> For the complete documentation index, see [llms.txt](https://support.docstudio.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://support.docstudio.com/admin-panel/account-settings/how-to-set-up-sso-oauth-2.0-with-azure.md).

# How to set up SSO OAuth 2.0 with Azure

Single Sign-On (SSO) is an authentication method that enables users to securely log in to various applications, platforms, or websites using a single set of credentials. SSO functions based on a trust relationship between a service provider application and an identity provider (IdP) such as Google, Okta, OneLogin, or Microsoft AD FS. This trust is typically established through a certificate exchanged between the IdP and the service provider:

<figure><img src="/files/FPWEIC1NKLeUwueGIjnX" alt=""><figcaption></figcaption></figure>

Benefits of using SSO:

* Users sign in with existing credentials. They type passwords less often.
* Your IdP stays the source of truth for authentication.
* You do not need to sync passwords with the IdP.

In DocStudio, you can configure Single Sign-On to allow employees to access DocStudio through their Identity Provider (IdP), removing the need for passwords during the login process, ensuring secure and quick access.

DocStudio's single sign-on system can be configured using OAuth 2.0.

{% columns %}
{% column %}
In the **'Integrraions'** tab, you can add your SSO providers to set up SSO authentication for corporate users. To **'Create an SSO provider'**, click on the corresponding button and complete the fields in the modal window:
{% endcolumn %}

{% column %}

<figure><img src="/files/CxSxmwamVGBotfsqEhRw" alt=""><figcaption></figcaption></figure>
{% endcolumn %}
{% endcolumns %}

You can choose the type of metadata (URL or XML). After filling out the details, click the <img src="/files/F0ede5xeVlYuP0oLQGBt" alt="" data-size="line"> button.

The providers added this way can be edited or deleted (although deletion requires сonfirmation)

<figure><img src="/files/6EHg1MnDWSiAW88Y7TUM" alt=""><figcaption></figcaption></figure>

### Configuring on the Azure Side

To proceed, register the application in the **Azure Active Directory (Azure AD)** with a corporate identity management administrator account.

<figure><img src="/files/n5PNE1fxPYFSjlHCOegm" alt=""><figcaption></figcaption></figure>

Then navigate to the menu and go to:

**Microsoft Entra ID** → **All applications** → **New application**

<figure><img src="/files/xbSQipB0cTvjpK6FTGDo" alt=""><figcaption></figcaption></figure>

During registration, set:

* Name
* Supported account types
* Redirect URI

{% columns %}
{% column %}
For the redirect URI, use the value shown in DocStudio when you configure the SSO provider.
{% endcolumn %}

{% column %}

<figure><img src="/files/yOXtuibLIxjHzH2u5d2f" alt=""><figcaption></figcaption></figure>
{% endcolumn %}
{% endcolumns %}

Next, create a client secret in Azure.

<figure><img src="/files/kMUt3kKQzrdVhx0kKkrd" alt=""><figcaption></figcaption></figure>

Copy the secret **Value** and paste it into the DocStudio SSO settings field **Client Secret**.

<figure><img src="/files/13FAvubvygzW2mXNsGgX" alt="" width="455"><figcaption></figcaption></figure>

You can find the remaining values in the application's overview.

* Client ID

<figure><img src="/files/9r5xzjhJOfgLb7tTLwOY" alt=""><figcaption></figcaption></figure>

After you click the **Azure** button in DocStudio SSO settings, the required URLs are added automatically.

<figure><img src="/files/k5ZD0BLIxirKHe2QzoNR" alt="" width="375"><figcaption></figcaption></figure>

These URLs contain placeholders like `/{tenant}` and `/common`. Replace them with your Azure **Directory (tenant) ID**.

The SSO provider is created successfully.

{% columns %}
{% column %}
You can verify the setup using the link shown in the settings.
{% endcolumn %}

{% column %}

<figure><img src="/files/5oRb7cZTTBTcSvTaDeSM" alt=""><figcaption></figcaption></figure>
{% endcolumn %}
{% endcolumns %}

Next, enable SSO in the domain settings.

{% hint style="info" %}
Don’t forget to enable access for your users on the Azure side.
{% endhint %}
