<img height="1" width="1" style="display:none" src="https://www.facebook.com/tr?id=691116991096043&amp;ev=PageView&amp;noscript=1">
Skip to content
  • There are no suggestions because the search field is empty.

Configure Microsoft SSO

This article will walk you through the steps required to configure SSO with Microsoft Entra ID, so your users can log in to Gatekeeper with their Microsoft account.

 Estimated Read Time: 4 Minutes


Sections in this article:


Step 1: Add Gatekeeper to your Enterprise Applications

Before configuring authentication settings in Gatekeeper, you must set up a custom application in Microsoft Entra ID.

  1. From the Azure portal, navigate to Microsoft Entra ID.
  2. Click Add, then select Enterprise Application.
    add enterprise application
  3. Click ➕ Create your own application.
    create your own app

  4. Enter a name for the application (e.g. Gatekeeper), then click Create. Create a custom application, do not select a pre-existing gallery application. 
    create GK app
  5.  Under Getting Started, click Set up single sign on.
    Set up SSO

     

  6. Select Linked as the SSO type.
    linked SSO
  7. Enter the Sign on URL for your region using one of the options below:
    • If US: https://auth-us.gatekeeperhq.com/users/auth/microsoft_oauth2
    • If Canada: https://auth-ca.gatekeeperhq.com/users/auth/microsoft_oauth2
    • If EU: https://auth-eu.gatekeeperhq.com/users/auth/microsoft_oauth2
    • If APAC: https://auth-apac.gatekeeperhq.com/users/auth/microsoft_oauth2
  8. Click Save.
    Save sign on url
  9. As the final step, you can assign the users or groups in Microsoft Entra who should be able to authenticate and log in to Gatekeeper.

Part 2: Log in to Gatekeeper with Microsoft

  1. Log out of Gatekeeper.
  2. On the login screen, click Microsoft.
    log in with MS
  3. Enter your credentials and sign in.

You are now logged in to Gatekeeper via your Microsoft account. When troubleshooting login issues, verify the case sensitivity of both the email address and password.

Note: 

  • Access to the Vendor Portal will remain via username and password, even when SSO authentication is set.
  • Access to the Employee Portal via Microsoft SSO can be enabled/disabled in the Just In Time Provisioning settings screen.
  • It's recommended to verify if other users can log in successfully via Microsoft by checking their login history. To find this, from the navigation menu, expand Settings and click Users. Click on a user's name, then go to the Logins tab.microsoft login history

Part 3: Restrict Access to Only Allow Microsoft SSO

Once you have verified that this app has been set up successfully and that users can authenticate via SSO, you can lock your Gatekeeper environment so that Microsoft SSO is the only valid login option. To do this:

  1. From the navigation menu, expand Settings, then click Configuration.
  2. Click Authentication.
  3. Select the Require Microsoft Single Sign On (SSO) radio button.
  4. Enable the Support Access toggle to allow tenant users with the @gatekeeperhq.com domain to bypass your SSO authentication requirements, so that they can assist with any support enquiries related to your tenant. It is strongly recommended to enable this. 
    enable support access
  5. Click Save.

Note: If you would like to continue allowing users to log in using the standard username and password set from within Gatekeeper, as well as Microsoft SSO authentication methods, select the Standard authentication or Allow all authentication methods radio buttons.

FAQs

A specific user can't sign in via SSO/SAML and gets the following error: Your administrator has configured the application to block users unless they are specifically granted access to the application. The signed-in user is blocked because they are not a direct member of a group with access, nor have access been directly assigned by an administrator. Please contact your administrator to assign access to this application. Everyone else can sign in fine. What's wrong?

This error comes from Microsoft Entra, not Gatekeeper, and means the user hasn't been assigned to the Gatekeeper SSO/SAML enterprise application in Entra. Ask your Entra administrator to assign the user to the application.