Microsoft Entra ID
Connect your Microsoft Entra tenant to Limrun with OIDC SSO. To manage organization membership from Entra, also configure SCIM through a non-gallery enterprise application. This setup does not require a Limrun gallery listing.
This guide uses two applications in your tenant: Limrun SSO for authentication and Limrun SCIM for provisioning. Keep their user and group assignments aligned.
Prerequisites
- Admin access to the Limrun organization and DNS access for its email domains.
- Entra permissions to create app registrations, grant admin consent, manage credentials, assign users, and configure enterprise application provisioning.
- An Entra license that supports the provisioning and group assignment features you plan to use. Check Microsoft's licensing guidance.
- Work email addresses populated in Entra that belong to a verified Limrun domain.
Configure SSO
Verify your domain in Limrun
- Open console.limrun.com and go to Settings > Domain Verification.
- Add the email domain your users sign in with.
- Publish the TXT record shown in Limrun, then select Verify DNS.
Once you save an SSO connection, users with that verified domain must use Continue with SSO, including existing users. The separate Microsoft social sign-in flow does not satisfy the organization's SSO requirement.
Register the SSO application
-
Open the Microsoft Entra admin center in your organization's tenant.
-
Go to App registrations > New registration and name the app
Limrun SSO. -
Select Accounts in this organizational directory only.
-
Add a Web redirect URI:
https://api.limrun.com/authn/oidc/callback -
Register the application. Copy its Application (client) ID and Directory (tenant) ID.
-
Under Certificates & secrets, create a client secret and copy its Value. The secret ID is not the secret value. Record its expiration date so you can replace it in Limrun before it expires.
Use the Web platform and authorization code flow. Limrun does not need implicit grant enabled. For registration details, see Microsoft's app registration guide.
Configure the email claim and assignments
- In the app registration, open Token configuration > Add optional claim.
- Select ID, add
email, and save. If prompted, enable the permission needed to include the claim. - Confirm each assigned user's email is populated and belongs to a verified Limrun domain. The ID token must contain
email; Limrun does not fall back topreferred_usernameor the user's principal name. - Open the corresponding Limrun SSO application under Enterprise applications. Under Properties, set Assignment required? to Yes and save.
- Under Users and groups, assign the users or groups allowed to sign in, including the administrator configuring Limrun.
- Return to the app registration's API permissions. Add Microsoft Graph delegated permissions for
openid,email, andprofile, then select Grant admin consent for your tenant. Assignment-required apps need admin consent before assigned users can sign in.
See Microsoft's guides to optional claims and assignment and consent.
Save the Entra connection in Limrun
Open Settings > Single Sign-On and enter:
| Limrun field | Value |
|---|---|
| Issuer URL | https://login.microsoftonline.com/<tenant-id>/v2.0, replacing <tenant-id> with your Directory ID. |
| Client ID | Application ID of Limrun SSO. |
| Client Secret | The secret Value from that app registration. |
Select Save. Use the tenant-specific issuer, not /common or /organizations. You can confirm the issuer in https://login.microsoftonline.com/<tenant-id>/v2.0/.well-known/openid-configuration.
Log in with Microsoft Entra ID
- Open console.limrun.com/authn/login.
- Select Continue with SSO and enter your work email.
- Complete authentication in your organization's Microsoft tenant.
Without SCIM, successful SSO creates or links the account and joins the organization. If you plan to use SCIM, test with an existing Limrun admin, then complete provisioning before inviting users to sign in.
Configure SCIM provisioning
Entra's non-gallery provisioning supports a SCIM URL and bearer token. The steps below use Limrun's generated credential directly. See Microsoft's non-gallery SCIM guide.
Create the provisioning application
- In Entra, open Enterprise applications > New application > Create your own application.
- Name it
Limrun SCIMand choose Integrate any other application you don't find in the gallery. - In Limrun, open Settings > Single Sign-On > Directory provisioning (SCIM) and generate a credential.
- In Limrun SCIM, open Provisioning and configure automatic provisioning. Depending on your Entra portal, select Get started or New configuration.
