Setting Up Sign-In with Microsoft (SSO)
As of: 29 September 2026
Time required: approximately 10 minutes
Who this article is for: IT administrators whose staff should sign in to Captured Knowledge (CK) with their existing Microsoft account (Microsoft Entra ID, formerly Azure AD).
Expected results: your users sign in to Captured Knowledge with "Sign in with Microsoft" and land in your organisation's team automatically. Captured Knowledge never sees their passwords.
How sign-in works
Users sign in directly with Microsoft, at: https://app.capturedknowledge.ai/accounts/microsoft/login/
Our application "captured-knowledge-identity" (application ID b7825a85-2f10-424e-aa50-35a9ee0096f2) requests only the standard sign-in permissions: openid, profile, email and the Microsoft Graph permission User.Read (read access to the signed-in user's own profile only). Captured Knowledge receives the signed-in user's name and email address — no access to mailboxes or other data. (Connecting your mailboxes is a separate setup with its own guide.)
Captured Knowledge assigns users to your team by your tenant ID. Everyone from your tenant who signs in becomes a member of your team (role "Member"). If only certain people should be able to sign in, enable user assignment (step 2).
Step 1: Grant admin consent (recommended)
These permissions do not strictly require admin consent — users could consent individually. We still recommend tenant-wide consent so sign-in works smoothly, especially if your tenant restricts user consent. Choose one method:
Method A — consent link (recommended): as an administrator (Global Administrator, Privileged Role Administrator, Cloud Application Administrator or Application Administrator), open the following link, replacing YOUR_TENANT_ID with your organisation's tenant ID:
https://login.microsoftonline.com/YOUR_TENANT_ID/adminconsent?client_id=b7825a85-2f10-424e-aa50-35a9ee0096f2
Method B — sign in as an administrator: an administrator with one of the roles from method A signs in at https://app.capturedknowledge.ai/accounts/microsoft/login/ and selects "Consent on behalf of your organization" in the permission prompt. Only administrators see this option.
Method C — Microsoft Entra admin center: under Enterprise applications, filter by application ID b7825a85-2f10-424e-aa50-35a9ee0096f2, open "captured-knowledge-identity", then Permissions > "Grant admin consent". The application only appears there once someone from your organisation has signed in or consented.
Step 2: User assignment (optional)
If only some of your staff should be able to sign in, enable "Assignment required" in the Microsoft Entra admin center under Enterprise applications > captured-knowledge-identity > Properties, and assign the users or groups under Users and groups.
With "Assignment required", admin consent (step 1) is mandatory, because users can then no longer consent themselves. Users who are not assigned get error AADSTS50105 when signing in.
Step 3: Send us the details
Your tenant ID (Microsoft Entra admin center > Overview). We use it to assign sign-ins from your organisation to your team.
No passwords, secret keys or app registration of your own are needed; when consent is granted, Microsoft creates the enterprise application in your tenant automatically.
Notes
Conditional Access: check that your policies allow users to access approved third-party applications.
Network access: users need access to Microsoft's sign-in pages and to
https://app.capturedknowledge.ai.Revoking sign-in: remove a user's assignment (with "Assignment required") or delete the enterprise application "captured-knowledge-identity". Removing someone from the team in Captured Knowledge alone is not enough: as long as they can sign in with Microsoft, the next sign-in adds them to the team again.
If you have questions, write to us at [email protected].
Related Articles