Set up single sign-on with Microsoft Entra ID
Tabs
FormCan connects to Microsoft Entra ID (formerly Azure AD) with OpenID Connect or SAML 2.0. OpenID Connect uses an app registration; SAML 2.0 uses an enterprise application and gives members a tile in My Apps.
For an overview of the Single Sign-On page, see Single sign-on (SSO).
Before you begin
- You are an Entra administrator who can register applications.
- In FormCan, you are the team owner or a member with the Manage members access.
- In FormCan, open your team menu and select Single Sign-On. On the Connection tab, pick Microsoft Entra ID and the protocol you prefer. Keep this page open: it shows the values Entra needs, each with a Copy button.
Option 1: OpenID Connect
In the Microsoft Entra admin center
-
Go to Identity > Applications > App registrations and click New registration.
-
Enter a name, for example
FormCan. Under Supported account types, select Accounts in this organizational directory only. -
Under Redirect URI, choose the platform Web and paste the Sign-in redirect URI from FormCan. Click Register.
-
On the Overview page, copy the Application (client) ID and the Directory (tenant) ID.
-
Go to Certificates & secrets, click New client secret, and copy the secret Value at once. It is shown only once.
NoteCopy the Value of the secret, not the Secret ID. Note the expiry date: when the secret expires, sign-in stops until you paste a new one in FormCan.
-
Under API permissions, the default User.Read is enough. Click Grant admin consent so members do not see a consent prompt.
In FormCan
-
Under 3. Values from your identity provider, enter the Issuer URL:
https://login.microsoftonline.com/your-tenant-id/v2.0, with your Directory (tenant) ID in place ofyour-tenant-id. -
Paste the Application (client) ID as the Client ID, and the secret Value as the Client secret.
-
Click Save connection.
Option 2: SAML 2.0
In the Microsoft Entra admin center
-
Go to Identity > Applications > Enterprise applications and click New application, then Create your own application.
-
Enter a name, for example
FormCan, select Integrate any other application you don’t find in the gallery, and click Create. -
Open Single sign-on and select SAML.
-
Edit Basic SAML Configuration:
- Identifier (Entity ID): the Entity ID from FormCan.
- Reply URL (Assertion Consumer Service URL): the ACS URL from FormCan.
- Sign on URL (optional): the Start URL from FormCan.
Click Save.
-
Leave Attributes & Claims at the defaults. FormCan recognises the email, given name and surname claims Entra sends when you pick Microsoft Entra ID as the provider.
-
Under SAML Certificates, copy the App Federation Metadata Url.
-
Under Users and groups, assign the people or groups who may sign in.
In FormCan
-
Under 3. Values from your identity provider, paste the App Federation Metadata Url into Metadata URL and click Load from metadata. FormCan fills in the entity ID, the sign-on URL and the signing certificate.
-
Check the values and click Save connection.
Verify your domain, test and turn on
-
On the Email domains tab, add your company domain, create the TXT record FormCan shows at your DNS provider, and click Verify.
-
In the status card, click Test connection. A window signs you in through Entra ID and shows the email, name and claim names FormCan received.
-
Click Turn on single sign-on.
Members can now click SSO on the FormCan login page, open the start URL, or use the FormCan tile in My Apps. See Sign-in rules to require single sign-on or to let new members join automatically.
Good to know
- Users without a mailbox: when Entra sends no email claim, FormCan uses the user principal name as the email address. It must be on one of your verified domains.
- Guest users: a guest’s address is usually on another domain, so the sign-in is refused unless you verify that domain too.
Troubleshooting
| What you see | What to check |
|---|---|
| AADSTS50011 | The redirect URI or reply URL in Entra differs from the value on the FormCan page. |
| AADSTS700016, or “Invalid audience” | The client ID or the entity ID does not match. |
| AADSTS50105 | The user is not assigned to the enterprise application. |
| “The identity provider returned a token we could not verify.” | The client secret has expired, or the Secret ID was pasted instead of the Value. |
| “The identity provider sent an email at @example.com, which is not one of your verified domains.” | The account’s email or user principal name is on a domain you have not verified. |