Skip to main content
Microsoft renamed Azure Active Directory (Azure AD) to Microsoft Entra ID. The steps below use the current names; the older Azure AD portal labels map one to one. You register Variable as an app registration in your tenant — think of it as issuing Variable a badge that lets it ask Microsoft “who is this person?”. A tenant is your organization’s own directory in Microsoft’s cloud. You need the Application Administrator or Cloud Application Administrator role in Entra ID, or Global Administrator. Read the single sign-on overview first if you have not verified your domain in Variable.

Register the app

  1. Sign in to the Microsoft Entra admin center.
  2. Go to Identity → Applications → App registrations and select New registration.
  3. Set Name to Variable, or anything your team will recognize.
  4. Under Supported account types, choose Accounts in this organizational directory only (Single tenant). This pins sign-in to your directory, so accounts from other Microsoft tenants and personal Microsoft accounts are rejected.
  5. Under Redirect URI, choose the Web platform and enter:
    It must match exactly, including https and no trailing slash.
  6. Select Register.
On the app’s Overview page, copy two values:
  • Application (client) ID
  • Directory (tenant) ID — the ID itself, in the form xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx, not your domain name

Check the permissions

Variable asks Microsoft for your users’ name and email address, and nothing else.
  1. Open API permissions.
  2. Confirm Microsoft Graph → User.Read (Delegated) is listed. It is added by default.
  3. Select Grant admin consent for your organization. Without it, each person is asked to approve access on their first sign-in, and if your tenant blocks user consent they cannot sign in at all.
Variable matches each person to their Variable user by email address, so invite people with the address they use to sign in to Microsoft.

Create a client secret

  1. Open Certificates & secrets → Client secrets → New client secret.
  2. Give it a description such as Variable SSO and choose an expiry. Microsoft allows at most 24 months.
  3. Select Add, then copy the secret Value straight away. Microsoft shows it once; the Secret ID column is not the secret.
Write the expiry date in your calendar. When the secret expires, SSO stops working for everyone until you send us a new one.

Send us the credentials

Send us the following through an agreed-upon secure channel:
  • Provider: Microsoft
  • Application (client) ID
  • Directory (tenant) ID
  • Client secret Value
  • The email domains to cover, each verified in Variable
  • A contact who can test the sign-in
We confirm once it is switched on.

Test it

  1. Open a private browser window and go to https://app.variable.global.
  2. Enter your work email and continue. You are sent to Microsoft.
  3. Sign in. You land back in Variable.

Troubleshooting

Restrict who can sign in (optional)

By default anyone in your tenant can start a sign-in. To limit it to specific people, open the app under Enterprise applications, then Properties, set Assignment required? to Yes, and add users or groups under Users and groups. People who are not assigned are stopped by Microsoft before they reach Variable.