Skip to main content

Using Microsoft Entra ID single sign-on with Dext

Set up Microsoft Entra ID SSO with Dext using SAML authentication and connect your Entra tenant to your Dext account.

Alexander avatar
Written by Alexander
Updated yesterday

You can connect Microsoft Entra ID to your Dext account using SAML single sign-on (SSO).

To complete the setup, you will:

  1. Create a Dext Enterprise Application in Microsoft Entra ID.

  2. Retrieve your account CRN (Identifier) and Reply URL from Dext

  3. Configure SAML in Entra ID.

  4. Paste your App Federation Metadata URL into Dext to finalise the connection.

Important:

  • You must be an Admin user in Dext to manage Authentication settings.

  • You must have at least the Application Administrator role in Microsoft Entra ID.


Step 1 - Create the Enterprise Application in Microsoft Entra ID

Before configuring SAML, you must first create the Enterprise Application in your Microsoft Entra ID tenant.


Create a new Enterprise Application

  1. Log in to Microsoft Entra ID.

  2. Go to Enterprise applications.

  3. Select New application.

Enterprise Applications page in Microsoft Azure showing New application button

Create your own application

  1. On the Microsoft Entra App Gallery page, select Create your own application.

  2. Enter Dext as the application name.

  3. Select Integrate any other application you don’t find in the gallery (Non-gallery).

  4. Select Create.

Create application panel with Dext entered and Non-gallery integration selected

Your Enterprise Application is now created, and you’ll be redirected to the Application Overview page.

Keep this tab open. You’ll switch between Dext and Microsoft Entra ID during this setup.


Step 2 - Retrieve your Identifier (CRN) and Reply URL from Dext

Now switch to Dext. You need your account-specific values before configuring SAML.

  1. In Dext, go to Practice settings or Business settings in the sidebar.

  2. Select Authentication.

  3. Select Connect next to Microsoft Entra ID.

Authentication settings page in Dext with Connect button next to Microsoft Entra ID

Confirm Enterprise Application creation

  1. Tick I have created a new enterprise application in my Microsoft Entra ID tenant.

  2. Select Next.

Configure Single Sign-On window showing confirmation checkbox and Next button

Copy your Identifier (CRN) and Reply URL

Dext now displays:

You’ll need both values in the next step.

Metadata URL input field in Configure Single Sign-On window with Connect button

Keep this tab open.


Step 3 - Configure SAML in Microsoft Entra ID

Return to your Enterprise Application in Entra.

  1. Open the Enterprise Application you just created.

  2. Select Single sign-on on the Overview page or from the left-hand sidebar.

  3. Select SAML.

Dext Enterprise Application overview page with Set up single sign on highlighted
Single sign-on method page showing SAML tile selected

Configure Basic SAML settings

  1. In Basic SAML Configuration, select Edit.

  2. Set the following values:

Azure SAML configuration page with Identifier set to CRN and Reply URL set to Dext URL

Copy the App Federation Metadata URL

  1. Scroll to the SAML Certificates section.

  2. Copy the App Federation Metadata Url.

SAML certificates panel displaying App Federation Metadata URL

Step 4 - Complete the connection in Dext

Return to the Dext SSO modal.

  1. Tick I have configured the SAML settings in my Microsoft Entra ID tenant.

  2. Select Next.

Configure Single Sign-On window showing SAML configuration confirmation step

Enter your Metadata URL

  1. Paste the App Federation Metadata URL into the Metadata URL field.

  2. Select Connect.

Dext SSO configuration window with Metadata URL field and Connect button

Successful connection

If successful, you’ll see a confirmation screen.

Successful connection message confirming Dext account connected to Microsoft Entra ID

Your Dext account is now connected to Microsoft Entra ID.

To allow users to log in via SSO, assign users or groups to the Dext Enterprise Application in Microsoft Entra ID.


Troubleshooting

If your SAML certificate changes in Microsoft Entra ID

If the SAML certificate is updated or renewed in Microsoft Entra ID, SSO will stop working until you refresh the configuration in Dext.


Refresh SAML configuration

  1. Go to Practice settings or Business settings > Authentication.

  2. Select Refresh in the top-right corner.

Authentication settings page with Refresh button highlighted

You’ll see a modal displaying the Metadata URL Dext uses to fetch your SAML configuration.

Synchronize configurations window displaying Metadata URL and Refresh button

Select Refresh to synchronise your latest SAML certificate. Dext will fetch and apply the updated configuration automatically.


Connecting to a new Microsoft Entra ID application

If you need to connect Dext to a different Enterprise Application:

  1. Go to Practice settings or Business settings > Authentication.

  2. Select Disconnect.

  3. Confirm the action.

This immediately disables the existing SSO connection.

Authentication settings page with Disconnect button highlighted

After disconnecting:

  • Repeat the integration flow.

  • Enter the new App Federation Metadata URL.

  • Verify that the fetched certificate details match your Entra configuration.


Can I connect multiple Dext accounts to Microsoft Entra ID?

Yes. Each Dext account requires its own Enterprise Application in Microsoft Entra ID.

When configuring SAML, use the CRN for the specific Dext account you are connecting.

Did this answer your question?