> ## Documentation Index
> Fetch the complete documentation index at: https://launchdarkly.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Entra ID

<View title="Developer" />

<View title="Federal docs" />

<View title="EU docs" />

This topic explains how to integrate LaunchDarkly with Microsoft Entra ID (formerly Azure Active Directory). The Entra ID App Gallery includes LaunchDarkly and provides a LaunchDarkly application template that facilitates configuration.

If you want to set up SCIM provisioning with Entra ID, read [Configure SCIM](/docs/home/account/scim#configure-scim).

<Note>
  **You cannot manage teams using the UI after enabling SCIM**

  If you configure SCIM to provision resources from identity providers, you can no longer manage teams using the LaunchDarkly user interface.
</Note>

## Integrate LaunchDarkly with Entra ID

To integrate LaunchDarkly with Entra ID:

1. Log in to Entra ID.
2. Navigate to "Enterprise applications."
3. Click **New application**:

<Frame caption="The &#x22;Enterprise applications&#x22; page with &#x22;New application&#x22; called out.">
  <img src="https://mintcdn.com/launchdarkly/unfRSXbmQkdGxJjN/images/__third_party/entra-new-application.png?fit=max&auto=format&n=unfRSXbmQkdGxJjN&q=85&s=cb3d68208f423ff0db2f3bd000786af5" alt="The &#x22;Enterprise applications&#x22; page with &#x22;New application&#x22; called out." width="1169" height="220" data-path="images/__third_party/entra-new-application.png" />
</Frame>

4. Search for the LaunchDarkly application.
5. After you add it, follow the [Microsoft Entra integration with LaunchDarkly tutorial](https://learn.microsoft.com/en-us/entra/identity/saas-apps/launchdarkly-tutorial).

If your instance of Entra ID manages multiple LaunchDarkly accounts, [start a Support ticket](https://support.launchdarkly.com/hc/en-us/requests/new).

<Note>
  **Entra ID user identifier guidelines**

  During configuration, we recommend using the identifier `user.mail`, provided that every user has their email address attribute set. If you haven't set attributes for every user, use the identifier `user.userprincipalname`.
</Note>

After you set up the integration, log in to LaunchDarkly by clicking the LaunchDarkly app in Entra or through Microsoft's [My App portal](https://myapplications.microsoft.com/). To learn more, read Microsoft's [Sign in and start apps from the My Apps portal](https://support.microsoft.com/en-us/account-billing/sign-in-and-start-apps-from-the-my-apps-portal-2f3b1bae-0e5a-4a86-a33e-876fbd2a4510).

If members cannot log in after you set up SSO, read the troubleshooting article [New users are unable to log in with Entra (formerly Azure AD) once SSO is configured](https://support.launchdarkly.com/hc/en-us/articles/17256877142683-New-users-are-unable-to-log-in-with-Azure-AD-once-SSO-is-configured).

To learn how to display member names in LaunchDarkly, read the help center article [How to populate firstName and lastName claims in the LaunchDarkly UI with Entra ID](https://support.launchdarkly.com/hc/en-us/articles/37980051672987-How-to-populate-firstName-and-lastName-claims-in-the-LaunchDarkly-UI-with-Entra-ID).

## Configure team-based or role-based access

After you integrate LaunchDarkly with Entra ID, you can configure LaunchDarkly teams or LaunchDarkly roles to map with Entra ID resources. Configuring team-based access is the most common solution, because it enables you to use Just-In-Time (JIT) user provisioning with your LaunchDarkly teams and keeps team members in sync with an Entra ID group. To learn more, read [Map LaunchDarkly teams to Entra ID Security Groups](#map-launchdarkly-teams-to-entra-id-security-groups).

You can optionally configure role-based access to map LaunchDarkly custom roles to Entra ID user attributes or to Entra ID security groups. To learn more, read either [Map custom roles to Entra User Attributes](#map-custom-roles-to-entra-user-attributes) or [Map custom roles to Entra Security Groups](#map-custom-roles-to-entra-security-groups).

<Note>
  **Removing existing roles**

  SAML ignores empty fields if used in **Roles** or **customRoles**. This only applies to role-based access configured with `role` or `customRole` claims. It does not affect team-based access mapping.

