Connect Microsoft Entra ID (or another SAML 2.0 IdP) under Settings → SAML SSO. Owners and Admins manage this page.

https://app.np4th.com):| Field | URL |
|---|---|
| Entity ID | https://app.np4th.com/api/auth/saml/{slug} |
| ACS (Reply URL) | https://app.np4th.com/api/auth/saml/{slug}/acs |
| SP metadata | https://app.np4th.com/api/auth/saml/{slug}/metadata |
| Login | https://app.np4th.com/api/auth/saml/{slug}/login |
np4th-sp-metadata.xml) for your IdP.Accounts match by Entra object ID claim http://schemas.microsoft.com/identity/claims/objectidentifier. Profile field placeholder: Entra object ID (oid).
Under Email domains, list one domain per line for SSO discovery. Public providers (gmail, outlook, and similar) cannot be claimed.
| Setting | Purpose |
|---|---|
| Admin groups | Entra group object IDs and/or names → Admin |
| User groups | Entra group object IDs and/or names → User |
| Default role if no group match | User or Admin |
| Require Entra group membership to sign in | Block users with no matching group |
| JIT provision users on first SSO sign-in | Create users automatically on first login |
Highest group match wins. Owner is not assigned by default SSO mapping—Owners remain break-glass accounts.
With enforce on, non-Owner users must use SSO. Keep at least one active Owner who can still use password sign-in.
If SSO misconfiguration locks out Admins/Users:
?local=1 / ?nosso=1 on the dashboard).Title on that page: NP4th Owner break-glass login.