Register the app
- Sign in to the Microsoft Entra admin center.
- Go to Identity → Applications → App registrations and select New registration.
-
Set Name to
Variable, or anything your team will recognize. - Under Supported account types, choose Accounts in this organizational directory only (Single tenant). This pins sign-in to your directory, so accounts from other Microsoft tenants and personal Microsoft accounts are rejected.
-
Under Redirect URI, choose the Web platform and enter:
It must match exactly, including
httpsand no trailing slash. - Select Register.
- Application (client) ID
- Directory (tenant) ID — the ID itself, in the form
xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx, not your domain name
Check the permissions
Variable asks Microsoft for your users’ name and email address, and nothing else.- Open API permissions.
- Confirm Microsoft Graph → User.Read (Delegated) is listed. It is added by default.
- Select Grant admin consent for your organization. Without it, each person is asked to approve access on their first sign-in, and if your tenant blocks user consent they cannot sign in at all.
Create a client secret
- Open Certificates & secrets → Client secrets → New client secret.
- Give it a description such as
Variable SSOand choose an expiry. Microsoft allows at most 24 months. - Select Add, then copy the secret Value straight away. Microsoft shows it once; the Secret ID column is not the secret.
Send us the credentials
Send us the following through an agreed-upon secure channel:- Provider: Microsoft
- Application (client) ID
- Directory (tenant) ID
- Client secret Value
- The email domains to cover, each verified in Variable
- A contact who can test the sign-in
Test it
- Open a private browser window and go to
https://app.variable.global. - Enter your work email and continue. You are sent to Microsoft.
- Sign in. You land back in Variable.