  To clear all existing roles, enter an empty string in the field.
</Note>

If you are uncertain about which configuration to choose, contact your LaunchDarkly account team.

## Map LaunchDarkly teams to Entra ID Security Groups

After you integrate LaunchDarkly with Entra ID, you can map LaunchDarkly teams to Entra Security Groups. This keeps the members of your LaunchDarkly teams in sync with your Entra ID groups and enables you to use JIT user provisioning with Entra ID groups to automatically map users to LaunchDarkly teams.

There are four steps to this process:

1. [Create Security Groups in Entra ID](#create-groups-in-entra-id)
2. [Create teams in LaunchDarkly](#create-teams-in-launchdarkly)
3. [Assign Entra ID Security Groups to the LaunchDarkly Enterprise Application](#assign-entra-id-security-groups-to-the-launchdarkly-enterprise-application)
4. [Create a new Entra ID claim](#create-a-new-entra-id-claim)

### Create Security Groups in Entra ID

First, set up a Security Group in Entra ID:

1. In Entra ID, navigate to "Groups," then click **New group**.
2. Select the "Security" group type and enter a group name.
3. Click **Create**. You are returned to the groups list.
4. Copy the object ID of the group you want to link to a LaunchDarkly team:

<Frame caption="The &#x22;Groups&#x22; section with the &#x22;Object Id&#x22; column called out.">
  <img src="https://mintcdn.com/launchdarkly/unfRSXbmQkdGxJjN/images/__third_party/azure-groups-object-id-callout.png?fit=max&auto=format&n=unfRSXbmQkdGxJjN&q=85&s=d492a05e8b03004419cb9b856665a549" alt="The &#x22;Groups&#x22; section with the &#x22;Object Id&#x22; column called out." width="1056" height="477" data-path="images/__third_party/azure-groups-object-id-callout.png" />
</Frame>

You will use this group's name and object ID in the next section.

Repeat this procedure for as many groups you want to assign to LaunchDarkly teams.

### Create teams in LaunchDarkly

<Warning>
  **Map the group name and object ID to a team before proceeding**

  You must map the Entra ID group name and object ID to a LaunchDarkly team before you continue. Failing to complete this step will prevent you from creating new Entra ID claims later in the procedure.
</Warning>

Next, create a team in LaunchDarkly using your Entra ID group name and the object ID you copied from the previous step:

1. Click the **gear** icon in the left sidebar to view Organization settings.
2. Click **Teams**.
3. Click **Create team**. The "Create team" dialog appears.
4. In the **Name** field, enter the Entra ID group name you created in the previous step.
5. In the **Key** field, paste the Entra ID object ID for the group that you copied the previous section.
6. Click **Create team**.

Repeat this procedure for as many teams as you want to sync with Entra ID Security Groups.

### Assign Entra ID Security Groups to the LaunchDarkly Enterprise Application

Then, assign Entra ID Security Groups to the LaunchDarkly Enterprise Application:

1. In Entra ID, open the LaunchDarkly Enterprise Application.
2. Click **Users and groups**. The "Users and groups" screen appears:

<Frame caption="The &#x22;Users and groups&#x22; screen in Entra ID.">
  <img src="https://mintcdn.com/launchdarkly/unfRSXbmQkdGxJjN/images/__third_party/entra-users-and-groups.png?fit=max&auto=format&n=unfRSXbmQkdGxJjN&q=85&s=439072564520d9e8967ed925b6394a4d" alt="The &#x22;Users and groups&#x22; screen in Entra ID." width="857" height="782" data-path="images/__third_party/entra-users-and-groups.png" />
</Frame>

3. On the "Groups" tab, choose the group you want to edit and click **Select**. The "Add Assignment" screen appears.
4. Click **None Selected** under "Users and groups" to add a new group. The "Users and groups" screen appears.

