All Collections
Integrations
Single Sign-on (SSO)
How to configure Microsoft Azure AD Single Sign-on (SSO)
How to configure Microsoft Azure AD Single Sign-on (SSO)

Setup your Microsoft Azure AD Single Sign-on (SSO) in Tanda

Ryan Johnston avatar
Written by Ryan Johnston
Updated over a week ago

Tanda supports single sign-on with Microsoft Azure AD. To configure in Tanda, head to the integrations page.

The following steps will assist in setting up the integration in Azure AD.


  1. To configure the integration, you must have your app administrator (or higher) head to the app registrations page in the Azure portal. You can just search ‘app registration’ in the global search bar

  2. If you haven't configured Tanda yet, click new registration. If you've already completed this, skip to step 7.

  3. In the new app registration page enter the app name 'Tanda'. Some customers like to add ‘web’ after so they know it’s not the mobile app, however, this is optional.

  4. Now choose the supported account types for the AUTHENTICATION (this is how you also set up your Azure AD to auth users into Tanda from your AD)

  5. The following should be your redirect URI: https://my.tanda.co/users/auth/azure_oauth2/callback

  6. Hit register

  7. On completion of reregistering an app, you need to get the Application (client) id from Azure, highlighted below on the overview page of the app

  8. Next, head to branding on the next page and complete the details ensuring the home page URL is filled out with your special URL. This is the most important part. You can then optionally upload one of Tanda's logos.

  9. Your special URL should look like this: https://my.tanda.co/users/preauth/azure_oauth2?company={business_name_here} What comes after company should be nice and simple (ideally the initials of your business name. Don't use any caps or symbols etc. It is not user-facing.

  10. Next go to the authentication menu and make sure the following is true:
    - Redirect URL: https://my.tanda.co/users/auth/azure_oauth2/callback

  11. Now head back into Tanda and enter your client secret and other required details. This page can be found at https://my.tanda.co/integrations/singlesignon (Your company name should be the name you used at the end of your URL earlier in step 9)

  12. You still need to set an application admin/owner/group in Azure (if not complete already) and assign the app to the relevant users or groups.

  • You can assign owner(s) from the owner's tab in the side navigation of Azure

  • You can then add the application to users from the enterprise applications screen which you can search for from the top global search bar in Azure.

Logging in:

In the current state, you will need to access the integration via your Azure Dashboard to SSO into Tanda. You can vote for service provider initiation on the Tanda log-in page by voting for the feature here.

Did this answer your question?