> ## Documentation Index
> Fetch the complete documentation index at: https://docs.wegive.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Setting Up Azure Entra Single Sign-On (SSO) for Your WeGive Dashboard

> WeGive Help Center article: Setting Up Azure Entra Single Sign-On (SSO) for Your WeGive Dashboard

This guide walks Microsoft Entra (formerly Azure AD) administrators through configuring single sign-on for their organization's WeGive dashboard users.

## Overview

WeGive uses the modern **OpenID Connect (OIDC) / OAuth 2.0** approach to single sign-on. We do not use the older SAML-based SSO approach, so if your IT team is familiar with SAML setups, expect a slightly different (and simpler) configuration flow.

Once SSO is enabled, your dashboard users will authenticate against your Entra tenant instead of using a separate WeGive password.

### What WeGive's SSO does and doesn't do

* **Authentication only.** WeGive uses Entra to verify who a user is, not to determine what they can do.
* **No role mapping from group claims.** Roles and permissions continue to be managed inside WeGive. We don't read the `groups` claim from your tokens.
* **Full just-in-time (JIT) provisioning, floored at no access.** On first SSO sign-in, WeGive creates a user record from the token *and* automatically grants them organization membership — but with a built-in `no-access` role that confers no actual permissions. A new SSO user can sign in and land in the dashboard, but can't do anything there until an admin assigns a real role. The recommended flow is still to invite the user from WeGive first (with the role you want them to have) before their first SSO sign-in, so they land with real permissions immediately rather than a no-access placeholder that needs manual follow-up.

## Before You Start

You'll need:

* An admin account in your Microsoft Entra tenant
* The email domain you want to use for SSO (e.g., `yourcompany.com`)
* A WeGive account contact to coordinate with — SSO requires a configuration step on our end

## Step 1: Register WeGive as an Application in Entra

In the Entra admin center, register a new application for WeGive with the following settings:

* **Redirect URI:** `https://api.wegive.com/api/auth/azure/callback`
* **Response type:** `id_token`
* **Response mode:** `form_post`
* **Scopes:** `openid`, `profile`, `email`

## Step 2: Grant Admin Consent

This step is easy to miss but required — without admin consent, sign-in attempts will fail.

1. Go to the Microsoft Entra admin center at [entra.microsoft.com](https://entra.microsoft.com) and sign in.
2. Select **Identity**, then **Applications**, then **Enterprise apps**.
3. Search for and select the **WeGive** application.
4. Under **Manage**, select **API permissions**.
5. At the top of the API permissions page, click **"Grant admin consent for \[organization name]"**.
6. When prompted, confirm by clicking **Grant**.

## Step 3: Send the Following Information to WeGive

Once your application is registered and admin consent is granted, securely send the following four values to your WeGive contact:

* `tenant_id`
* `client_id`
* `client_secret`
* `domain` (the email domain your users will sign in with, e.g., `yourcompany.com`)

We'll use these to create the integration record on our side and activate SSO for your organization.

**Security note:** Please share these values through a secure channel — not in a plain email. Coordinate with your WeGive contact on the best method.

## Step 4: Test the Configuration

Once WeGive confirms the configuration is live, test SSO end-to-end with a single user before rolling it out broadly.

To verify SSO is working:

1. Log out of the WeGive dashboard.
2. Go to the dashboard sign-in page and enter your email address.
3. When you tab from the email field to the password field, the Microsoft SSO authentication process should be triggered automatically.
4. Complete the Microsoft sign-in flow.
5. You should land back in the WeGive dashboard, signed in.

If the Microsoft flow doesn't trigger when you tab away from the email field, double-check that admin consent has been granted (Step 2) and that the email domain on your account matches the `domain` value sent to WeGive.

## Adding Users After SSO Is Live

Because WeGive uses full JIT provisioning floored at `no-access`, here's the recommended order of operations for adding a new dashboard user:

1. **Create the user in Entra** (or confirm they already exist in your tenant).
2. **Invite the user from WeGive** with the appropriate role, *before* their first SSO sign-in.
3. **The user signs in via SSO.** If they were already invited with a role, that role is in place when they land in the dashboard. If they sign in without having been invited first, WeGive still creates their account and organization membership automatically — but with the no-access role, so they'll be signed in but unable to do anything until an admin assigns a real role afterward.

If you invite from WeGive without the user existing in Entra, they won't be able to complete sign-in.

## Frequently Asked Questions

**Does WeGive support SAML SSO?** No. WeGive uses OIDC / OAuth 2.0 only.

**Can roles be assigned based on Entra group membership?** Not today. WeGive does not read the `groups` claim. Roles are assigned inside WeGive and remain there.

**Can users be auto-provisioned with a role on first login?** Partially. A user account and organization membership ARE created automatically on first SSO sign-in, but the membership starts with a built-in `no-access` role that grants nothing. Invite the user from WeGive first (before their first sign-in) so a real role is assigned from the start, rather than relying on this no-access fallback and following up manually.

**What happens during the cutover when SSO is first enabled?** The dashboard may be briefly unavailable to your admins while we activate the configuration. We recommend coordinating a window with your team for the activation.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.