> ## Knowledge Base Index
> Fetch the complete knowledge base index at: https://knowledge.yourwatchtower.com/sitemap.xml
> Use this file to discover available pages before exploring further.
> Pure-Markdown content can be obtained by appending a '.md' suffix to the content URLs listed in the sitemap (without the trailing slash).

# SSO Instructions

# SSO Instructions

## Microsoft Entra

Log into Microsoft Entra Admin Center, navigate to Enterprise applications, and select to create a new application.

![](https://storage.crisp.chat/users/helpdesk/website/-/e/e/8/c/ee8c717f4fba7800/unnamed_1ls6xrz.png)
Select create your own application at the top (or use an already created application if applicable)

![](https://storage.crisp.chat/users/helpdesk/website/-/e/e/8/c/ee8c717f4fba7800/unnamed1_14ou5bd.png)
Name your application and select Integrate any other application you don't find in the gallery (Non-gallery) and then click Create.

Once your application is created, navigate to the Single Sign-On setup page and select SAML.

![](https://storage.crisp.chat/users/helpdesk/website/-/e/e/8/c/ee8c717f4fba7800/unnamed2_n72ini.png)

Click Edit on Basic SAML Configuration and add the following values from the SSO Connection you created in Stytch:

* Identifier (Entity ID): the Audience URI will be supplied by Watchtower
* Reply URL (Assertion Consumer Service URL): the ACS URL will be supplied by Watchtower

![](https://storage.crisp.chat/users/helpdesk/website/-/e/e/8/c/ee8c717f4fba7800/unnamed3_bltk85.png =623xauto)

Leave the other values blank and click Save.

Next, edit the Attributes & Claims section. Click on the Unique User Identifier (Name ID) under Required Claim, and change the Source attribute to use user.primaryauthoritativeemail

![](https://storage.crisp.chat/users/helpdesk/website/-/e/e/8/c/ee8c717f4fba7800/unnamed4_1i727l6.png)
Under Additional claims, you edit and delete the default options so you are left with two claims: user.givenname as firstName and user.surname as lastName. Save.

![](https://storage.crisp.chat/users/helpdesk/website/-/e/e/8/c/ee8c717f4fba7800/unnamed5_10w5d1i.png)
Share the Metadata URL with Watchtower to finalize configuration.

![](https://storage.crisp.chat/users/helpdesk/website/-/e/e/8/c/ee8c717f4fba7800/unnamed6_2izko7.png)

The last step is to add users to your application in Entra, which you can do by navigating to Users and Groups and selecting "Add user/group".

![](https://storage.crisp.chat/users/helpdesk/website/-/e/e/8/c/ee8c717f4fba7800/unnamed7_2g0o2l.png)