- Enter Limrun's SCIM base URL as the Tenant URL, and its generated credential as the Secret Token. Copy the credential without a
Bearerprefix. - Select Test Connection, then save.
The SCIM credential is separate from the Limrun SSO client secret and Limrun API keys. Generating it starts SCIM setup: existing members retain access, while invitations, auto-join, and admission of new users are disabled.
Configure attribute mappings
Enable both user and group provisioning. Under the provisioning configuration's attribute mappings, map only attributes Limrun supports. Remove mappings for enterprise-extension fields such as manager and department.
| Entra source | SCIM user attribute | Configuration |
|---|---|---|
mail | userName | Use as the matching attribute. Must equal the OIDC email claim. |
objectId | externalId | Stable directory identifier. |
displayName | displayName | Optional profile field. |
givenName | name.givenName | Optional profile field. |
surname | name.familyName | Optional profile field. |
mail | emails[type eq "work"].value | Same work email. |
| Entra's account-enabled and assignment status mapping | active | Preserve the default lifecycle expression so deprovisioning sends false. |
Use userPrincipalName for userName only when it equals the OIDC email. A guest's #EXT# principal name is not a work email. Every provisioned user's email domain must be verified in the Limrun organization.
For groups, keep objectId mapped to externalId, displayName to displayName, and members to members. Use distinct group names for Entra matching, even though Limrun identifies groups by their SCIM IDs.
See Microsoft's attribute mapping guide and Limrun's supported SCIM attributes and operations.
Synchronize groups and activate access management
- Assign pilot access groups under Limrun SCIM > Users and groups. Include an admin group and its direct user members.
- Scope provisioning to Sync only assigned users and groups. Ensure those users can also sign in through Limrun SSO. See Microsoft's scoping guidance.
- Start provisioning. Check Entra's provisioning logs and wait for both users and group memberships to appear in Limrun. A successful connection test alone does not synchronize the directory.
- In Limrun, map the synchronized groups to Admin, Member, or Viewer. Confirm that every existing member who should retain access, including administrators, is active and belongs to a mapped group.
- Select Activate SCIM. Test a provisioned user's SSO login, then test group removal, deactivation, and reactivation with a pilot account.
Activation is permanent and can remove or demote the last admin. A user needs both an active SCIM record and membership in a mapped group. Direct application assignment without a mapped group does not grant Limrun access after activation. Nested groups are not supported; provision direct user memberships.
For role precedence, recovery, and credential rotation, see SCIM provisioning.
Troubleshoot
"Your organization requires SSO". Use Continue with SSO and your work email. The separate Microsoft sign-in route cannot bypass the configured organization connection.
"SSO not configured". Verify the email domain under Settings > Domain Verification and save the OIDC connection for the same organization.
Microsoft rejects the redirect URI. Register https://api.limrun.com/authn/oidc/callback as a Web redirect URI on Limrun SSO. Do not use /authn/microsoft/callback for this setup.
The ID token is missing email. Add the optional email ID-token claim and populate the user's email in Entra. Check that the value matches SCIM userName.
Microsoft rejects the client secret. Use the secret's Value, not its ID. If it expired, create a replacement and update the Limrun SSO connection.
Microsoft asks for admin approval. Have an Entra administrator grant consent to the sign-in permissions on Limrun SSO, then retry with an assigned user.
Provisioning returns 401 or 403. Check the SCIM base URL and Secret Token. After rotating the Limrun SCIM credential, replace the token in Entra; the previous credential stops working immediately.
A provisioned user cannot enter Limrun. Confirm SCIM is activated, the user is active, and a synchronized group containing the user maps to a role. Also check assignment to Limrun SSO. Review both Entra provisioning logs and Limrun provisioning history for failed or pending changes.
Users synchronize but groups do not. Enable group mappings, assign the groups to Limrun SCIM, and check the provisioning scope. Limrun calculates roles from SCIM group membership, not from OIDC group claims.
Was this guide helpful?