<Frame caption="The &#x22;Users and groups&#x22; screen.">
  <img src="https://mintcdn.com/launchdarkly/unfRSXbmQkdGxJjN/images/__third_party/azure-users-and-groups-selection.png?fit=max&auto=format&n=unfRSXbmQkdGxJjN&q=85&s=fa387cd7ea7c5083c7cc32a2b7e0fb94" alt="The &#x22;Users and groups&#x22; screen." width="995" height="600" data-path="images/__third_party/azure-users-and-groups-selection.png" />
</Frame>

5. Choose the group you created in the [Create Security Groups in Entra ID](#create-security-groups-in-entra-id) step.
6. Click **Select**. You are returned to the "Add Assignment" screen.
7. Click **Assign**.

Repeat this procedure for each Entra ID Security Group you created.

### Create a new Entra ID claim

Finally, create a new Entra ID claim:

1. In Entra ID, open the LaunchDarkly Enterprise Application.
2. Click **Single sign-on**.
3. Scroll to the "Attributes & Claims" section.
4. Click **Edit**. The "Manage claims" form appears.

<Frame caption="The &#x22;Attributes & Claims&#x22; section with the &#x22;Edit&#x22; button called out.">
  <img src="https://mintcdn.com/launchdarkly/unfRSXbmQkdGxJjN/images/__third_party/entra-edit-user-attributes-callout.png?fit=max&auto=format&n=unfRSXbmQkdGxJjN&q=85&s=62a5c0c6687131daaba532fc610b3fb5" alt="The &#x22;Attributes & Claims&#x22; section with the &#x22;Edit&#x22; button called out." width="1035" height="708" data-path="images/__third_party/entra-edit-user-attributes-callout.png" />
</Frame>

5. Click "+ Add a group claim." A "Group Claims" dialog appears.
6. Select "Groups assigned to the application" under "Which groups associated with the user should be returned in the claim?"
7. Select "Group ID" as the source attribute.
8. Open the **Advanced options** section.
9. Check the "Customize the name of the group claim" box.
10. Enter `teamKey` into the **Name** field:

<Frame caption="The &#x22;Group Claims&#x22; dialog.">
  <img src="https://mintcdn.com/launchdarkly/unfRSXbmQkdGxJjN/images/__third_party/azure-group-claims.png?fit=max&auto=format&n=unfRSXbmQkdGxJjN&q=85&s=80b93e2b8e4cd391cbe61cda8c912041" alt="The &#x22;Group Claims&#x22; dialog." width="576" height="985" data-path="images/__third_party/azure-group-claims.png" />
</Frame>

11. Click **Save**. You are returned to the "Attributes & Claims" screen.

Close the "Attributes & Claims" screen to return to the "Single sign-on" page. To test your SSO configuration, click **Test** at the bottom of the page.

## Map custom roles to Entra User Attributes

After you integrate LaunchDarkly with Entra ID, you can map LaunchDarkly role and custom role attributes to Entra User Attributes using Entra claims. The LaunchDarkly Entra SSO integration provides JIT user provisioning for IdP-Initiated SSO.

To learn more about SSO provisioning for roles, read [Roles](/docs/home/account/roles).

To set up `role` and `customRole` claims in Entra ID:

1. In Entra ID, open the LaunchDarkly Enterprise Application.
2. Click **Single sign-on**.
3. Scroll to the "Attributes & Claims" section.
4. Click **Edit**.
5. Click **Add new claim**. The "Manage claim" screen appears:

<Frame caption="The &#x22;Manage claim&#x22; screen.">
  <img src="https://mintcdn.com/launchdarkly/unfRSXbmQkdGxJjN/images/__third_party/entra-manage-claim.png?fit=max&auto=format&n=unfRSXbmQkdGxJjN&q=85&s=4f6eb093da640ea98793dcb7fccee7d8" alt="The &#x22;Manage claim&#x22; screen." width="959" height="339" data-path="images/__third_party/entra-manage-claim.png" />
</Frame>

6. Enter "role" in the **Name** field.
7. Leave the source as "Attribute."
8. Choose a source attribute from the menu that is not currently mapped, such as `user.country`.
9. Click **Save**.
10. Repeat steps 5-9 with "customRole," mapping to a different unused source attribute.

