> ## Documentation Index
> Fetch the complete documentation index at: https://brightdata-ipv6-release.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# How to set up Entra ID (formerly Azure Active Directory) SSO and provisioning with Bright Data

* Prepare application

* Setup SSO

* Setup SCIM provisioning

## Prepare Application

* Go to [https://entra.microsoft.com/](https://entra.microsoft.com/) and log in to your account.

* Create Enterprise application:

<img src="https://mintcdn.com/brightdata-ipv6-release/goTKF0pTvyg90BEz/images/general/authentication/entra-sso/entra_1.png?fit=max&auto=format&n=goTKF0pTvyg90BEz&q=85&s=ca3b60a73a69b42f8b2065a851bb5019" alt="" width="1827" height="928" data-path="images/general/authentication/entra-sso/entra_1.png" />

* Click “Create your own application”

* Enter name of your application

* Select “Integrate any other application you don't find in the gallery (Non-gallery)”

* Click “Create”

<img src="https://mintcdn.com/brightdata-ipv6-release/goTKF0pTvyg90BEz/images/general/authentication/entra-sso/entra_2.png?fit=max&auto=format&n=goTKF0pTvyg90BEz&q=85&s=6731d25124203b00e61557ad6b8ee5fe" alt="" width="1827" height="929" data-path="images/general/authentication/entra-sso/entra_2.png" />

## Setup SSO

* Go to [https://brightdata.com](https://brightdata.com) and log in to your account.

* Choose Settings->Account settings->Passwords & authentication in left side menu and toggle Microsoft Entra ID (Azur AD) switch

<img src="https://mintcdn.com/brightdata-ipv6-release/goTKF0pTvyg90BEz/images/general/authentication/entra-sso/entra_3.png?fit=max&auto=format&n=goTKF0pTvyg90BEz&q=85&s=fc5236e286644807e32730723940ecfb" alt="" width="1727" height="919" data-path="images/general/authentication/entra-sso/entra_3.png" />

* From “App registrations” view select your application.

* Copy “Application (client) ID” to “Client ID”

* Copy “Directory (tenant) ID” to “OAuth2 issuer (tenant)”

* Go to “Add a certificate or secret”

<img src="https://mintcdn.com/brightdata-ipv6-release/goTKF0pTvyg90BEz/images/general/authentication/entra-sso/entra_4.png?fit=max&auto=format&n=goTKF0pTvyg90BEz&q=85&s=0a8201b76564c9786d95d67645c1f07d" alt="" width="1824" height="930" data-path="images/general/authentication/entra-sso/entra_4.png" />

* At secrets screen click “New client secret”

* Fill Description

* Click “Add”

<img src="https://mintcdn.com/brightdata-ipv6-release/goTKF0pTvyg90BEz/images/general/authentication/entra-sso/entra_5.png?fit=max&auto=format&n=goTKF0pTvyg90BEz&q=85&s=9e2b42e80666ec69f52e5642f3ec342e" alt="" width="1823" height="930" data-path="images/general/authentication/entra-sso/entra_5.png" />

* Once secret is created copy secret value to “Client secret”.

* Copy “Sign-in redirect URI” to be used at next step

<img src="https://mintcdn.com/brightdata-ipv6-release/goTKF0pTvyg90BEz/images/general/authentication/entra-sso/entra_6.png?fit=max&auto=format&n=goTKF0pTvyg90BEz&q=85&s=9107dc9e9d81c5ec1c3641f64390ce29" alt="" width="1828" height="929" data-path="images/general/authentication/entra-sso/entra_6.png" />

* At “Authentication” screen click “Add platform” and select “Web”

<img src="https://mintcdn.com/brightdata-ipv6-release/goTKF0pTvyg90BEz/images/general/authentication/entra-sso/entra_7.png?fit=max&auto=format&n=goTKF0pTvyg90BEz&q=85&s=eed40d15b4dd097277364a0c6c5e89a7" alt="" width="1825" height="930" data-path="images/general/authentication/entra-sso/entra_7.png" />

* Paste previously copied “Sign-in redirect URI” to the “Redirect URIs” and save settings by clicking “Configure”:

<img src="https://mintcdn.com/brightdata-ipv6-release/goTKF0pTvyg90BEz/images/general/authentication/entra-sso/entra_8.png?fit=max&auto=format&n=goTKF0pTvyg90BEz&q=85&s=54d6e38e6b4fe65714b7da35a23691e7" alt="" width="1825" height="930" data-path="images/general/authentication/entra-sso/entra_8.png" />

* Activate EntraID integration at BrighData control panel and test login:

<img src="https://mintcdn.com/brightdata-ipv6-release/goTKF0pTvyg90BEz/images/general/authentication/entra-sso/entra_9.png?fit=max&auto=format&n=goTKF0pTvyg90BEz&q=85&s=a14f5695b36ec664cb0b90410e372ca9" alt="" width="892" height="916" data-path="images/general/authentication/entra-sso/entra_9.png" />

## Setup SCIM provisioning

* Copy “Auth token” from SCIM section of BrightData EntraID settings:

<img src="https://mintcdn.com/brightdata-ipv6-release/goTKF0pTvyg90BEz/images/general/authentication/entra-sso/entra_10.png?fit=max&auto=format&n=goTKF0pTvyg90BEz&q=85&s=13b956a6186b1f65e89b22c4277bce71" alt="" width="671" height="878" data-path="images/general/authentication/entra-sso/entra_10.png" />

* Select your application from “Enterprise Applications” view and go to “Provisioning” settings:

<img src="https://mintcdn.com/brightdata-ipv6-release/goTKF0pTvyg90BEz/images/general/authentication/entra-sso/entra_11.png?fit=max&auto=format&n=goTKF0pTvyg90BEz&q=85&s=3ed70a4e780a6ec314961327d717f99f" alt="" width="1559" height="930" data-path="images/general/authentication/entra-sso/entra_11.png" />

* Select “Provisioning” under “Manage” menu:

<img src="https://mintcdn.com/brightdata-ipv6-release/goTKF0pTvyg90BEz/images/general/authentication/entra-sso/entra_12.png?fit=max&auto=format&n=goTKF0pTvyg90BEz&q=85&s=ae2e791739d40acff4ca6215dc9039f3" alt="" width="1557" height="931" data-path="images/general/authentication/entra-sso/entra_12.png" />

* Select “Automatic” Provisioning Mode

* Fill “Tenant URL” with [https://brightdata.com/users/auth/scim](https://brightdata.com/users/auth/scim) value

* Fill “Secret Token” with previously copied value from BrightData control panel settings

* Test Connection. You should see successful message in top right corner
  Save Settings

<img src="https://mintcdn.com/brightdata-ipv6-release/goTKF0pTvyg90BEz/images/general/authentication/entra-sso/entra_13.png?fit=max&auto=format&n=goTKF0pTvyg90BEz&q=85&s=a1206c60512dcb7d0a1f9e5215f15bd6" alt="" width="1823" height="931" data-path="images/general/authentication/entra-sso/entra_13.png" />

* Return to “Overview” tab and click “Start provisioning”.

* You can test provisioning at “Provision on demand” page, but first assign your users to BrightData application at “Users and groups” page:

<img src="https://mintcdn.com/brightdata-ipv6-release/goTKF0pTvyg90BEz/images/general/authentication/entra-sso/entra_14.png?fit=max&auto=format&n=goTKF0pTvyg90BEz&q=85&s=7287e634944ad70a168e7e2c8217043b" alt="" width="1825" height="930" data-path="images/general/authentication/entra-sso/entra_14.png" />
