> Full SurrealDB documentation index: https://surrealdb.com/docs/llms.txt

# Microsoft Entra ID

Configure Microsoft Entra ID (Azure Active Directory) as an identity provider for single sign-on in SurrealDB. Register an application in Entra and add a Microsoft Entra ID connection in SurrealDB Studio.

Connect Microsoft Entra ID (formerly Azure Active Directory) to SurrealDB to allow members of your organisation to sign in with their Microsoft accounts. You register an application in the Microsoft Entra admin center, then enter its details in a new connection in SurrealDB Studio.

Before you start, [verify the email domain](/docs/manage/enterprise/single-sign-on.md#step-1-verify-an-email-domain) your company uses. You also need an Entra account that can register applications.

## Step 1: Register an application

1. In the Microsoft Entra admin center, open **Entra ID**, then **App registrations**.
2. Select **New registration**.

![The App registrations page in the Microsoft Entra admin center, with App registrations and New registration highlighted.](~/assets/img/surrealdb/manage/enterprise-sso-entra-1.webp)

3. Enter a **Name**, for example `SurrealDB`.
4. Under **Supported account types**, select **Single tenant only**, so that only accounts in your directory can sign in.
5. Under **Redirect URI**, select **Web** as the platform and enter `https://auth.surrealdb.com/login/callback`.
6. Select **Register**.

![The Register an application form in Entra, with the Web redirect URI and the Register button highlighted.](~/assets/img/surrealdb/manage/enterprise-sso-entra-2.webp)

## Step 2: Copy the application ID

Entra opens the **Overview** of the new application. Copy the **Application (client) ID**.

![The Overview page of the SurrealDB application in Entra, with the application (client) ID highlighted.](~/assets/img/surrealdb/manage/enterprise-sso-entra-3.webp)

## Step 3: Check the API permissions

Open **API permissions** and make sure the application has the delegated Microsoft Graph permission `User.Read`. A new registration usually has it already. If it is missing, select **Add a permission**, then **Microsoft Graph**, then **Delegated permissions**, and add `User.Read`.

## Step 4: Create a client secret

1. Open **Certificates & secrets**.
2. On the **Client secrets** tab, select **New client secret**.
3. Enter a **Description**, for example `SurrealDB`, and choose when it **Expires**.
4. Select **Add**.

![The Certificates & secrets page in Entra, with the Add a client secret panel open and the steps numbered.](~/assets/img/surrealdb/manage/enterprise-sso-entra-4.webp)

Copy the secret's **Value**, not its **Secret ID**. Entra shows the value only once, while you are still on the page.

> [!WARNING]
> Sign-in through this connection stops working on the date the client secret expires. Note the date, and create a new secret and update the connection in SurrealDB before then.

## Step 5: Add the connection in SurrealDB

1. Open **Single sign-on** in your enterprise and add a new connection.
2. Select **Microsoft Entra ID**.
3. Under **Name the connection**, enter a **Display name**. Members see this name on the sign-in screen.
4. Under **Enter the Microsoft Entra ID details**, enter:
    - **Directory domain**: a domain of your directory, for example `example.onmicrosoft.com`.
    - **Client ID**: the application (client) ID from step 2.
    - **Client secret**: the secret value from step 4.
5. Under **Route sign-in domains**, select the verified domains to send to this connection. This is optional, and you can change it later.
6. Select **Create connection**.

The **Set up Microsoft Entra ID** section of the form shows the redirect URI, with a copy button beside it, if you need it again.

![The New Microsoft Entra ID connection form in SurrealDB Studio, with the display name, directory domain, client ID, client secret and a routed domain filled in.](~/assets/img/surrealdb/manage/enterprise-sso-entra-5.webp)

SurrealDB stores the client secret securely and does not show it again.

## Next steps

If you did not route a domain when you created the connection, [route one now](/docs/manage/enterprise/single-sign-on.md#step-3-route-domains-to-the-connection). Then [choose the applications](/docs/manage/enterprise/single-sign-on.md#step-4-choose-the-applications) that people can sign in to with this connection.
