Single Sign-On with Azure AD
This guide explains how to configure and enable Single Sign-On (SSO) for users logging into the platform using their Microsoft 365 / Azure AD identity.
Overview
Integrating with Microsoft 365 allows users with assigned permissions to log in seamlessly using their existing Microsoft work account.
Users who are already authenticated with Azure AD will gain immediate access.
Other users will be redirected to the standard Microsoft sign-in page for authentication.
Users without permissions in the platform will be denied login access.
This login method applies to the main platform interface and to embedded access management wizards (e.g., eHub forms).
How to Activate SSO
Follow these steps to enable SSO for your organization.
Locate your Microsoft 365 Tenant ID.
Send an email to support@identum.no containing your Tenant ID.
In the email, explicitly request the activation of SSO between eAdm and Microsoft 365.
After the Identum support team confirms that the setup is complete, you must
clear your browser cache to ensure the new login method is applied.
Authentication Logic
Once enabled, the system authenticates users by matching the email address registered in their user profile against the User Principal Name (UPN) in Azure AD.
Warning: Users must have permissions assigned to them before they can log in. A user requires at least the "Employee" permission level to view their own account details.