Skip to main content

Set up SSO with Microsoft Entra ID

Use Microsoft Entra ID Single Sign-On to let your team members sign in to Contrast using their existing Microsoft credentials.

Written by Karim Matrah

Prerequisites

Microsoft Entra ID Single Sign-On is available on the Enterprise plan.

You will need administrator access to your Microsoft Azure Portal to configure the integration.

Supported features

Contrast supports:

  • SSO using OpenID Connect (OIDC)

  • Just-in-time (JIT) provisioning: users are automatically created in Contrast when they sign in for the first time

Configuration steps

1. Microsoft Entra Tenant

  1. In your Microsoft Azure Portal, go to Microsoft Entra ID.

  2. Copy your directory's Tenant ID.

Keep this value handy, you'll need it in the next step.

2. Configure Contrast

Next, add your Microsoft Entra ID settings to your Contrast account.

  1. Sign in to your Contrast account.

  2. Go to Settings → Integrations.

  3. Click the Microsoft Entra ID card to open the configuration modal.

  4. Enter the Tenant ID from the previous step.

  5. Save your configuration.

Your Microsoft Entra ID integration is now configured.

Test the integration

To verify that everything is working correctly:

  1. Enter your work email address (make sure it is the same email address associated with your Microsoft account).

  2. Click Continue.

  3. You will be redirected to Microsoft to sign in.

  4. After successfully signing in, you will be redirected to your Contrast dashboard.

If this is the first time the user has signed in to Contrast, their account will be automatically created through just-in-time provisioning.

Did this answer your question?