Skip to main content

Enterprise SSO Guide — On-Prem Edition

Setting up Enterprise SSO for an on-prem Unstract deployment involves two main steps:

  1. Configure your Identity Provider — Set up your identity provider by following the relevant guide:

  2. Configure Unstract Roles — Map your identity provider's groups to Unstract roles to enable role-based access control. Follow the Unstract Roles Guide to complete this step.

Choosing an Azure AD / Entra ID mode

On-prem deployments can reach Microsoft Azure AD (Entra ID) either through Auth0 as an identity broker, or directly, with Unstract talking to Entra ID itself and no third party in the authentication path. A deployment runs one or the other.

See the mode comparison before starting — the two differ in the redirect URI you register in Entra ID, the Microsoft Graph permissions required, how groups map to roles, and which user-management features remain available inside Unstract.

Looking for cloud setup?

If you're using Unstract Cloud, see the Enterprise SSO Guide — Cloud Edition instead.