Using Microsoft Entra ID for single sign-on
===========================================

Admins can integrate RingCentral with Microsoft Entra ID (formerly known as Azure Active Directory) to use for single sign-on (SSO).

Configuring SSO for RingCentral in Microsoft Entra ID
-----------------------------------------------------

* Go to [Microsoft Azure](https://portal.azure.com/ "") and sign in.
* Under Azure services, click **Microsoft Entra ID** . If it isn't listed here, use the search bar to find and select the service.

  ![Microsoft Entra ID](https://assets.ringcentral.com/content/dam/xml-assets/sf-migration/en_US/RC_US/RingCentral_MVP/Single-Sign-On-Integrate-RingCentral-Azure-Active-Directory/images/MSEntra1.png)

* Click **Add** (a), then select **Enterprise application** (b).

  ![](https://assets.ringcentral.com/content/dam/xml-assets/sf-migration/en_US/RC_US/RingCentral_MVP/Single-Sign-On-Integrate-RingCentral-Azure-Active-Directory/images/AzureSSOconfig2.png)

* In the search bar, type in **RingCentral** , then press **Return**.
* In the search results, click the **RingCentral** app.

  ![Browse Microsoft Entra Gallery](https://assets.ringcentral.com/content/dam/xml-assets/sf-migration/en_US/RC_US/RingCentral_MVP/Single-Sign-On-Integrate-RingCentral-Azure-Active-Directory/images/MSEntra2.png)

* At the bottom of the right-hand panel, click **Create**.
* Click **Get started** in the **Set up single sign on** card.
* Select **SAML** .

  ![](https://assets.ringcentral.com/content/dam/xml-assets/sf-migration/en_US/RC_US/RingCentral_MVP/Single-Sign-On-Integrate-RingCentral-Azure-Active-Directory/images/AzureSSOconfig4.png)

* Click **Edit** to the right of *Basic SAML Configuration* .

  ![](https://assets.ringcentral.com/content/dam/xml-assets/sf-migration/en_US/RC_US/RingCentral_MVP/Single-Sign-On-Integrate-RingCentral-Azure-Active-Directory/images/AzureSSOconfig5.png)

* Remove the URLs in the following fields. You can click on the **Trash** icon.
  * US/CA customers:
    * **Identifier (Entity ID)**: https://ssoeuro.ringcentral.com
    * **Reply URL (Assertion Consumer Service URL)**: https://ssoeuro.ringcentral.com/sp/ACS.saml2

  * EU customers:
    * **Identifier (Entity ID)**: https://sso.ringcentral.com
    * **Reply URL (Assertion Consumer Service URL)**: https://sso.ringcentral.com/sp/ACS.saml2

* Add the following URLs in the respective fields. Copy the URLs exactly as shown below.
  * US/CA customers:
    * **Identifier (Entity ID)**: https://sso.ringcentral.com
    * **Reply URL (Assertion Consumer Service URL)**: https://sso.ringcentral.com/sp/ACS.saml2
    * **Relay State**: https://service.ringcentral.com/mobile/ssoLogin

  * EU customers:
    * **Identifier (Entity ID)**: https://ssoeuro.ringcentral.com
    * **Reply URL (Assertion Consumer Service URL)**: https://ssoeuro.ringcentral.com/sp/ACS.saml2
    * **Relay State**: https://service.ringcentral.co.uk/mobile/ssoLogin

* Save the configuration.
* Copy the URL from the **App Federation Metadata Url** field to import to your RingCentral account.

To complete integration, follow the steps in [Setting up single sign-on in the Admin Portal](https://support.ringcentral.com/article-v2/1149.html?brand=RingCentral&product=RingEX&language=en_US "").

Managing assignments in Microsoft Entra ID
------------------------------------------

By default, *Assignment Required* is set to **Yes** for the application. When turned on, users must be added to a direct or group assignment in the application. You can also turn the *Assignment Required* to **No**.

To add direct users or group assignments:

* Go to [Microsoft Azure](https://portal.azure.com/ "") and sign in.
* Under Azure services, click**Microsoft Entra ID**. If it isn't listed here, use the search bar to find and select the service.
* In the left menu, click **Enterprise applications**.
* Click **RingCentral** in the list.
* In the left menu, click **Users and groups**.
* Click **Add user/group** .

  ![Add user group](https://assets.ringcentral.com/content/dam/xml-assets/sf-migration/en_US/RC_US/RingCentral_MVP/Single-Sign-On-Integrate-RingCentral-Azure-Active-Directory/images/MSEntra3.png)

* Under Users and groups, click **None** selected.

  ![](https://assets.ringcentral.com/content/dam/xml-assets/sf-migration/en_US/RC_US/RingCentral_MVP/Single-Sign-On-Integrate-RingCentral-Azure-Active-Directory/images/MSEntra4.png)

* Check the boxes next to the users and groups you want to add, then click **Select**.
* Click **Assign**.

To turn off the *Assignment Required* toggle:

* Go to [Microsoft Azure](https://portal.azure.com/ "") and sign in.
* Under Azure services, click **Microsoft Entra ID** . If it isn't listed here, use the search bar to find and select the service.

  ![Microsoft Entra ID](https://assets.ringcentral.com/content/dam/xml-assets/sf-migration/en_US/RC_US/RingCentral_MVP/Single-Sign-On-Integrate-RingCentral-Azure-Active-Directory/images/MSEntra1.png)

* In the left menu, click **Enterprise applications**.
* Click **RingCentral** in the list.
* In the left menu, click **Properties** .

  ![Click Properties](https://assets.ringcentral.com/content/dam/xml-assets/sf-migration/en_US/RC_US/RingCentral_MVP/Single-Sign-On-Integrate-RingCentral-Azure-Active-Directory/images/MSEntra5.png)

* Click **No** next to *Assignment required?*.
* Click **Save** .

  ![turn off assignment](https://assets.ringcentral.com/content/dam/xml-assets/sf-migration/en_US/RC_US/RingCentral_MVP/Single-Sign-On-Integrate-RingCentral-Azure-Active-Directory/images/MSEntra6.png)