## Map custom roles to Entra Security Groups

In addition to Entra User Attributes, you can also assign LaunchDarkly custom roles to Entra Security Groups.

There are five steps to this process:

1. [Create roles in LaunchDarkly](#create-roles-in-launchdarkly)
2. [Create groups in Entra ID](#create-groups-in-entra-id)
3. [Create roles for the Entra LaunchDarkly Enterprise Application](#create-roles-for-the-entra-launchdarkly-enterprise-application)
4. [Set up groups and roles in the Entra LaunchDarkly Enterprise Application](#set-up-groups-and-roles-in-the-entra-launchdarkly-enterprise-application)
5. [Update the Entra LaunchDarkly Enterprise Application SSO configuration](#update-the-entra-launchdarkly-enterprise-application-sso-configuration)

Each of these steps is outlined below.

### Create roles in LaunchDarkly

To begin, create the roles in LaunchDarkly that you want to use with the Entra LaunchDarkly Enterprise Application. Make note of each role's key, as you will need the key when you set up your Entra ID app role.

To learn how, read [Roles](/docs/home/account/roles).

### Create groups in Entra ID

After you have created your custom roles in LaunchDarkly, set up your groups in Entra ID:

1. In Entra ID, navigate to "Groups," then click **New group**.
2. Select a group type and enter a group name.
3. Click "No members selected" to add new members:

<Frame caption="A new Entra ID group.">
  <img src="https://mintcdn.com/launchdarkly/unfRSXbmQkdGxJjN/images/__third_party/entra-new-group-members.png?fit=max&auto=format&n=unfRSXbmQkdGxJjN&q=85&s=1d1beb799c695804f4fe022bcfa7bfa5" alt="A new Entra ID group." width="692" height="697" data-path="images/__third_party/entra-new-group-members.png" />
</Frame>

4. Select members from the list to add to the group, then click **Select**:

<Frame caption="Adding members to a new Entra ID group.">
  <img src="https://mintcdn.com/launchdarkly/unfRSXbmQkdGxJjN/images/__third_party/entra-new-group-members-add.png?fit=max&auto=format&n=unfRSXbmQkdGxJjN&q=85&s=299830bdfc0369d458ce180b6df0c7c2" alt="Adding members to a new Entra ID group." width="955" height="771" data-path="images/__third_party/entra-new-group-members-add.png" />
</Frame>

Your Entra ID members are now in the group.

### Create roles for the Entra LaunchDarkly Enterprise Application

Next, create roles within Entra ID:

1. In Entra ID, navigate to **Applications**.
2. Click **App registrations** in the left sidebar.
3. Click the **All applications** tab:

<Frame caption="The &#x22;All applications&#x22; tab on the &#x22;App registrations&#x22; page in Entra ID.">
  <img src="https://mintcdn.com/launchdarkly/unfRSXbmQkdGxJjN/images/__third_party/entra-app-registrations.png?fit=max&auto=format&n=unfRSXbmQkdGxJjN&q=85&s=d886dfb1f7a95b111af4ff28947142d7" alt="The &#x22;All applications&#x22; tab on the &#x22;App registrations&#x22; page in Entra ID." width="988" height="327" data-path="images/__third_party/entra-app-registrations.png" />
</Frame>

4. Click **LaunchDarkly** to open the application.
5. Navigate to "App roles" and click **Create app role**.
6. Enter the role information. The **value** must be the key of the custom role you created during the [Create custom roles in LaunchDarkly](#create-roles-in-launchdarkly) step:

<Frame caption="A new role in Entra ID with the &#x22;Value&#x22; field called out.">
  <img src="https://mintcdn.com/launchdarkly/unfRSXbmQkdGxJjN/images/__third_party/azure-new-role.png?fit=max&auto=format&n=unfRSXbmQkdGxJjN&q=85&s=99ff8c418e1a886fdc4c9884e6d85f0b" alt="A new role in Entra ID with the &#x22;Value&#x22; field called out." width="1001" height="640" data-path="images/__third_party/azure-new-role.png" />
</Frame>

7. Click **Apply**.

Repeat this procedure for each new Entra app role.

