Microsoft Entra ID

This guide sets up SAML single sign-on from Microsoft Entra ID (formerly
Azure AD), then optional SCIM provisioning so Entra manages who has access.
You’ll need an Entra role that can create enterprise applications (Cloud
Application Administrator or Global Administrator) and a Twelfth workspace
owner or admin. Read Single sign-on & SCIM first
if you haven’t.

1. Create the enterprise application

  1. In the Entra admin centre, open Identity →
    Applications → Enterprise applications → New application
    .
  2. Choose Create your own application, name it Twelfth, select
    Integrate any other application you don’t find in the gallery
    (Non-gallery)
    , and create it.
  3. In the new application, open Single sign-on → SAML.

2. Paste Twelfth’s details into Entra

In Twelfth, open Settings → Workspace → Security & SSO → Single sign-on. Under Create the
app in your identity provider
you’ll find the values below, each with a copy
button. In Entra’s Basic SAML Configuration panel, set:

Entra field Twelfth value
Identifier (Entity ID) Identifier (Entity ID) from the panel
Reply URL (Assertion Consumer Service URL) Reply URL (Assertion Consumer Service) from the panel
Sign on URL https://twelfth.ai/login (optional)

Save. Leave Attributes & Claims at their defaults: Twelfth reads Entra’s
standard claims (emailaddress, givenname, surname, displayname) and the
Unique User Identifier as user.userprincipalname. If your users’
principal names are not their email addresses, change the Unique User
Identifier to user.mail.

3. Paste Entra’s details into Twelfth

  1. In Entra’s SAML page, under SAML Certificates, copy the App Federation
    Metadata Url
    .
  2. In Twelfth’s panel, choose SAML 2.0, enter your email domain (for
    example contoso.com), paste the metadata URL, and press Register identity
    provider
    .
Several email domains?

If your people sign in with more than one domain, enter them separated by commas.
Each one needs its own DNS record in the next step.

4. Prove you own the domain

The panel now shows a DNS TXT record. Add it at your DNS host, then press
Check now. Until it resolves, sign-in through Entra is refused — this is what
stops anyone else registering your domain.

5. Assign people and test

  1. In Entra, open the application’s Users and groups and assign at least
    yourself.
  2. Sign out of Twelfth, open the login page, choose
    See other login methods → Continue with single sign-on, and enter your
    work email. You should land back in the workspace.
Assignment required

Entra only issues an assertion for assigned users. Someone not assigned to the
application sees an Entra error (AADSTS50105), not a Twelfth one — assign them
and try again.

6. Provisioning (SCIM)

With SSO working, let Entra manage membership:

  1. In Twelfth’s panel, under Directory provisioning, press Generate SCIM
    token
    . Copy the token — it is shown once — and the Tenant URL above it.
  2. In Entra, open the application’s Provisioning → Get started, set
    Provisioning Mode to Automatic, and under Admin Credentials enter
    the Tenant URL and the token as Secret Token. Press Test Connection,
    then Save.
  3. Under Mappings → Provision Microsoft Entra ID Users, the defaults work.
    Make sure userPrincipalName → userName and mail → emails[type eq "work"].value
    are present (they are by default).
  4. Set Provisioning Status to On and save. Entra provisions assigned users
    on its cycle (initially within ~40 minutes; you can trigger Provision on
    demand
    for one person to test).

People assigned to the app join the workspace; people unassigned or deleted are
deactivated in Twelfth (never deleted). Roles and remits are still set in
Twelfth.

Troubleshooting

  • “Provider domain has not been verified” — the DNS record hasn’t resolved
    yet. Check the record name and value exactly as shown, then Check now.
  • “Single sign-on isn’t set up for that email domain” — the domain typed on
    the login page doesn’t match the domain registered in the panel.
  • Entra error AADSTS700016 / AADSTS50011 — the Identifier or Reply URL in
    Entra doesn’t match the panel exactly. Re-copy both.
  • Signed in, but landed in the wrong workspace — the person belongs to more
    than one workspace; switch from Settings → Workspace → My workspaces.