---
title: Single sign-on (OpenID Connect)
description: SSO set up with OpenID Connect and Entra
---

[Skip to content](https://support.iventis.com/oidc-sso#main-content)

English

Show submenu for translations

[Contact us](https://support.iventis.com/kb-tickets/new?hsLang=en) [Customer portal](https://customer-portal.iventis.com/tickets-view?hsLang=en)

![Iventis\_Pos\_CMYK-1.jpg\]](https://support.iventis.com/hs-fs/hubfs/Iventis_Pos_CMYK-1.jpg?height=50&name=Iventis_Pos_CMYK-1.jpg)

Open main navigation

Close main navigation

- English
  
  Show submenu for translations
- [Contact us](https://support.iventis.com/kb-tickets/new)
- [Customer portal](https://customer-portal.iventis.com/tickets-view)
- Go to www.iventis.com

 Go to www.iventis.com

 Hello. How can we help you?

- There are no suggestions because the search field is empty.

1. [Knowledge Base](https://support.iventis.com/?hsLang=en)
2. [Account & Billing](https://support.iventis.com/account-billing?hsLang=en)

# Single sign-on (OpenID Connect)

## OpenID Connect (OIDC) single sign-on lets people sign in to your Iventis project with their Microsoft Entra ID account, so they don't need a separate Iventis password.

### Before you begin

You need all of the following before starting:

- **SSO on your plan**: your Iventis subscription must include single sign-on. Contact your Iventis support to upgrade if the Single sign-on page is not available in project settings.
- **An Iventis project administrator** to enter the connection details and enable SSO.
- **A Microsoft Entra administrator** with at least the **Application Administrator** role, to register the app and grant access.
- **A mail address for each user** in Entra. Iventis matches someone's first SSO sign-in to their Iventis account by email address.

### Step 1: Copy the Redirect URI from Iventis

1. In Iventis, open **Project settings** and select **SSO Configuration.**  
   **![](https://support.iventis.com/hs-fs/hubfs/undefined-Oct-05-2026-03-20-24-4720-PM.png?width=193&height=500&name=undefined-Oct-05-2026-03-20-24-4720-PM.png)**
2. Set **Protocol** to **OpenID Connect**.
3. Copy the **Redirect URI**. It has the form `https://<your-project>.<iventis-domain>/permissions/signin-oidc`.

Leave this page open; you'll come back to it in later.

### Step 2: Register Iventis in Microsoft Entra ID

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com).
2. Go to **Entra ID** \> **App registrations** and select **New registration**.
3. Enter a name, for example *Iventis*.
4. Under **Supported account types**, select **Accounts in this organizational directory only (Single tenant)**.
5. Under **Redirect URI**, choose **Web** and paste the Redirect URI from Step 1.
6. Select **Register**.
7. On the app's **Overview** page, copy the **Application (client) ID** and the **Directory (tenant) ID**.
8. Select **Certificates & secrets** \> **Client secrets** \> **New client secret**. Add a description, choose an expiry, and select **Add**.
9. Copy the secret's **Value** straight away. Entra only shows it once. Copy the **Value** column, not the **Secret ID**.

### Step 3: Add claims

Add **given\_name** and **family\_name** if possible.

1. In the app registration, select **Token configuration** \> **Add optional claim**.
2. Choose **ID**, tick **given\_name** and **family\_name**, and select **Add**.
3. If asked, turn on the Microsoft Graph profile permission and select **Add**.
4. Optionally, select **Grant admin consent for** *your organisation* and confirm, so users aren't asked to consent when they first sign in. You must do this if your organisation doesn't let users consent to apps themselves.

### Step 4: Choose who can sign in (recommended)

By default, anyone in your Entra tenant can get a token for the app. Iventis still only admits project members with SSO turned on, but requiring assignment lets you control access from Entra as well.

1. Go to **Entra ID** \> **Enterprise apps** and open the app with the name you registered in Step 2.
2. Select **Properties**, set **Assignment required?** to **Yes**, and select **Save**.
3. Select **Users and groups** \> **Add user/group**, and assign the people or groups who use Iventis.

### Step 5: Enter the details in Iventis and enable SSO

1. Back on the **Single sign-on** page in Iventis, with **Protocol** set to **OpenID Connect**, enter: 
     - **Tenant ID**: the Directory (tenant) ID from Step 2
     - **Client ID**: the Application (client) ID from Step 2
     - **Client secret**: the secret Value from Step 2
2. Turn on **Single sign-on enabled**.
3. Select **Save** and confirm.

Iventis stores the client secret encrypted and never displays it again. The page confirms that a secret is stored; leave the field blank to keep it.

### Step 6: Turn on SSO for people and test sign-in

Enabling SSO on the project doesn't switch anyone over yet. Each person signs in with SSO once it's turned on for them.

1. Test with one person first. In the Iventis **People** app, select or invite them and choose **Enable sso**.
2. Ask them to go to your project's Iventis address and select **Login with Single Sign-on**. They sign in with their Microsoft account and land in the project.
3. Once that works, enable SSO for everyone else in the same way. People you invite from now on can be invited with SSO already on.

On a person's first SSO sign-in, Iventis finds their account by email address, then links it to their Entra account so later sign-ins still work if their email changes.

Keep at least one project administrator on password sign-in until SSO is working for everyone, so you can't lock yourselves out.

### Rotating the client secret and turning SSO off

**Client secrets expire.** When the secret expires, nobody can sign in with SSO, so replace it before the expiry date shown in Entra:

1. In the app registration, select **Certificates & secrets** \> **New client secret** and copy the new **Value**. Leave the old secret in place for now.
2. In Iventis, enter the new value in **Client secret** on the **Single sign-on** page and select **Save**.
3. Test an SSO sign-in, then delete the old secret in Entra.

**Turning SSO off:**

- If SCIM provisioning is enabled, turn it off first. Iventis won't let you disable SSO while SCIM is on.
- When SSO is turned off, everyone who signs in with SSO is emailed instructions to set a password.
- If SSO is turned on again later, it has to be re-enabled for each person in the People app.

- [Getting started](https://support.iventis.com/getting-started?hsLang=en)
- [Using Iventis](https://support.iventis.com/using-iventis?hsLang=en#main-content)

    - [Create: How to build an event site or operational plan](https://support.iventis.com/using-iventis?hsLang=en#create-how-to-build-an-event-site-or-operational-plan)
    - [Share: How to share your event site and venue plans](https://support.iventis.com/using-iventis?hsLang=en#share-how-to-share-your-event-site-and-venue-plans)
    - [Analysis: How to analyse costs, bill of quantities, and more!](https://support.iventis.com/using-iventis?hsLang=en#analysis-how-to-analyse-costs-bill-of-quantities-and-more)
    - [3D Line Models](https://support.iventis.com/using-iventis?hsLang=en#3d-line-models)
    - [Digital Twin](https://support.iventis.com/using-iventis?hsLang=en#digital-twin)
- [Account & Billing](https://support.iventis.com/account-billing?hsLang=en)
- [Tips & Tricks](https://support.iventis.com/tips-tricks?hsLang=en)
- [FAQs](https://support.iventis.com/faqs?hsLang=en#main-content)

    - [Permissions](https://support.iventis.com/faqs?hsLang=en#permissions)

# Iventis

Tel: + 44 (0) 203 443 9030

<https://www.linkedin.com/company/iventis-ltd/> <https://twitter.com/IventisSoftware> <https://www.instagram.com/iventis_software/> <https://www.facebook.com/iventis.software>

Copyright © 2026, Iventis