NL Dutch
FR French
IT Italian
JP Japanese
DE German
US English (US)
ES Spanish

Contact Us

If you still have questions or prefer to get help directly from an agent, please submit a request.
We’ll get back to you as soon as possible.

  • Contact Us
English (US)
NL Dutch
FR French
IT Italian
JP Japanese
DE German
US English (US)
ES Spanish
  • Home
  • AutoElevate Knowledgebase
  • AutoElevate Features & Troubleshooting

SSO with Entra ID (Azure AD) for AutoElevate

Learn how to enable and configure single sign-on (SSO) with Azure Active Directory (Azure AD).

Written by Owen Parry

Updated at August 20th, 2026

Contact Us

If you still have questions or prefer to get help directly from an agent, please submit a request.
We’ll get back to you as soon as possible.

  • AutoElevate Knowledgebase
    New to AutoElevate? START HERE AutoElevate Features & Troubleshooting Managing Rules in AutoElevate Integrations for AutoElevate AutoElevate FAQ Selling AutoElevate
  • Password Boss Knowledgebase
    Using Password Boss Administrating Password Boss Legacy Password Boss
  • CyberFOX DNS Filtering
    Getting Started with DNS Filtering DNS Filtering Concepts Network Requirements for DNS Filtering DNS Filtering Company and Location Setup Managing your DNS Filtering Policies Using Roaming Clients for DNS Filtering DNS Filtering Reports & Logs DNS Filtering Troubleshooting
  • Marketing Toolkit
    MSP Marketing & Education Toolkit CyberFOX Brand Guidelines
  • Changelogs for Autoelevate and Password Boss
  • CyberFOX Product Roadmap
  • Current Status
+ More

Table of Contents

Overview What Entra ID SSO Does Before you Begin Microsoft Entra Licensing for Group Assignment GCC Entra ID Limitations Enable Entra ID SSO Start the SSO Setup Authenticate and Grant Consent Delegate MFA to a Microsoft Entra Custom Control Troubleshoot the Initial SSO Connection The Microsoft Sign-In Page Does Not Open Check the Browser Check Microsoft Entra ID Retry the Connection Assign Users, Groups, and Roles Assign a User or Group Verify the Assignment Complete Company Access Configuration Sign In With Entra ID Configure Co-Managed Users Create the AutoElevate User Add and Assign the External User Enforce SSO for Existing Users Maintain Emergency Administrative Access Advanced Use Cases Manage Technician Access Through Groups Preconfigure New Administrators Apply Microsoft Conditional Access Remove Access During Offboarding Best Practices Troubleshooting User Cannot Sign In User Is Assigned but Does Not Appear in AutoElevate Group Members Cannot Sign In User Has the Wrong Role User Can Sign In but Cannot Access a Company SSO Previously Worked but Stopped When to Contact CyberFOX Support Security & Sync Behavior Authentication Authorization User and Role Changes Administrator Consent Sensitive Troubleshooting Data Related Articles

Overview


Single Sign-On (SSO) with Microsoft Entra ID allows authorized administrators and technicians to access the AutoElevate Admin Portal using their Microsoft identity. This centralizes authentication, supports Microsoft Entra security controls, and allows AutoElevate roles to be assigned through the AutoElevate Enterprise Application.

This integration is intended for administrators and technicians who require access to the AutoElevate Admin Portal. It does not provide SSO access for managed end users.

 

What Entra ID SSO Does


After the integration is enabled, AutoElevate creates an Enterprise Application in Microsoft Entra ID. Administrators can then assign users or groups to an AutoElevate role through that application.

Users select Log In with Entra ID on the AutoElevate Admin Portal login page. Microsoft authenticates the user, and AutoElevate uses the assigned application role to determine whether the user can access the portal.

Each user must be assigned one AutoElevate role. The email address of the AutoElevate user must match the email address associated with the Microsoft Entra ID account.

 

Before you Begin


Confirm the following requirements before enabling the integration:

  • You are signed in to AutoElevate as an AE Administrator.
  • You have access to a Microsoft Entra ID account authorized to approve the requested application permissions.
  • Microsoft Entra multi-factor authentication is enabled for users who will sign in through the identity provider.
  • You have identified which administrators, technicians, or groups require access.
  • Each user will be assigned only one AutoElevate role.
  • Each user's AutoElevate email address matches their Microsoft Entra ID account.
  • You understand that this integration grants access to the AutoElevate Admin Portal, not the endpoint agent or end-user interface.

The existing article identifies Global Administrator as an example of a Microsoft role with sufficient permissions. The exact role required may depend on the Microsoft tenant's application-consent policies. 

Microsoft Entra Licensing for Group Assignment

Microsoft documents that group-based Enterprise Application assignment requires Microsoft Entra ID P1 or P2. Assignments also do not cascade through nested groups. If group assignment is unavailable or a nested group member cannot access AutoElevate, verify the tenant licensing and assign a supported group or the user directly. 

