Skip to main content

Microsoft Entra Single Sign-On (SSO) Setup

Step-by-step instructions on how to set up Microsoft Entra ID SSO so Buddy Punch users can log in using corporate credentials seamlessly.

Rachel avatar
Written by Rachel
Updated this week

Overview: Microsoft Entra ID (formerly known as Azure Active Directory) is a cloud-based identity and access management solution from Microsoft. It enables organizations to manage and secure user identities, enforce access controls, and streamline authentication across internal systems and external applications.

When integrated with Buddy Punch, Microsoft Entra ID allows employees to sign in using their existing organizational credentials. This Single Sign-On (SSO) functionality helps reduce password fatigue, enhances security by centralizing authentication, and simplifies access to Buddy Punch for time tracking and workforce management.

Important! The Microsoft Entra SSO can only be used with the Buddy Punch website. Additionally, Microsoft Entra SSO access is only available to users on the Enterprise plan.

Instructions:


Prerequisites

To set up Single Sign-On (SSO) with Microsoft Entra ID, a few requirements must be met before we can begin the integration process, which include:

  1. Your company must be on the Buddy Punch Enterprise Plan.

  2. The person requesting SSO setup must be an Administrator on your Buddy Punch account.

Once both prerequisites are confirmed, you can move on to the next section covering how to Initiate SSO Setup in Buddy Punch.


Initiate SSO Setup in Buddy Punch

Once both prerequisites are confirmed as detailed here, you can then reach out to our team to initiate the SSO setup process.

This can either be done by contacting our support team at [email protected] or by using the in-app chat in the bottom right-hand corner of your Buddy Punch Administrator account:

After verification, we’ll provide your organization with our SAML metadata file, which is used to configure the connection between Microsoft Entra ID and Buddy Punch.

Important! We only offer IDP-initiated SAML SSO at this time.

In return, we'll need your team to provide the following:

  1. App Federation Metadata URL

  2. Login URL (Optional, if you don't want your employees to be directed to our login page from our emails)

  3. Entra ID Identifier

Once we have that information, it will take approximately one business day to get SSO enabled on the account.


Enable SSO in Microsoft

After receiving the Buddy Punch SAML metadata file, you can start the process of enabling single sign-on for an enterprise application.

Instructions covering this full process are provided by Microsoft here.

After our team follows up to confirm the SSO is live, you can then proceed with testing the SSO.

Did this answer your question?