### Set up groups and roles in the Entra LaunchDarkly Enterprise Application

Then, set up groups and roles in Entra ID:

1. In Entra ID, open the LaunchDarkly Enterprise Application.
2. Click **Users and groups**. The "Users and groups" screen appears:

<Frame caption="The &#x22;Users and groups&#x22; screen in Entra ID.">
  <img src="https://mintcdn.com/launchdarkly/unfRSXbmQkdGxJjN/images/__third_party/entra-users-and-groups.png?fit=max&auto=format&n=unfRSXbmQkdGxJjN&q=85&s=439072564520d9e8967ed925b6394a4d" alt="The &#x22;Users and groups&#x22; screen in Entra ID." width="857" height="782" data-path="images/__third_party/entra-users-and-groups.png" />
</Frame>

3. On the "Groups" tab, choose the group you want to edit and click **Select**. The "Add Assignment" screen appears.
4. Click **None Selected** under "Users and groups" to add a new group. The "Users and groups" screen appears:

<Frame caption="The &#x22;Users and groups&#x22; screen.">
  <img src="https://mintcdn.com/launchdarkly/unfRSXbmQkdGxJjN/images/__third_party/azure-users-and-groups-selection.png?fit=max&auto=format&n=unfRSXbmQkdGxJjN&q=85&s=fa387cd7ea7c5083c7cc32a2b7e0fb94" alt="The &#x22;Users and groups&#x22; screen." width="995" height="600" data-path="images/__third_party/azure-users-and-groups-selection.png" />
</Frame>

5. Choose the group you created in the [Create groups in Entra ID](#create-groups-in-entra-id) step.
6. Click **Select**. You are returned to the "Add Assignment" screen.
7. Click **None Selected** under "Select a new role" to add a new role:

<Frame caption="Selecting a role to add to a group.">
  <img src="https://mintcdn.com/launchdarkly/unfRSXbmQkdGxJjN/images/__third_party/azure-select-a-role.png?fit=max&auto=format&n=unfRSXbmQkdGxJjN&q=85&s=a176c6e54805c365db39ede65980f677" alt="Selecting a role to add to a group." width="1041" height="472" data-path="images/__third_party/azure-select-a-role.png" />
</Frame>

8. Choose the role you created in the [Create roles for the Entra LaunchDarkly Enterprise Application](#create-roles-for-the-entra-launchdarkly-enterprise-application) step.
9. Click **Select**. You are returned to the "Add Assignment" screen.
10. Click **Assign**.

Repeat this procedure for each group and role you want to set up.

### Update the Entra LaunchDarkly Enterprise Application SSO configuration

Finally, update Entra's SSO configuration:

1. In Entra ID, open the LaunchDarkly Enterprise Application.
2. Click **Single sign-on**.
3. Scroll to the "Attributes & Claims" section.
4. Click **Edit**. The "Manage claims" form appears.

<Frame caption="The &#x22;Attributes & Claims&#x22; section with the &#x22;Edit&#x22; button called out.">
  <img src="https://mintcdn.com/launchdarkly/unfRSXbmQkdGxJjN/images/__third_party/entra-edit-user-attributes-callout.png?fit=max&auto=format&n=unfRSXbmQkdGxJjN&q=85&s=62a5c0c6687131daaba532fc610b3fb5" alt="The &#x22;Attributes & Claims&#x22; section with the &#x22;Edit&#x22; button called out." width="1035" height="708" data-path="images/__third_party/entra-edit-user-attributes-callout.png" />
</Frame>

5. Enter `customRole` in the **Name** field.
6. Leave the **Namespace** field empty.
7. Select "Attribute" as the source.

8) Enter `user.assignedroles` in the **Source attribute** field.

9. Click **Save**. You are returned to the "Attributes & Claims" screen.

Close the "Attributes & Claims" screen to return to the "Single sign-on" page. To test your SSO configuration, click **Test**.

For another example of this setup process, read [How to setup LaunchDarkly custom roles from Entra (formerly Azure AD) Security Groups](https://support.launchdarkly.com/hc/en-us/articles/17058194555291-How-to-setup-LaunchDarkly-custom-roles-from-Azure-AD-Security-Groups).