GCC Entra ID Limitations

GCC Entra ID is not fully supported by the AutoElevate integration. GCC users may be able to sign in using Entra ID, but automated user synchronization is unavailable. User creation and role changes must be managed manually in the AutoElevate Admin Portal. 

GCC High compatibility is not documented as supported in the current public article. Confirm the tenant type with CyberFOX Support before implementation.


 

Enable Entra ID SSO


Start the SSO Setup

  1. Sign in to the AutoElevate Admin Portal as an AE Administrator then Open Settings.
  2. Locate Admin Portal & Mobile App Authentication and Find Single Sign On (SSO) with Entra ID.
  3. Select the pencil icon to edit the configuration.

 

 

Authenticate and Grant Consent

  1. Sign in using a Microsoft Entra ID administrator account authorized to approve the integration.
  2. Review the requested permissions.
  3. If appropriate for your organization, select the option to consent on behalf of the organization.
  4. Accept the permissions.
  5. Return to AutoElevate and confirm that SSO is enabled.

A successful setup creates the AutoElevate Enterprise Application in the connected Microsoft Entra tenant.
 

Delegate MFA to a Microsoft Entra Custom Control

Organizations using a third-party MFA provider through a Microsoft Entra Custom Control can delegate MFA enforcement to that control.

  1. In the AutoElevate Admin Portal, open Settings.
  2. Edit Single Sign On (SSO) with Entra ID.
  3. Select Delegate MFA to Custom Control in Entra ID.


     
  4. Review and accept the displayed terms.
  5. Select Save.

Enable this option only when the Microsoft tenant is already configured to enforce MFA through the intended Custom Control.


 

Troubleshoot the Initial SSO Connection


The Microsoft Sign-In Page Does Not Open

Selecting Enable SSO with Entra ID should redirect the browser to Microsoft. If AutoElevate displays a message but the Microsoft sign-in page does not open, the authorization process cannot finish and the Enterprise Application may not be created.

Possible symptoms include:

  • No Microsoft sign-in page appears.
  • The AutoElevate page refreshes without continuing.
  • The browser reports that a pop-up or redirect was blocked.
  • SSO remains disabled.
  • No AutoElevate application appears under Microsoft Entra Enterprise Applications.

Check the Browser

  1. Allow pop-ups and redirects for the AutoElevate Admin Portal.
  2. Temporarily disable extensions that block scripts, authentication windows, or cross-site redirects.
  3. Retry the process in a current version of Microsoft Edge or Google Chrome.
  4. If the problem continues, open the browser's developer tools and review the Console and Network tabs for blocked requests or authentication errors.
  5. Record any error messages before retrying.

Use a private browsing session only as a troubleshooting test. Browser restrictions or required extensions may behave differently in a private session.

Check Microsoft Entra ID

Confirm that:

  • The administrator is connected to the correct Microsoft tenant.
  • The account is allowed to approve the requested permissions.
  • Tenant-wide consent settings are not preventing approval.
  • Conditional Access or application-control policies are not blocking the authorization process.
  • An AutoElevate Enterprise Application was not created during an earlier attempt.

If an AutoElevate Enterprise Application already exists, record its Application ID, assignments, and configuration before changing or removing anything.

Retry the Connection

  1. Sign out of the AutoElevate Admin Portal.
  2. Close the affected browser session.
  3. Start a new browser session.
  4. Sign back in as an AE Administrator.
  5. Return to Settings and edit Single Sign On (SSO) with Entra ID.
  6. Select Enable SSO with Entra ID.
  7. Complete the Microsoft authentication and consent process.
  8. Confirm that the AutoElevate Enterprise Application now appears in Microsoft Entra ID.

 

Assign Users, Groups, and Roles


Enabling SSO does not automatically grant every tenant user access to AutoElevate. Users or groups must be assigned to the AutoElevate Enterprise Application and mapped to an AutoElevate role.

Microsoft supports assigning individual users or groups to Enterprise Applications. When an application exposes roles, the administrator can select the appropriate role while creating the assignment. 

Assign a User or Group

  1. Sign in to the Microsoft Entra admin center.
  2. Open Enterprise Applications.
  3. Select All applications. Search for and select AutoElevate.


     
  4. Open Users and groups.


     
  5. Select Add user/group.
  6. Under Users and groups, select None Selected. The Select the user or group that requires access. Under Select a role, choose the appropriate AutoElevate role. Select Assign.


     

Microsoft Entra group assignments do not apply through nested group membership. Assign the applicable group directly or assign the individual user. 

