Microsoft Entra ID
This guide sets up SAML single sign-on from Microsoft Entra ID (formerly
Azure AD), then optional SCIM provisioning so Entra manages who has access.
You’ll need an Entra role that can create enterprise applications (Cloud
Application Administrator or Global Administrator) and a Twelfth workspace
owner or admin. Read Single sign-on & SCIM first
if you haven’t.
1. Create the enterprise application
- In the Entra admin centre, open Identity →
Applications → Enterprise applications → New application. - Choose Create your own application, name it Twelfth, select
Integrate any other application you don’t find in the gallery
(Non-gallery), and create it. - In the new application, open Single sign-on → SAML.
2. Paste Twelfth’s details into Entra
In Twelfth, open Settings → Workspace → Security & SSO → Single sign-on. Under Create the
app in your identity provider you’ll find the values below, each with a copy
button. In Entra’s Basic SAML Configuration panel, set:
| Entra field | Twelfth value |
|---|---|
| Identifier (Entity ID) | Identifier (Entity ID) from the panel |
| Reply URL (Assertion Consumer Service URL) | Reply URL (Assertion Consumer Service) from the panel |
| Sign on URL | https://twelfth.ai/login (optional) |
Save. Leave Attributes & Claims at their defaults: Twelfth reads Entra’s
standard claims (emailaddress, givenname, surname, displayname) and the
Unique User Identifier as user.userprincipalname. If your users’
principal names are not their email addresses, change the Unique User
Identifier to user.mail.
3. Paste Entra’s details into Twelfth
- In Entra’s SAML page, under SAML Certificates, copy the App Federation
Metadata Url. - In Twelfth’s panel, choose SAML 2.0, enter your email domain (for
examplecontoso.com), paste the metadata URL, and press Register identity
provider.
If your people sign in with more than one domain, enter them separated by commas.
Each one needs its own DNS record in the next step.
4. Prove you own the domain
The panel now shows a DNS TXT record. Add it at your DNS host, then press
Check now. Until it resolves, sign-in through Entra is refused — this is what
stops anyone else registering your domain.
5. Assign people and test
- In Entra, open the application’s Users and groups and assign at least
yourself. - Sign out of Twelfth, open the login page, choose
See other login methods → Continue with single sign-on, and enter your
work email. You should land back in the workspace.
Entra only issues an assertion for assigned users. Someone not assigned to the
application sees an Entra error (AADSTS50105), not a Twelfth one — assign them
and try again.
6. Provisioning (SCIM)
With SSO working, let Entra manage membership:
- In Twelfth’s panel, under Directory provisioning, press Generate SCIM
token. Copy the token — it is shown once — and the Tenant URL above it. - In Entra, open the application’s Provisioning → Get started, set
Provisioning Mode to Automatic, and under Admin Credentials enter
the Tenant URL and the token as Secret Token. Press Test Connection,
then Save. - Under Mappings → Provision Microsoft Entra ID Users, the defaults work.
Make sureuserPrincipalName → userNameandmail → emails[type eq "work"].value
are present (they are by default). - Set Provisioning Status to On and save. Entra provisions assigned users
on its cycle (initially within ~40 minutes; you can trigger Provision on
demand for one person to test).
People assigned to the app join the workspace; people unassigned or deleted are
deactivated in Twelfth (never deleted). Roles and remits are still set in
Twelfth.
Troubleshooting
- “Provider domain has not been verified” — the DNS record hasn’t resolved
yet. Check the record name and value exactly as shown, then Check now. - “Single sign-on isn’t set up for that email domain” — the domain typed on
the login page doesn’t match the domain registered in the panel. - Entra error AADSTS700016 / AADSTS50011 — the Identifier or Reply URL in
Entra doesn’t match the panel exactly. Re-copy both. - Signed in, but landed in the wrong workspace — the person belongs to more
than one workspace; switch from Settings → Workspace → My workspaces.