Configuring single sign-on between Microsoft Entra ID and Lucen Track
In this article, you'll learn how to configure SSO through Microsoft Entra ID so you can log in seamlessly and securely to Lucen Track
Here's how to configure single sign-on between Microsoft Entra ID and Lucen Track. The setup happens in two places. First in Entra to create the application, then back in Lucen Track to paste in the values Entra gives you. Have both open side by side.
Step 1: Grab your Service Provider details from Lucen Track:
In Lucen Track, go to Workspace Settings > Security, and select "Configure SSO (SAML 2.0)". Two values here are what Entra needs:
Step 2: Create the application in Microsoft Entra:
1. Sign in to the Microsoft Entra admin center as an admin.
2. Go to Identity > Applications > Enterprise applications > New application.
3. Choose Create your own application, name it "Lucen Track", and select Integrate any other application you don't find in the gallery (Non-gallery).
4. Open the new app and go to Single sign-on > SAML.
5. Under Basic SAML Configuration, either upload the SP metadata file from Step 1, or enter manually:
7. Under SAML Certificates, download the Certificate (Base64).
8. Note the values in the Set up Lucen Track section. You'll need the Login URL and Microsoft Entra Identifier.
Step 3: Enter the Entra values back in Lucen Track:
Return to the SSO settings page and fill in:
Step 1: Grab your Service Provider details from Lucen Track:
In Lucen Track, go to Workspace Settings > Security, and select "Configure SSO (SAML 2.0)". Two values here are what Entra needs:
- SAML Endpoint URL (ACS): the "Reply URL" Entra asks for (e.g.
https://.../api/accounts/2/login/saml/consume) - Download SP Metadata: click this to download an XML file. It's the easiest way to configure Entra, since you can upload it directly instead of typing values by hand.
Step 2: Create the application in Microsoft Entra:
1. Sign in to the Microsoft Entra admin center as an admin.
2. Go to Identity > Applications > Enterprise applications > New application.
3. Choose Create your own application, name it "Lucen Track", and select Integrate any other application you don't find in the gallery (Non-gallery).
4. Open the new app and go to Single sign-on > SAML.
5. Under Basic SAML Configuration, either upload the SP metadata file from Step 1, or enter manually:
- Identifier (Entity ID) and Reply URL (ACS URL) from the metadata file / the SAML Endpoint URL in Lucen Track.
7. Under SAML Certificates, download the Certificate (Base64).
8. Note the values in the Set up Lucen Track section. You'll need the Login URL and Microsoft Entra Identifier.
Step 3: Enter the Entra values back in Lucen Track:
Return to the SSO settings page and fill in:
- Issuer ID: use theMicrosoft Entra Identifierfrom Entra
- Login URL (IDP): use theLogin URLfrom Entra
- X.509 Certificate: open the Base64 certificate in a text editor and paste its contents here
Save the settings.
Step 4: Assign users and test:
In Entra, go to your app > Users and groups and assign the people (or groups) who should have access. Then test the login with a test account while "Allow username/password login" is still on. That toggle is your safety net if something's misconfigured.
Once you've confirmed SSO works end to end, turn "Allow username/password login" off to require SSO for everyone.