Skip to content

Integrate Microsoft Entra ID SSO

Connect Microsoft Entra ID for single sign-on

Connect Microsoft Entra ID (formerly Azure Active Directory) to Tallyfy in about 30 minutes. Your users get automatic authentication and account creation - no password juggling.

Requirements

  • Microsoft Entra ID access
  • Administrator privileges in Microsoft Entra ID
  • Tallyfy Professional or Enterprise plan
  • SAML configuration values from Tallyfy Support

What you’ll do

  1. Create a Microsoft Entra ID enterprise application
  2. Configure SAML settings in both systems
  3. Test the SSO connection

How SSO setup works

Microsoft Entra ID, Tallyfy Support, and you work together to set up single sign-on.

Diagram

What to notice:

  • Steps 1-10 show the one-time setup between you and Tallyfy Support
  • Steps 11-15 show what happens every time someone logs in
  • You can’t skip the support ticket (step 1)

Phase 1: Create enterprise application

Access enterprise applications

  1. Sign in to the Azure Portal with administrator credentials

  2. Navigate to Microsoft Entra ID service (may still show as Azure Active Directory in some interfaces)

  3. Select Enterprise Applications from the Manage section

  4. Click +New application

  5. Choose Create your own application

    Azure SSO integration setup view view view

Define application properties

  1. Enter “Tallyfy” as the application name

  2. Select Integrate any other application you don’t find in the gallery (Non-gallery)

  3. Click Create

    Azure SSO integration setup view view view

Assign users (optional)

Assign users now or after setup - your choice:

Azure SSO integration setup view view view

Phase 2: Configure SAML settings

Access SAML configuration

  1. In the application’s sidebar under Manage, select Single sign-on

  2. Choose SAML as the sign-on method

    Azure SSO integration setup view view view

Configure basic SAML settings

  1. Click Edit in the Basic SAML Configuration section.

    Azure SSO integration setup view view view

  2. Get Tallyfy’s SAML values from your organization profile in Tallyfy.

  3. Go to Org Settings tab.

  4. Click Add Configuration Details.

  5. Scroll down to find the default SAML values.

    Azure SSO integration setup view view view Azure SSO integration setup view view view

  6. Copy Tallyfy’s SP ACS URL to Microsoft Entra ID’s Reply URL (Assertion Consumer Service URL) field.

  7. Copy Tallyfy’s SP Entity ID to Microsoft Entra ID’s Identifier (Entity ID) field.

  8. Click Save.

    Azure SSO integration setup view view view

Configure user attributes

Get this right or users won’t sync. Here’s each attribute:

  1. Configure Name Identifier (User ID): Click the Unique User Identifier (Name ID) row.

    Azure SSO integration setup view view view

  2. Select Persistent for Name identifier format.

  3. Choose user.mail for Source attribute.

  4. Click Save.

  5. Configure First Name Attribute: Click the attribute row (typically user.givenname).

    Azure SSO integration setup view view view

  6. Set Name to: FirstName (capitalization matters).

  7. Clear the Namespace field.

  8. Set Source attribute to: user.givenname.

  9. Click Save.

  10. Configure Email attribute: Set Name to Email, clear Namespace, set Source attribute to user.mail. Click Save.

  11. Configure Last Name attribute: Set Name to LastName, clear Namespace, set Source attribute to user.surname. Click Save.

Your final attribute configuration should match this:

Azure SSO integration setup view view view

Phase 3: Complete the integration

Get Microsoft Entra ID SAML information

You need three things from Microsoft Entra ID:

  1. Go to the Set up section.

  2. Copy the Login URL.

  3. Copy the Microsoft Entra ID Identifier.

  4. Download the Certificate (Base64) from the SAML Signing Certificate section.

    Azure SSO integration setup view view view

Send information to Tallyfy Support

  1. Send the Microsoft Entra ID SAML information to Tallyfy Support

  2. Tallyfy Support configures your SAML settings

    Azure SSO integration setup view view view

Turn on SAML authentication

After Tallyfy Support confirms everything’s ready:

  1. Turn on the SAML activation toggle

    Azure SSO integration setup view view view

User access

Almost done:

  1. Get your organization’s Tallyfy login URL from the SAML setup modal (Tallyfy Support provides this)

  2. Share this URL with users who have Microsoft Entra ID access

    Azure SSO integration setup view view view

What happens when users visit this URL?

  • Existing Tallyfy users get authenticated instantly
  • New users are created automatically on first login

Troubleshooting

Users can’t log in? Check these:

  1. User is assigned to the Microsoft Entra ID application
  2. Attribute mappings are exact (names and capitalization)
  3. SAML certificate hasn’t expired
  4. Users are using the SSO URL (not regular login)
  5. Still stuck? Contact Tallyfy Support

Integrations > Authentication and SSO

Tallyfy offers free Single Sign-On integration for paid plans connecting to corporate identity systems like Microsoft Entra ID Google Workspace Okta and OneLogin with SSO-only enforcement options that can replace traditional e-signatures for internal approvals while providing enhanced security user experience and centralized access control through automated account provisioning and unified authentication policies.

Authentication > Integrate Okta SSO

Okta SAML/SSO integration with Tallyfy enables secure single sign-on authentication and automatic user provisioning through a collaborative 30-minute setup process that involves creating a SAML application in Okta configuring attribute mappings and working with Tallyfy Support to exchange configuration details.

Authentication > Integrate OneLogin SSO

OneLogin SAML/SSO integration with Tallyfy enables team members to authenticate using their OneLogin credentials through a 30-minute collaborative setup process that involves creating a SAML custom connector application in OneLogin and configuring attribute mappings and exchanging metadata with Tallyfy Support to enable automatic authentication and user provisioning for new accounts on first login.

Authentication > Integrate JumpCloud SSO

JumpCloud SAML/SSO integration with Tallyfy enables automatic user authentication and account creation through a 30-minute setup process involving creating a custom SAML application in JumpCloud configuring attribute mappings for email and name fields and exchanging metadata with Tallyfy Support to complete the single sign-on configuration.