> ## Documentation Index
> Fetch the complete documentation index at: https://docs.rdrive.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Setting up SSO - Azure AD

> Login to RDrive Company Level

# This article shows you how to add an Azure AD as an Identity Provider for SSO (Single Sign-on).

1. [Setting up Azure AD for SSO:](#setting-up-azure-ad-for-sso%3a)
2. [Create user:](#create-user%3a)
3. [Edit the newly created user:](#edit-the-newly-created-user%3a)
4. [Register RDrive as an application:](#register-rdrive-as-an-application%3a)
5. [Create a new client secret:](#create-a-new-client-secret%3a)
6. [Token configuration:](#token-configuration%3a)
7. [Back to Overview:](#back-to-overview%3a)

***

## Setting up Azure AD for SSO:

1. Login to RDrive Company Level

2. From the navigation menu choose: Security > OpenID

<img src="https://mintcdn.com/rdrive/NmCVs01a8HNGcruc/images/kb/103000035008/aB5X-ShUDFwn1k5MYG_nbkrE59G0UtzdwA.png?fit=max&auto=format&n=NmCVs01a8HNGcruc&q=85&s=bd3e3bcd89d12a8cfb9db9debdd51d8b" alt="Setting up SSO - Azure AD" width="302" height="350" data-path="images/kb/103000035008/aB5X-ShUDFwn1k5MYG_nbkrE59G0UtzdwA.png" />

3\. Choose 'Add Identity Provider' using the + button.

<img src="https://mintcdn.com/rdrive/NmCVs01a8HNGcruc/images/kb/103000035008/IiSn6Y0A5TaWwsTPMruMWL6taor9DZGnkA.png?fit=max&auto=format&n=NmCVs01a8HNGcruc&q=85&s=be9be69c89d89eacfe7ad8221fdcb239" alt="Setting up SSO - Azure AD" width="627" height="575" data-path="images/kb/103000035008/IiSn6Y0A5TaWwsTPMruMWL6taor9DZGnkA.png" />

4\. Copy the callback URL.

Next please log in to your Azure for the following process.

***

## Create user:

1. Go to the active directory page.

2. Users from the left side menu.

3. Create new user, not invite, so that the user is managed by the Azure AD.

4. **Fill in the First name and Last name!** These are mandatory information for Okta to create a new user.

<img src="https://mintcdn.com/rdrive/NmCVs01a8HNGcruc/images/kb/103000035008/HIPIX_4ypeOSsq6R9pXr-fh46xzq0H24CQ.png?fit=max&auto=format&n=NmCVs01a8HNGcruc&q=85&s=7642c28c6d41507fed2580be550dc50c" alt="Setting up SSO - Azure AD" width="940" height="792" data-path="images/kb/103000035008/HIPIX_4ypeOSsq6R9pXr-fh46xzq0H24CQ.png" />

***

## Edit the newly created user:

<img src="https://mintcdn.com/rdrive/NmCVs01a8HNGcruc/images/kb/103000035008/cQ9ng07X2stimMBw5s2Izu-nxOnLRbaf_g.png?fit=max&auto=format&n=NmCVs01a8HNGcruc&q=85&s=ea26c6e384d8e3be5f7540e782b1303b" alt="Setting up SSO - Azure AD" width="896" height="335" data-path="images/kb/103000035008/cQ9ng07X2stimMBw5s2Izu-nxOnLRbaf_g.png" />

1. Click Edit to allow editing.

2. Fill in the Email field.

3. Save changes (right to the Edit button).

<img src="https://mintcdn.com/rdrive/NmCVs01a8HNGcruc/images/kb/103000035008/DN0wu-sJAw82M6HkayyZQYYHx7VSP_yBjg.png?fit=max&auto=format&n=NmCVs01a8HNGcruc&q=85&s=20c9bc56473b6e02a7ba646e320ba36a" alt="Setting up SSO - Azure AD" width="940" height="751" data-path="images/kb/103000035008/DN0wu-sJAw82M6HkayyZQYYHx7VSP_yBjg.png" />

***

## Register RDrive as an application:

1. Back to the active directory page. Click **App registrations** from the menu on the left-hand side.

2. **New registration.**

3. Create a new APP, and name it. Leave the redirect URI blank, will add one later.

   <img src="https://mintcdn.com/rdrive/NmCVs01a8HNGcruc/images/kb/103000035008/CRwc0JXv4BXJskp2hmGPi6WfdkLc1SZzmg.png?fit=max&auto=format&n=NmCVs01a8HNGcruc&q=85&s=11f24afe9823ed11006910b4a44c6492" alt="Setting up SSO - Azure AD" width="940" height="739" data-path="images/kb/103000035008/CRwc0JXv4BXJskp2hmGPi6WfdkLc1SZzmg.png" />

4. Go to Overview of the newly created APP.

5. **Copy** the client ID, and store it for later use.

