel to send Corsa a client secret
mail attribute, or the UPN) that matches the address invited to Corsa.
Set up Microsoft SSO
1
Create the app registration
- Sign in to the Microsoft Entra admin center.
- Go to Identity → Applications → App registrations → New registration.
- Fill in the form:
- Name:
Corsa - Supported account types: Accounts in this organizational directory only (Single tenant)
- Redirect URI: platform Web, with the first URI for your region:
- Name:
- Click Register. On the Overview page, copy the Application (client) ID and the Directory (tenant) ID.
2
Add the second redirect URI
Open Authentication and add Corsa’s branded sign-in URI for your region:
- US workspace:
https://auth.corsa.finance/login/callback - EU workspace:
https://auth.eu.corsa.finance/login/callback
3
Create a client secret
- Open Certificates & secrets → Client secrets → New client secret.
- Choose an expiry (24 months is recommended) and click Add.
- Copy the secret’s Value right away. Entra shows it only once. You need the Value, not the Secret ID.
4
Grant API permissions
- Open API permissions.
- Check that Microsoft Graph → User.Read (Delegated) is listed. Add it if it isn’t.
- Click Grant admin consent for your organization, so users aren’t asked for consent on their first sign-in.
5
Limit access to specific users (optional)
- Open Enterprise applications → Corsa → Properties.
- Set Assignment required? to Yes.
- Add users or groups under Users and groups.
6
Send the details to Corsa
Send these to your Corsa representative or support@corsa.finance:
Corsa connects your tenant to your workspace and lets you know when it’s live. Tell Corsa if you also want to require SSO once testing succeeds.
7
Test sign-in
- Invite a test user by their exact Microsoft email address, with the role they should have.
- In a private browser window, the test user opens
app.corsa.finance(orapp.eu.corsa.finance). - They click Continue with SSO, enter their work email, and sign in on Microsoft’s page.
- They land in your workspace with the invited role. They don’t need to open the invitation link.
Troubleshooting
Still stuck? Contact support@corsa.finance with the user’s email, the time of the attempt, and a screenshot of the error, including any
AADSTS code and correlation ID.