Prerequisites
An active Microsoft Entra ID tenant
Administrative permissions in Microsoft Entra (for example, Cloud Application Administrator)
Access to the Falcon Hub security settings
The SSO feature is enabled for the Falcon Hub
Step 1: Register a new application in Microsoft Entra ID
Sign in to the Microsoft Entra admin center.
Go to App registrations.
Select New registration.
Enter a name for the application, for example: Falcon.
Under Supported account types, choose the option that matches your organization (for example, Accounts in this organizational directory only).
Select Register.
Note the following values:
Application (client) ID
Directory (tenant) ID
Go to Certificates & secrets.
Select New client secret.
Enter a description and choose an Expires value.
Select Add.
Copy and store the client secret Value (this is only shown once).
Step 2: Configure SSO in Falcon
Sign in to Falcon with the appropriate permissions.
Go to Security & Privacy.
Open Authentication.
Select Manage identity providers.
Create a new identity provider.
Enter the following information:
Issuer:
βhttps://login.microsoftonline.com/<tenant-id>/v2.0
β(Replace<tenant-id>with your Directory (tenant) ID from Microsoft Entra ID.)Client ID:
The Application (client) ID from Microsoft Entra IDClient secret:
The client secret Value you generated earlier
Select Save.
Copy the Callback URL by clicking it.
Step 3: Finish configuration in Microsoft Entra ID
In the Falcon app registration in Microsoft Entra ID, go to Authentication.
Select Add a platform.
Choose Web.
Paste the Callback URL from Falcon into Redirect URI.
Select Configure.
Step 4: Test the configuration
In Falcon, select Sign in with this identity provider, or copy the provider URL and open it in a browser.
You will be redirected to Microsoft.
Select your user account or sign in.
Accept the consent prompt for the Falcon application (if prompted).
You will receive an email from Falcon with further instructions.
Open the confirmation link from the email.
If required, confirm your identity with your password.
Your user is now successfully linked to your SSO provider.
Optional: Assign users
In Microsoft Entra ID, go to Enterprise applications and select the Falcon application.
Under Properties, set Assignment required? to Yes.
Select Save.
Go to Users and groups and select Add user/group.
Select the users or groups who should have access to Falcon and confirm the assignment.
