Setting Up SSO with Microsoft Entra ID (Azure AD)
Single sign-on lets your team log in to Dewy with their Microsoft work accounts. Setup happens in two places: your Dewy account and your Microsoft Entra ID tenant (formerly Azure Active Directory). You will likely need your IT administrator for the Microsoft side. A Microsoft Entra ID plan that supports enterprise applications is required.
Part 1: Turn on SSO in Dewy
- Log in to your Dewy account.
- Click Settings, then Security.
- Switch the Single Sign-On toggle to On.
- Choose your Sign In Method from the dropdown.
- Leave this page open. It shows two pre-populated values, Sign-on URL and SP Entity ID, that you will paste into Microsoft in Part 2.
Part 2: Create the application in Microsoft Entra ID
- In a new tab, log in to the Microsoft Entra admin center.
- Go to Enterprise applications and click New application.
- Click Create your own application.
- Name it with your Dewy account address, for example yourpractice.dewy.io, select Non-gallery, and click Create.
- In the new application, under Manage, click Single sign-on, then choose SAML.
- Click Edit on Basic SAML Configuration and fill in:
- Identifier (Entity ID): paste the SP Entity ID value from Dewy
- Reply URL (Assertion Consumer Service URL): paste the Sign-on URL value from Dewy
- Logout URL: https://yourpractice.dewy.io/admin/index.php?action=logout (replace yourpractice with your account name)
- Click Save. Note that the fields appear in a different order in Dewy and Microsoft; match them by name, not position.
- Still on the SAML-based Sign-on page, under SAML Signing Certificate, click Download next to Federation Metadata XML.
- Open the downloaded XML file in a text editor and copy its entire contents.
Part 3: Finish in Dewy
- Back in your Dewy account, paste the XML contents into the SAML Metadata field.
- Set Name of Secure Login Provider to something your team will recognize, for example Microsoft Single Sign-On.
- Click Save settings.
Test it
- In Microsoft Entra, return to the SAML-based Sign-on page for the application.
- Scroll to the bottom and click Test.
- Assign at least one user or group to the application under Users and groups, then have that person sign in to Dewy through the new SSO option.
Keep one admin login with a regular password until SSO is confirmed working, so nobody gets locked out. If the test fails, send a screenshot of the error through the help bubble in the bottom right corner of your Dewy account.