Skip to content

Integrate Microsoft Entra ID SSO

Connect Microsoft Entra ID for single sign-on

Connect Microsoft Entra ID (formerly Azure Active Directory) to Tallyfy in about 30 minutes. Your users get automatic login and account creation - no separate passwords needed.

Requirements

  • Microsoft Entra ID administrator access
  • Tallyfy Professional or Enterprise plan
  • SAML config values from Tallyfy Support

What you’ll do

  1. Create a Microsoft Entra ID enterprise application
  2. Configure SAML settings in both systems
  3. Test the connection

How SSO setup works

You, Tallyfy Support, and Microsoft Entra ID work together through a three-party setup.

Diagram

Key points:

  • Steps 1-10 are one-time setup between you and Tallyfy Support
  • Steps 11-15 happen every time someone logs in
  • You can’t skip the support ticket (step 1)

Phase 1: Create enterprise application

Access enterprise applications

  1. Sign in to the Azure Portal with administrator credentials

  2. Go to the Microsoft Entra ID service (may still show as Azure Active Directory in some interfaces)

  3. Select Enterprise Applications from the Manage section

  4. Click +New application

  5. Choose Create your own application

    Azure SSO integration setup view view view

Define application properties

  1. Enter “Tallyfy” as the application name

  2. Select Integrate any other application you don’t find in the gallery (Non-gallery)

  3. Click Create

    Azure SSO integration setup view view view

Assign users (optional)

Assign users now or after setup - your choice:

Azure SSO integration setup view view view

Phase 2: Configure SAML settings

Access SAML configuration

  1. In the application’s sidebar under Manage, select Single sign-on

  2. Choose SAML as the sign-on method

    Azure SSO integration setup view view view

Configure basic SAML settings

  1. Click Edit in the Basic SAML Configuration section.

    Azure SSO integration setup view view view

  2. In Tallyfy, go to your organization profile.

  3. Open the Org Settings tab.

  4. Click Add Configuration Details.

  5. Scroll down to find the default SAML values.

    Azure SSO integration setup view view view Azure SSO integration setup view view view

  6. Copy Tallyfy’s SP ACS URL to Microsoft Entra ID’s Reply URL (Assertion Consumer Service URL) field.

  7. Copy Tallyfy’s SP Entity ID to Microsoft Entra ID’s Identifier (Entity ID) field.

  8. Click Save.

    Azure SSO integration setup view view view

Configure user attributes

These must be exact - wrong names or capitalization will break user sync.

  1. Configure Name Identifier (User ID): Click the Unique User Identifier (Name ID) row.

    Azure SSO integration setup view view view

  2. Select Persistent for Name identifier format.

  3. Choose user.mail for Source attribute.

  4. Click Save.

  5. Configure First Name Attribute: Click the attribute row (typically user.givenname).

    Azure SSO integration setup view view view

  6. Set Name to: FirstName (capitalization matters).

  7. Clear the Namespace field.

  8. Set Source attribute to: user.givenname.

  9. Click Save.

  10. Configure Email attribute: Set Name to Email, clear Namespace, set Source attribute to user.mail. Click Save.

  11. Configure Last Name attribute: Set Name to LastName, clear Namespace, set Source attribute to user.surname. Click Save.

Your final attribute config should look like this:

Azure SSO integration setup view view view

Phase 3: Complete the integration

Get Microsoft Entra ID SAML information

You need three things from Microsoft Entra ID:

  1. Go to the Set up section.

  2. Copy the Login URL.

  3. Copy the Microsoft Entra ID Identifier.

  4. Download the Certificate (Base64) from the SAML Signing Certificate section.

    Azure SSO integration setup view view view

Send information to Tallyfy Support

  1. Send these three items to Tallyfy Support

  2. Tallyfy Support configures your SAML settings on their end

    Azure SSO integration setup view view view

Turn on SAML authentication

After Tallyfy Support confirms everything’s ready:

  1. Turn on the SAML activation toggle

    Azure SSO integration setup view view view

User access

  1. Get your organization’s SSO login URL from the SAML setup modal (Tallyfy Support provides this)

  2. Share this URL with your Microsoft Entra ID users

    Azure SSO integration setup view view view

When users visit this URL:

  • Existing Tallyfy users log in automatically
  • New users get an account created on first login

Troubleshooting

Users can’t log in? Check these:

  1. User is assigned to the Microsoft Entra ID application
  2. Attribute mappings are exact (names and capitalization)
  3. SAML certificate hasn’t expired
  4. Users are using the SSO URL (not regular login)
  5. Still stuck? Contact Tallyfy Support

Authentication > Integrate Okta SSO

Tallyfy integrates with Okta through SAML 2.0 SSO by creating an Okta SAML app and exchanging configuration details with Tallyfy Support so users can authenticate automatically and get accounts provisioned on first login in about 30 minutes.

Integrations > Authentication and SSO

Tallyfy offers free SSO on all paid plans with support for Microsoft Entra ID and Google Workspace and Okta and OneLogin and JumpCloud and any SAML 2.0 provider — letting teams log in with existing corporate credentials while also enabling SSO-based approval audit trails that can replace costly e-signature tools for internal use cases like purchase orders and policy acknowledgments.

Authentication > Integrate OneLogin SSO

Tallyfy integrates with OneLogin through SAML-based Single Sign-On by having an admin create a custom SAML connector in OneLogin and exchange configuration values like ACS URLs and X.509 certificates with Tallyfy Support so that team members can authenticate through a special SSO login URL with automatic provisioning for new users on first access.

Authentication > Integrate JumpCloud SSO

Tallyfy integrates with JumpCloud through SAML-based SSO by creating a custom SAML app in JumpCloud and exchanging identity provider metadata and service provider configuration with Tallyfy Support to enable automatic login and just-in-time user account creation for assigned users.