---
title: "Application Integration with Microsoft Entra"
canonical: "https://kb.uconn.edu/space/IKB/28612624386/Application%20Integration%20with%20Microsoft%20Entra"
format: markdown
---
> ℹ️ ## **Summary**
> ℹ️ 
> ℹ️ SSO is a [requirement for University applications](https://policy.uconn.edu/2021/08/30/system-and-application-security/), and [Microsoft Entra](https://uconn.atlassian.net/wiki/spaces/IKB/pages/28612362243) is the University’s standard platform for application integration. To get started:
> ℹ️ 
> ℹ️ Application owners should [open a ticket with the IAM team](https://techsupport.uconn.edu) and provide the [information needed to complete an integration](https://uconn.atlassian.net/wiki/spaces/IKB/pages/28612362251). They should also:
> ℹ️ 
> ℹ️ - Identify the appropriate internal or vendor-side contacts
> ℹ️ - Gather available information about the application’s supported SSO protocols and access requirements.
> ℹ️ 
> ℹ️ The IAM team is available to help guide application owners through the process, review technical details, and support integrations from planning through implementation.

## **Overview**

Single Sign-On (SSO) is a [requirement for University applications](https://policy.uconn.edu/2021/08/30/system-and-application-security/) as part of the standard approach to authentication. Integrating applications with Microsoft Entra helps ensure a consistent sign-in experience, supports centralized security controls, and aligns application access with the University’s identity and access management strategy.

Application owners play an important role in this process. In most cases, they are responsible for helping identify the appropriate vendor or technical contacts, confirming what authentication methods the application supports, and providing key information needed to begin the integration. The IAM team will work with application administrators and technical contacts throughout the process to review requirements, coordinate setup, and support onboarding to Microsoft Entra.

## **What Application Owners Need to Know**

Before requesting an SSO integration, application owners should understand that not all applications are configured the same way. Some vendors support modern standards such as SAML 2.0 or OpenID Connect (OIDC), while others may have more limited options or require vendor involvement before setup can begin.

Application owners should also be aware that SSO setup is a shared effort. The IAM team can guide the integration and configure the University side of the connection, but successful onboarding often depends on having accurate application details, a responsive vendor or technical contact, and a clear understanding of who should have access to the service.

In some cases, additional planning may be needed if the application also requires user provisioning, role-based access, group-based authorization, or custom attribute mapping. Applications hosting critical or sensitive information may also be onboarded to the access management program to ensure that user populations are managed securely and accurately.

## **How to Get Started**

To begin the SSO onboarding process, application owners should open a request with the IAM team through the appropriate University ticketing process. When submitting the request, include as much information as possible about the application and its authentication requirements.

As part of getting started, application owners should try to identify the appropriate application administrator, internal technical contact, or vendor-side contact who can help answer federation questions. This is especially important for vendor-hosted applications, where configuration details and protocol support may need to be confirmed directly with the provider.

Application owners should also identify which SSO protocols the application supports. The most common standards are:

- SAML 2.0
- OpenID Connect (OIDC)
- OAuth
- CAS

If the supported protocol is not known, the application owner should check the vendor’s documentation or contact the vendor directly before or shortly after opening the ticket. This helps reduce delays and ensures the integration can be evaluated correctly.

## **Information Required to Begin an Integration**

See the following article for the information requested to complete an integration. Not all of it is required to begin the process, and the IAM team can assist in gathering it.

[https://uconn.atlassian.net/wiki/x/CwBuqQY](https://uconn.atlassian.net/wiki/x/CwBuqQY) 

Providing complete and accurate information at the start of the request helps the IAM team assess the application, determine the appropriate integration method, and identify any issues early in the process. Missing or incomplete information can delay onboarding, especially when vendor coordination is required.

In particular, protocol support, technical contacts, required identifiers, and access requirements are critical to a successful setup. Even when not all information is available at the time the ticket is opened, submitting as much detail as possible will help move the process forward more efficiently.