<img src="https://mintcdn.com/rdrive/NmCVs01a8HNGcruc/images/kb/103000035008/gpYZXuXlkNtOWOXeFYCG59ptzyj4EQwXZQ.png?fit=max&auto=format&n=NmCVs01a8HNGcruc&q=85&s=3b5378c84f26deff41942730d9add271" alt="Setting up SSO - Azure AD" width="940" height="832" data-path="images/kb/103000035008/gpYZXuXlkNtOWOXeFYCG59ptzyj4EQwXZQ.png" />

***

## Create a new client secret:

1. Click **Certificates & secrets**

2. Create a **New client secret.**

   <img src="https://mintcdn.com/rdrive/NmCVs01a8HNGcruc/images/kb/103000035008/E0zslc2myjIKGb7GNU0wC0n55deHRZaQTg.png?fit=max&auto=format&n=NmCVs01a8HNGcruc&q=85&s=223298274c69c38c53411f528c5e3d00" alt="Setting up SSO - Azure AD" width="940" height="784" data-path="images/kb/103000035008/E0zslc2myjIKGb7GNU0wC0n55deHRZaQTg.png" />

3. Copy the circled value, and store it for later use. (✨The secret is shown only once)

<img src="https://mintcdn.com/rdrive/NmCVs01a8HNGcruc/images/kb/103000035008/7ftpWkDbnbtzP99hDcrqYLs4okvYnkmR9w.png?fit=max&auto=format&n=NmCVs01a8HNGcruc&q=85&s=7cc4823383651eae1cec540999e3e1ae" alt="Setting up SSO - Azure AD" width="940" height="493" data-path="images/kb/103000035008/7ftpWkDbnbtzP99hDcrqYLs4okvYnkmR9w.png" />

***

## Token configuration:

1. Add optional claims to the ID token.

   (Options are shown only when you check the ID button.)

   <img src="https://mintcdn.com/rdrive/NmCVs01a8HNGcruc/images/kb/103000035008/aQ9Lmdlmjl1yJFfqRPCrRvL2t5gJCs4Hjg.png?fit=max&auto=format&n=NmCVs01a8HNGcruc&q=85&s=d85a8570d7c9e1931735b1a49bd0b487" alt="Setting up SSO - Azure AD" width="940" height="449" data-path="images/kb/103000035008/aQ9Lmdlmjl1yJFfqRPCrRvL2t5gJCs4Hjg.png" />

2. Upon clicking Add, it asks you to add the required permission. Check the box to agree.

<img src="https://mintcdn.com/rdrive/NmCVs01a8HNGcruc/images/kb/103000035008/IEN2cjWxgG9IujZbkfeJpNAopaDdBbm4Xg.png?fit=max&auto=format&n=NmCVs01a8HNGcruc&q=85&s=5498eb9f70339016e66842fe50c197e1" alt="Setting up SSO - Azure AD" width="940" height="449" data-path="images/kb/103000035008/IEN2cjWxgG9IujZbkfeJpNAopaDdBbm4Xg.png" />

***

## Back to Overview:

1. Go to Overview of the APP.

2. Endpoints

3. Get the OpenID configuration URI.

<img src="https://mintcdn.com/rdrive/NmCVs01a8HNGcruc/images/kb/103000035008/0niizKT0BeZEj1xvy1FULZix3_J9M81aHA.png?fit=max&auto=format&n=NmCVs01a8HNGcruc&q=85&s=ef99ba5fbd3f953e7ead3fb47f0b6eb9" alt="Setting up SSO - Azure AD" width="940" height="359" data-path="images/kb/103000035008/0niizKT0BeZEj1xvy1FULZix3_J9M81aHA.png" />

4\. Back to RDrive and now add a 'Title' (in case you have multiple identity providers), OpenID configuration URI, ClientID & Client secret.

5\. When this is complete you can click 'Ok'

Your new identity provider is now available to select from the dropdown list when adding or updating a User.

<img src="https://mintcdn.com/rdrive/NmCVs01a8HNGcruc/images/kb/103000035008/6kw1tBSqK6r8DMfXaJ8dbPy64HTaADRRBQ.png?fit=max&auto=format&n=NmCVs01a8HNGcruc&q=85&s=bede58d8cbafdc02098fff9fffde86d3" alt="Setting up SSO - Azure AD" width="520" height="246" data-path="images/kb/103000035008/6kw1tBSqK6r8DMfXaJ8dbPy64HTaADRRBQ.png" />
