Single Sign-On (SSO) with Microsoft Entra ID

You can enable Single Sign-On for the Pexip apps by integrating the Pexip Service with Microsoft Entra ID (formerly called Azure Active Directory).

Your account manager at your local certified Pexip Partner needs to open a ticket with the Pexip Support team using the Single Sign-On (SSO) Setup Request form, and you need to supply your partner with details of your Microsoft Entra ID tenant.

Note that there is no synchronization with the SSO service. It supports sign-in only; company administrators still need to initiate user invitations.

This article explains the steps you (the customer company administrator) need to perform:

  1. From the Azure portal, add the Pexip Service app to enable SSO access.

    • You can install the app directly from this Azure app marketplace link.

    • Alternatively, search for it via Microsoft Entra ID > Enterprise Applications > New application and then in the Search box, search for Pexip.
  2. In either case, select the Pexip application and proceed to add it, following this Microsoft guide for what to enter on the Microsoft Entra integration with Pexip Service page.

    This guide also covers how to enable a user or group for the Pexip SSO application.

  3. In your request to your partner for SSO setup you need to provide the following items:

    • Login URL (SSO URL in the Pexip SSO Setup Request form)

      Example: https://login.microsoftonline.com/YOUR-AAD-TENANTID-HERE/saml2

    • Microsoft Entra Identifier (Entity ID in the Pexip SSO Setup Request form)

      Example: https://sts.windows.net/YOUR-AAD-TENANTID-HERE/

    • The certificate (Base64 format) downloaded from the Azure portal.

Pexip support will then enable your organization for SSO, and your users will have to be added by you in a group or to the application so they are allowed to use it for Pexip SSO.