Flamekeeper documentation

Connect Microsoft Entra ID SSO

Connect Microsoft Entra ID to Flamekeeper: register an app, copy tenant and client IDs, create a secret, verify DNS, and enable company sign-in.

Use Microsoft Entra ID, formerly Azure Active Directory, to let existing members access Flamekeeper with their company Microsoft account. Bringing employee handover and knowledge-transfer work into your company sign-in process helps teams use the authentication policies they already maintain.

Before you begin

You need a Flamekeeper Admin account, permission to register and manage applications in the intended Microsoft Entra workforce tenant, and access to your email domain's DNS records. An Entra administrator may need to handle application assignment or consent under your tenant's policies.

Invite members to Flamekeeper, have them verify their email addresses, and make sure they can use their Flamekeeper password before the first Microsoft sign-in. That first sign-in links their existing account.

Flamekeeper supports one specific tenant, one exact email domain, and one configured provider per organization. Personal Microsoft accounts and the shared common or organizations tenant endpoints are not supported. Saving Microsoft replaces an existing Okta connection; see provider switching.

1. Copy the Flamekeeper redirect URI

Open Organization settings → Microsoft SSO → Configure Microsoft Entra ID. Copy the Redirect URI shown in the dialog.

For the hosted service, the expected callback is https://api.useflamekeeper.com/auth/sso/callback. Use the exact value displayed for your environment, including the path. Keep it ready for the app registration.

2. Register the application in Entra

  1. Sign in to the Microsoft Entra admin center and select the correct workforce tenant.
  2. Go to Entra ID → App registrations → New registration.
  3. Name the app Flamekeeper.
  4. Choose Accounts in this organizational directory only. Some portal versions label this Single tenant only followed by your tenant name.
  5. Select Register.

Open the registration's Overview page and copy Application (client) ID and Directory (tenant) ID. These identify the app and tenant; do not substitute an Object ID. See Microsoft's app registration guide.

In the registration, open Authentication → Add a platform → Web, enter the callback from Flamekeeper, and save. If you already entered it as a Web redirect during registration, verify the saved value. Use the exact callback, without an added trailing slash. See Microsoft's redirect URI guidance.

3. Create and copy the client secret

Open Certificates & secrets → Client secrets → New client secret. Add a description, choose an expiry according to your organization's policy, and select Add.

Copy the Value immediately. Microsoft does not display the value again after you leave this page. The Secret ID is a different field and will not work as Flamekeeper's client secret. If the value was lost, create a new secret. Record its expiry in your team's credential-management process. See Microsoft's credential instructions.

Flamekeeper's current connection accepts a client secret; certificate upload and federated credentials are not supported in these settings. If your organization's policy requires those methods, contact your platform administrator before proceeding.

4. Assign the intended members

In Entra ID → Enterprise apps → All applications, open the application associated with your registration. Under Users and groups, choose Add user/group, select the intended members, and finish with Assign. Group assignment depends on your Entra licensing.

Have your administrator review the application's assignment and consent requirements. Where assignment is required, grant the required administrator consent before testing; do not relax tenant-wide policies to get past a login prompt. See Microsoft's assignment guide.

The Flamekeeper integration requests sign-in scopes, openid profile; it does not need mail, file, or directory-reading permissions for this workflow. Assigning a person in Entra does not create a Flamekeeper member or grant a Flamekeeper role.

5. Enter the fields in Flamekeeper

Return to Configure Microsoft Entra ID and complete the fields:

Flamekeeper field Value to enter
Email domain The exact domain used by members' Flamekeeper email addresses, such as example.com. No @, URL prefix, or path.
Directory (tenant) ID The directory ID copied from the app registration's Overview page.
Application (client) ID The application ID from that same Overview page.
Client secret The secret Value copied from Certificates & secrets.

Select Save configuration. Flamekeeper derives the tenant-specific issuer and checks provider metadata. A new connection shows Configured · disabled. Saving is not a complete login test, and the saved secret will not be shown again.

6. Verify the email domain

In the saved summary, find Verify your domain. Copy its Record name and TXT value into a new TXT record at your DNS provider.

The full record name has the form _flamekeeper-sso.example.com, and the value starts with flamekeeper-sso=. Use the complete generated value displayed in your own configuration. If your DNS editor appends the domain automatically, enter _flamekeeper-sso as the name so the domain is not repeated.

Save the DNS record, allow time for propagation, and select Verify domain in Flamekeeper. Ownership must show Verified before you can enable SSO. Configuring example.com does not include its subdomains. A domain cannot be verified for two organizations.

If you replaced Okta while keeping the same verified domain, Flamekeeper retains verification and you can proceed to activation.

7. Enable SSO and complete the first sign-in

Select Enable SSO and keep your administrator session open. In a separate private browser window:

  1. Open Flamekeeper login, enter your existing Flamekeeper email, and continue.
  2. Sign in with the intended company Microsoft account and complete any Microsoft authentication prompts.
  3. On Connect your Microsoft account, enter the same Flamekeeper email and its Flamekeeper password, not your Microsoft password. Complete Flamekeeper's existing two-factor step if required.
  4. Confirm that the correct organization and expected handover cases open.
  5. Sign out and repeat Microsoft sign-in to confirm that the established link works.

The confirmation binds the Microsoft identity to an existing Flamekeeper account. Later logins use that identity directly; mutable Microsoft email claims alone do not establish account ownership. The first-link attempt expires after ten minutes, so restart from the login page if it times out.

Members must have verified their Flamekeeper email and have an active or departing status. SSO does not accept invitations, provision accounts, or import Microsoft roles. Sign in with password instead remains available.

Troubleshooting

What you see What to check
Configure is unavailable Ask your platform administrator or Flamekeeper support to check whether SSO configuration is enabled.
Invalid tenant or issuer Copy the directory ID from the correct workforce tenant's registration. Do not enter a domain, full URL, or common.
Redirect URI mismatch Confirm the exact Flamekeeper callback is registered on the Web platform for this application.
Invalid or expired secret Use the Value, check expiry, and confirm that the secret belongs to the client ID entered in Flamekeeper.
Assignment or approval is required Ask the Entra administrator to check the enterprise application's assigned users, consent, and sign-in logs.
Account confirmation fails Use the original Flamekeeper email, its password and required two-factor step; check membership and verification. Recover a forgotten password through the normal password flow.
Domain verification fails Check the full DNS name, generated TXT value, propagation, and whether another organization holds the domain.
Settings changed or login expired Reload the settings or restart sign-in after configuration changes.

Renew the secret or disconnect

Before the secret expires, create a replacement in the same Entra app registration. In Flamekeeper, use Microsoft SSO → Edit configuration, enter the new secret value, and select Save configuration. Leaving the field blank retains the saved secret only for the same application.

Check a fresh Microsoft sign-in before deleting the old credential in Entra. Record the replacement's expiry. Changing the tenant or client ID requires credentials for that application and is not an account-relinking workflow.

Use Disable SSO to stop routing while retaining the setup, or Disconnect to remove it. Existing identity bindings remain on disconnect. Read SSO behavior and recovery before switching accounts or providers.

Keep the knowledge. Carry on with the work.

Open Flamekeeper