Skip to main content
Microsoft SSO lets your team sign in to Corsa with their Microsoft work accounts, under your tenant’s MFA, conditional access, and offboarding policies. You create one app registration in Entra ID and send Corsa its details. Corsa connects it to your workspace. Setup takes about 30 minutes on your side. For how SSO sign-in, invitations, and roles work in Corsa, see the SSO overview.

Before you start

You need:
  • An Entra role of Application Administrator, Cloud Application Administrator, or Global Administrator, to create the app registration and grant admin consent
  • Workspace owner access in Corsa, to invite users
  • The email domains your users sign in with (for example, yourcompany.com)
  • Your Corsa region: US (app.corsa.finance) or EU (app.eu.corsa.finance)
  • A secure channel to send Corsa a client secret
Each user’s Microsoft account must have an email address (the mail attribute, or the UPN) that matches the address invited to Corsa.

Set up Microsoft SSO

1

Create the app registration

  1. Sign in to the Microsoft Entra admin center.
  2. Go to Identity → Applications → App registrations → New registration.
  3. Fill in the form:
    • Name: Corsa
    • Supported account types: Accounts in this organizational directory only (Single tenant)
    • Redirect URI: platform Web, with the first URI for your region:
US workspace:
EU workspace:
  1. Click Register. On the Overview page, copy the Application (client) ID and the Directory (tenant) ID.
2

Add the second redirect URI

Open Authentication and add Corsa’s branded sign-in URI for your region:
  • US workspace: https://auth.corsa.finance/login/callback
  • EU workspace: https://auth.eu.corsa.finance/login/callback
Leave Access tokens and ID tokens (implicit grant) unchecked.
3

Create a client secret

  1. Open Certificates & secrets → Client secrets → New client secret.
  2. Choose an expiry (24 months is recommended) and click Add.
  3. Copy the secret’s Value right away. Entra shows it only once. You need the Value, not the Secret ID.
An expired secret blocks every SSO sign-in to your workspace. Set a reminder to rotate it before it expires.
4

Grant API permissions

  1. Open API permissions.
  2. Check that Microsoft Graph → User.Read (Delegated) is listed. Add it if it isn’t.
  3. Click Grant admin consent for your organization, so users aren’t asked for consent on their first sign-in.
5

Limit access to specific users (optional)

  1. Open Enterprise applications → Corsa → Properties.
  2. Set Assignment required? to Yes.
  3. Add users or groups under Users and groups.
6

Send the details to Corsa

Send these to your Corsa representative or support@corsa.finance:
Send the client secret over a secure channel, never in plain email or chat. It grants the same access as a password.
Corsa connects your tenant to your workspace and lets you know when it’s live. Tell Corsa if you also want to require SSO once testing succeeds.
7

Test sign-in

  1. Invite a test user by their exact Microsoft email address, with the role they should have.
  2. In a private browser window, the test user opens app.corsa.finance (or app.eu.corsa.finance).
  3. They click Continue with SSO, enter their work email, and sign in on Microsoft’s page.
  4. They land in your workspace with the invited role. They don’t need to open the invitation link.
Once the test passes, invite the rest of your team the same way.

Troubleshooting

Still stuck? Contact support@corsa.finance with the user’s email, the time of the attempt, and a screenshot of the error, including any AADSTS code and correlation ID.