With SSO, people must sign in with their Microsoft work account before they can open your portal. Access can either be granted to everyone in your company, or only one group.
This is what people see when they open an SSO-locked portal:
SSO can also auto-fill each person's name and email on forms, saving time and confirming who sent the request.
Before you start
You need an Enterprise plan in Journeys, with admin or editor access. Your IT team also needs to complete steps 1 and 2 in Microsoft Entra ID, where your company's work accounts are managed.
Forward this article to IT and let them know who should get portal access: the whole company, or a specific group. Then either:
Add them as a Journeys user so they can complete step 3 too (remove their access afterwards), or
Ask them to send you the client ID, tenant ID and group object ID (if any), so you can complete step 3 yourself.
Step 1: Register an app in Microsoft Entra ID
This creates the client ID and tenant ID that Journeys needs.
Go to entra.microsoft.com and sign in.
Go to Entra ID → App registrations, then click New registration.
In Name, enter something you'll recognize, for example "Journeys portal".
Under Supported account types, choose Single tenant only, followed by your organization's name.
Under Redirect URI, open Select a platform and choose Single-page application (SPA).
In the field beside it, enter
https://portal.50skills.app, or your own domain if you use one for your portal (e.g.https://mycompany.com).Click Register.
On the Overview page, copy the Application (client) ID and the Directory (tenant) ID. You'll paste both into Journeys in step 3.
Step 2 (optional): Limit access to one group
Skip this step if everyone in your organization should be able to sign in.
Add group info to sign-ins
In your app registration, open Token configuration and click Add groups claim.
Select Security groups.
Under Customize token properties by type, expand ID and make sure that Group ID is selected.
Click Add. The claim now appears in the Optional claims table.
Create the group
If you already have a group, skip to step 7 and just copy the group's object ID.
Go to Entra ID → Groups → All groups, then click New group.
In Group type, select Security.
Enter a Group name, for example "Journeys employee portal access".
Check that Membership type is Assigned. It usually is already.
Under Members, click No members selected and add the people who should have access.
Once done, click Create.
Open the new group and copy its object ID.
Step 3: Turn on SSO in Journeys
Have your IDs ready before you start. The portal is closed to everyone from step 3 until you click Save.
In Journeys, go to Settings → Portals.
Select the portal you want to lock and open the Security tab.
Select Azure (SSO) Login. This saves straight away, and from here until step 7 the portal is closed to everyone.
Paste the Directory (tenant) ID into Azure Tenant ID.
Paste the Application (client) ID into Azure Client ID (Application ID).
If you created a group, paste its Object ID into Authorized Group ID. Leave it empty to let in everyone in your organization.
Click Save. The portal is now live again, behind Microsoft sign-in.
Pre-fill names and emails (optional)
A section called Azure settings (Advanced) appears once SSO is on. Under Default field mapping, choose how the signed-in person's name and email fill in on forms:
Do not use portal identity: people type their name and email themselves.
Pre-fill only: both are filled in, but people can change them.
Pre-fill and lock: both are filled in and can't be changed.
Test your setup
Open your portal in a private or incognito window.
Click Sign in. Microsoft opens in a pop-up, so allow pop-ups if your browser blocks it.
Sign in as someone who should have access. They should see the portal.
If you set a group, open a new private window and sign in as someone outside it. They should see a "not authorized" message.
Adding and removing people
Access is managed in the Entra ID group, not in Journeys.
Go to Entra ID → Groups → All groups.
Open your portal group.
Click Members.
Click Add members to give access, or select people and click Remove to revoke access.
Common questions
What information is shared between Journeys and Microsoft?
Journeys only sends Microsoft the sign-in request. No portal content or form data leaves Journeys. After sign-in, Microsoft sends back the person's name, email address and groups (as Object IDs): the groups decide portal access, and the name and email fill in forms if you picked a pre-fill option in step 3.
Can Entra ID admins access the portal without being in the group?
No. If you set a group, everyone must be a member, including Entra ID admins.
Can I use more than one group?
Not currently. You can set one group per portal. To include people from several teams, create one group with all of them.
Can guest users sign in?
Yes, if you add them to the group.
What happens if the group is deleted?
Nobody can access the portal. To fix, create a new group and paste its Object ID into the portal's Security tab.
How long does a sign-in last?
Group membership is checked each time someone signs in. A session then lasts
60 days, and visiting the portal near the end extends it by another 60, so a
regular visitor stays signed in.
Can I see who signed in?
Yes, in Entra ID under Monitoring & health → Sign-in logs. Please note that the free tier only keeps 7 days of logs.
Can I use SSO and a password together?
No. Each portal uses one option: none, password, or Azure SSO. If you need multiple layers of security, use Azure SSO with a group restriction.
Do I need a paid Entra ID plan?
No. Everything here works on the free tier.


