Verify the Assignment

Confirm that:

  • The user or group appears in the Enterprise Application assignment list.
  • The correct AutoElevate role is displayed.
  • The user is not assigned multiple AutoElevate roles.
  • The user's email address matches their AutoElevate account.
  • The user is accessing the correct AutoElevate portal.

The current article states that a new assignment can take approximately 30 seconds to one minute to propagate. 

Complete Company Access Configuration

When a newly assigned user signs in for the first time, AutoElevate administrators may receive an email requesting that the user's company access be configured.

An administrator can also create the AutoElevate user before the first SSO login and assign the required company access in advance.

Role assignment controls the user's AutoElevate portal role. Company access determines which managed companies the user can access. Both must be configured appropriately.

Sign In With Entra ID

After the assignment has propagated:

  1. Open the AutoElevate Admin Portal login page.
  2. Select Log In with Entra ID.
  3. Authenticate using the assigned Microsoft account.
  4. Complete MFA when required.
  5. Confirm that the expected companies and administrative functions are available.

 

Configure Co-Managed Users


Co-managed users should be created in AutoElevate before they are invited and assigned through Microsoft Entra ID.

Create the AutoElevate User

  1. Open Users in the AutoElevate Admin Portal.
  2. Create the user.
  3. Assign the appropriate AutoElevate role.
  4. Select the companies the user is permitted to access.
  5. Select Save without sending the AutoElevate invitation email.

Add and Assign the External User

  1. Add the co-managed user to your Microsoft Entra tenant as an external user.
  2. Confirm that the external user's email matches the AutoElevate account.
  3. Open the AutoElevate Enterprise Application.
  4. Assign the external user to the appropriate AutoElevate role.
  5. Have the user sign in using Log In with Entra ID.

An authorized Microsoft Entra administrator must approve the permissions required for the co-managed tenant configuration. 

Enforce SSO for Existing Users


Existing AutoElevate users may continue to have a local AutoElevate password until it is removed.

To require an existing user to authenticate through Microsoft Entra ID:

  1. Open Users in the AutoElevate Admin Portal.
  2. Locate the user.
  3. Open the Actions menu.
  4. Select Remove Password.
  5. Confirm that the user has a valid Enterprise Application assignment and AutoElevate role.
  6. Have the user test Log In with Entra ID.

Do not remove the user's password until SSO has been successfully tested. Removing the password before confirming the Microsoft assignment could prevent the user from accessing the portal.

Maintain Emergency Administrative Access

Before enforcing SSO for all administrators, maintain a documented emergency-access process. This could include a carefully controlled local administrator account if supported by your organization's security policy. Emergency credentials should be stored securely, monitored, and tested according to your access-control procedures.

 

Advanced Use Cases


Manage Technician Access Through Groups

Partners with multiple technicians can assign an eligible Microsoft Entra group to the AutoElevate Enterprise Application instead of managing every technician individually.

Use separate groups when technicians require different AutoElevate roles. Do not place one person into multiple assigned groups that map to different AutoElevate roles.

Preconfigure New Administrators

Create the user in AutoElevate before their first SSO login when company access must be assigned in advance. Confirm that the AutoElevate and Microsoft email addresses match exactly.

Apply Microsoft Conditional Access

Because Microsoft handles the identity-provider authentication, organizations can evaluate whether their existing Conditional Access requirements should apply to the AutoElevate Enterprise Application. Test new policies with a limited group before broad enforcement to avoid unintentionally blocking AutoElevate administrators.

Remove Access During Offboarding

When an administrator or technician no longer requires AutoElevate access:

  1. Remove the user from the applicable Enterprise Application assignment or assigned group.
  2. Disable or remove the AutoElevate user as required by your offboarding process.
  3. Review the user's company access and administrative activity.
  4. Confirm that the user can no longer authenticate.

Removing a Microsoft assignment and disabling an AutoElevate account should be treated as separate validation steps.

 

Best Practices


  • Use dedicated groups for each AutoElevate role.
  • Assign the least-privileged role required.
  • Avoid nested groups because Microsoft Entra Enterprise Application assignments do not cascade to nested group members. 
  • Confirm email-address matching before troubleshooting synchronization.
  • Test SSO with a pilot administrator before enforcing it broadly.
  • Confirm successful SSO before removing a user's local password.
  • Maintain an emergency administrative-access procedure.
  • Review Enterprise Application assignments regularly.
  • Remove access promptly when a technician changes roles or leaves the organization.
  • Document which Microsoft administrators can approve the integration.
  • Review Microsoft sign-in and AutoElevate activity when investigating unauthorized-access concerns.
     

Troubleshooting


User Cannot Sign In

Verify that:

  • SSO is enabled in AutoElevate.
  • The user is assigned to the AutoElevate Enterprise Application.
  • The user has exactly one AutoElevate role.
  • The user's email addresses match.
  • The user is selecting Log In with Entra ID.
  • Microsoft MFA has been completed.
  • Conditional Access is not blocking the sign-in.
  • Company access has been configured in AutoElevate.

