Set up single sign-on (SSO) for Amplitude using Microsoft Azure Active Directory

  • Updated

Amplitude provides a single sign-on integration with Microsoft Azure Active Directory for customers on Scholarship, Growth, or Enterprise plans.

Before you begin

For some general information about SSO, see our Help Center article on SSO in Amplitude.

In order to set up SSO, you must be an org admin for your Amplitude organization. You must also able to configure Azure Active Directory for your organization in Microsoft Azure.

Set up SSO for Amplitude using Microsoft Azure Active Directory

To configure SSO for Amplitude using Azure Active Directory, follow these steps:

  1. From the Azure portal, navigate to the Azure Active Directory section.

    an_azure_1_aad.png

  2. Open the Enterprise applications sub-section.

    an_azure_2_enterprise_apps.png

  3. Click + New application to add a new application.

    an_azure_3_new_app.png

  4. Search for Amplitude in the app gallery. From the results list, select Amplitude and click Add in the bottom-right of the app summary.

    an_azure_4_gallery.png

  5. Click Single sign-on to open the SSO app settings. Then enter the identifier and the reply URL in the appropriate text fields.

    an_azure_6_settings.png

These can be found under Entity ID and Assertion Consumer Service URL, respectively, in Amplitude's SSO settings.

Screen

  1. In the User identifier field, select user.mail from the drop-down list.

    an_azure_7_user_identifier.png

  2. Save the changes. Then click Metadata XML to download the metadata file.

    an_azure_8_download_metadata.png

  1. In Amplitude, navigate to gear_icon_for_settings.png > Organization settings > Access & SSO Setting > Single Sign-On Settings and upload the metadata file. Be sure to choose Microsoft Azure Active Directory as the Identity Provider.

  2. Save your changes to enable SSO.