> ## Documentation Index
> Fetch the complete documentation index at: https://docs.corsa.finance/llms.txt
> Use this file to discover all available pages before exploring further.

# Microsoft Entra ID SSO

> Configure Microsoft Entra ID (formerly Azure AD) so your team can sign in to Corsa with their Microsoft work accounts.

Microsoft SSO lets your team sign in to Corsa with their Microsoft work accounts, under your tenant's MFA, conditional access, and offboarding policies. You create one app registration in Entra ID and send Corsa its details. Corsa connects it to your workspace. Setup takes about 30 minutes on your side.

For how SSO sign-in, invitations, and roles work in Corsa, see the [SSO overview](/security/sso).

***

## Before you start

You need:

* An Entra role of **Application Administrator**, **Cloud Application Administrator**, or **Global Administrator**, to create the app registration and grant admin consent
* **Workspace owner** access in Corsa, to invite users
* The email domains your users sign in with (for example, `yourcompany.com`)
* Your Corsa region: **US** (`app.corsa.finance`) or **EU** (`app.eu.corsa.finance`)
* A secure channel to send Corsa a client secret

Each user's Microsoft account must have an email address (the `mail` attribute, or the UPN) that matches the address invited to Corsa.

***

## Set up Microsoft SSO

<Steps>
  <Step title="Create the app registration">
    1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com).
    2. Go to **Identity → Applications → App registrations → New registration**.
    3. Fill in the form:
       * **Name:** `Corsa`
       * **Supported account types:** **Accounts in this organizational directory only (Single tenant)**
       * **Redirect URI:** platform **Web**, with the first URI for your region:

    **US workspace:**

    ```
    https://tweed-compliance.us.auth0.com/login/callback
    ```

    **EU workspace:**

    ```
    https://tweed-compliance.eu.auth0.com/login/callback
    ```

    4. Click **Register**. On the **Overview** page, copy the **Application (client) ID** and the **Directory (tenant) ID**.
  </Step>

  <Step title="Add the second redirect URI">
    Open **Authentication** and add Corsa's branded sign-in URI for your region:

    * US workspace: `https://auth.corsa.finance/login/callback`
    * EU workspace: `https://auth.eu.corsa.finance/login/callback`

    Leave **Access tokens** and **ID tokens** (implicit grant) unchecked.
  </Step>

  <Step title="Create a client secret">
    1. Open **Certificates & secrets → Client secrets → New client secret**.
    2. Choose an expiry (24 months is recommended) and click **Add**.
    3. Copy the secret's **Value** right away. Entra shows it only once. You need the **Value**, not the **Secret ID**.

    <Warning>
      An expired secret blocks every SSO sign-in to your workspace. Set a reminder to rotate it before it expires.
    </Warning>
  </Step>

  <Step title="Grant API permissions">
    1. Open **API permissions**.
    2. Check that **Microsoft Graph → User.Read** (Delegated) is listed. Add it if it isn't.
    3. Click **Grant admin consent for your organization**, so users aren't asked for consent on their first sign-in.
  </Step>

  <Step title="Limit access to specific users (optional)">
    1. Open **Enterprise applications → Corsa → Properties**.
    2. Set **Assignment required?** to **Yes**.
    3. Add users or groups under **Users and groups**.
  </Step>

  <Step title="Send the details to Corsa">
    Send these to your Corsa representative or [support@corsa.finance](mailto:support@corsa.finance):

    | Detail | Where to find it | Example |
    | - | - | - |
    | Application (client) ID | App registration → **Overview** | `your-client-id` |
    | Directory (tenant) ID or primary domain | App registration → **Overview** | `yourcompany.onmicrosoft.com` |
    | Client secret value | Copied in the client secret step | Send securely |
    | Secret expiry date | **Certificates & secrets** | `2028-10-07` |
    | Email domains users sign in with | Your directory | `yourcompany.com` |
    | Corsa workspace name and region | Corsa | Acme Compliance, US |

    <Warning>
      Send the client secret over a secure channel, never in plain email or chat. It grants the same access as a password.
    </Warning>

    Corsa connects your tenant to your workspace and lets you know when it's live. Tell Corsa if you also want to [require SSO](/security/sso#users-roles-and-security) once testing succeeds.
  </Step>

  <Step title="Test sign-in">
    1. Invite a test user by their exact Microsoft email address, with the role they should have.
    2. In a private browser window, the test user opens `app.corsa.finance` (or `app.eu.corsa.finance`).
    3. They click **Continue with SSO**, enter their work email, and sign in on Microsoft's page.
    4. They land in your workspace with the invited role. They don't need to open the invitation link.

    Once the test passes, invite the rest of your team the same way.
  </Step>
</Steps>

***

## Troubleshooting

| What the user sees | Likely cause | Fix |
| - | - | - |
| A password screen instead of Microsoft after entering their email | Corsa doesn't have that email domain on file | Send Corsa the missing domain |
| Microsoft error `AADSTS50011` (redirect URI mismatch) | A redirect URI is missing or mistyped | Add both URIs for your region exactly as shown |
| Microsoft error `AADSTS7000215` or `AADSTS7000222` | The client secret is wrong or has expired | Create a new secret and send its **Value** to Corsa securely |
| Microsoft error `AADSTS65001`, or a consent prompt | Admin consent wasn't granted | **API permissions → Grant admin consent** |
| Microsoft error `AADSTS50105` | Assignment is required and the user isn't assigned | Assign the user or their group under **Enterprise applications → Corsa → Users and groups** |
| Corsa page "No workspace access yet" | No pending invitation for this exact email | Invite that exact email from your workspace |
| Corsa page "You are signed in with a different email than the one invited" | The Microsoft email differs from the invited address, for example an alias | Invite the address Microsoft returns (`mail`, or the UPN if `mail` is empty) |
| A sign-in error with email and password or Google | SSO is required for your workspace | Use **Continue with SSO** |

Still stuck? Contact [support@corsa.finance](mailto:support@corsa.finance) with the user's email, the time of the attempt, and a screenshot of the error, including any `AADSTS` code and correlation ID.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.