User Is Assigned but Does Not Appear in AutoElevate

Wait for the assignment to propagate, then confirm that the user has attempted an SSO login.

If the user must have company access before their first login, create the user manually in AutoElevate and confirm that the email address matches the Microsoft account.

Group Members Cannot Sign In

Confirm that:

  • The group is assigned directly to the Enterprise Application.
  • The tenant has the licensing required for group-based assignment.
  • The affected person is a direct member of the assigned group.
  • The group is mapped to an AutoElevate role.
  • The user is not receiving conflicting role assignments.

Microsoft states that nested group memberships are not supported for Enterprise Application assignment. 

User Has the Wrong Role

Review the user's direct assignments and assigned group memberships in Microsoft Entra ID.

Ensure that the user receives only one AutoElevate role. Remove conflicting assignments and allow the change to propagate before testing again.

User Can Sign In but Cannot Access a Company

Microsoft Entra role assignment and AutoElevate company access are separate controls.

An AutoElevate administrator must edit the user and grant access to the appropriate managed companies.

SSO Previously Worked but Stopped

Check:

  • Microsoft account status
  • Enterprise Application assignment
  • Group membership
  • AutoElevate user status
  • AutoElevate role assignment
  • Company access
  • Conditional Access results
  • Microsoft Entra sign-in logs
  • Recent tenant-consent or Enterprise Application changes

Do not delete and recreate the Enterprise Application as an initial troubleshooting step.

Note: Required Microsoft permissions and consent requirements may vary by tenant configuration. If your organization uses custom Entra ID restrictions, review those policies before attempting setup.

 

 

When to Contact CyberFOX Support


If the issue persists after completing the troubleshooting steps above, contact CyberFOX Support and include the following information:

  • AutoElevate organization name
  • Microsoft Entra ID Tenant ID
  • Browser name and version
  • Screenshot of the message displayed after selecting Enable SSO with Entra ID
  • Browser Console errors (F12 Developer Tools)
  • Confirmation whether an AutoElevate Enterprise Application exists in Microsoft Entra ID
  • Date and time of the most recent failed attempt
  • Any Conditional Access, application consent, or tenant restrictions that may affect authentication

Providing this information upfront can significantly reduce troubleshooting time and help identify tenant-specific configuration issues more quickly.

Security & Sync Behavior


Authentication

Microsoft Entra ID performs the identity-provider authentication when the user selects Log In with Entra ID. Microsoft MFA and applicable Conditional Access requirements are evaluated through the connected tenant.

Authorization

The Enterprise Application role determines the AutoElevate role assigned to the user. AutoElevate company access is managed separately in the AutoElevate Admin Portal. A successful Microsoft login does not automatically mean the user has access to every managed company.

User and Role Changes

Allow time for new assignments and role changes to propagate before testing. GCC environments do not support automated user syncing or automatic reflection of role changes. Those users must be created and managed manually in AutoElevate. 

Administrator Consent

Only an authorized Microsoft administrator should approve the integration. Review the requested permissions before granting consent and periodically review the Enterprise Application, its assignments, and its owners.

Sensitive Troubleshooting Data

Screenshots and browser logs may contain tenant identifiers, usernames, URLs, or authentication details. Review collected information before sharing it with Support and never submit passwords, MFA codes, session tokens, or client secrets.

Related Articles


  • AutoElevate Features & Troubleshooting
  • SSO with Entra ID (Azure AD) for AutoElevate
single sign-on azure ad identity management azure auth sso sso with azure ad entra id autoelevate admin consent application consent enterprise application microsoft 365 single sign-on sso azure ad microsoft authentication global administrator user provisioning role mapping browser troubleshooting pop-up blocker redirect failure idp identity provider enterprise apps tenant id authentication troubleshooting microsoft entra login issues security settings conditional access autoelevate administrator azure integration sso setup sso troubleshooting cyberfox autoelevate administrator access microsoft entra id role assignment technician access user assignment group assignment external user co-managed user mfa multi-factor authentication tenant consent role synchronization company access login troubleshooting

Was this article helpful?

Yes
No
Give feedback about this article

Related Articles

  • Settings Overview
CyberFOX

PRACTICAL CYBERSECURITY FOR LEAN IT TEAMS

Platforms
  • Privileged Access Management
  • Password Management
  • DNS Filtering
  • SASE
Industry
  • Higher Education
  • K-12 Education
  • State and Local Government
  • Manufacturing
Company
  • About
  • Awards
  • Partnerships
  • Trust & Legal
  • Contact
  • Login
  • FAQ
  • Referral Program
  • Support
© 2026 CYBERFOX LLC ALL RIGHTS RESERVED | Privacy Policy | Terms of Service | Sitemap
Expand