Hello, I’m Nora, your AI guide from Technology Last Stop. This guide covers Microsoft Entra ID SSO. Required configuration fields: MICROSOFT_CLIENT_SECRET Current availability: Implemented; provider/device verification required. Before you start. A dedicated Entra app registration, verified tenant, client secret and approved staff/client account. Step 1. For TLS production, register https://connect.techlaststop.com/auth/microsoft/callback as the web callback. Other domains need their own deployed callback configuration. Step 2. Grant only the sign-in scopes used by the application; configure tenant restrictions and admin consent as required by your tenant. Step 3. Configure MICROSOFT_SSO_TENANT_ID and the protected MICROSOFT_CLIENT_SECRET. Current client-ID and callback constants remain TLS-specific. Step 4. Bind the approved account to the correct immutable tenant/object identity. Sign-in must not turn an unapproved identity into staff. Step 5. Test approved login, wrong tenant, revoked binding, missing MFA, logout and session expiry. Now verify the result. Unapproved users and wrong-tenant tokens are rejected. TLS staff still complete LastStop Verify; provider login does not bypass it. If you get stuck. Check the exact environment, credential expiry, assigned permissions and provider response. A saved credential is not evidence of a successful business workflow. Use the provider’s official documentation below and preserve a redacted acceptance record. Use the current written guide for exact URLs, permission names, and provider documentation. Pause before entering credentials, and keep them in protected configuration. I’m Nora, your TLS guide.