---
title: How to Configure the Profile Application in Microsoft Entra ID Tenant
slug: portal-sub/how-to-configure-the-profile-application-in-microsoft-entra-id-tenant
docTags: 
createdAt: 2026-03-04T12:03:15.527Z
---

# Article Overview

The following article is intended for System Administrators or technical users of Profile. 

It will cover the process for configuring your organization’s Microsoft Entra ID instance to prepare for setting up Single Sign-On (SSO) with Profile. As you complete these steps, you will gather certain settings that will be required for configuring Profile.  

:::hint{type="info"}
**Disclaimer:**

The instructions provided for configuring Microsoft Entra ID are based on our findings and industry best practices. They are intended as general guidance and may not cover all unique configurations or specific requirements of your organization. 

Before implementing these configurations, we strongly recommend consulting with your organization’s security, compliance, and IT teams to ensure that the assigned privileges and settings align with your internal security policies and compliance requirements. 

Intrahealth assumes no responsibility for any misconfigurations, security vulnerabilities, or compliance issues that may arise from applying these configurations. A thorough review and approval by your internal teams are essential to ensure that the integration between Profile and Microsoft Entra ID aligns with your organization’s operational, security, and compliance standards. ****


:::

# Configure the Profile Application in Microsoft Entra ID

:::::WorkflowBlock
:::WorkflowBlockItem
Login to [https://entra.microsoft.com](https://entra.microsoft.com)

::Image[]{src="https://api.qa.archbee.co/api/optimize/zICxj0dnLereb6UUrBA3-/EKgd3Ms_yldTYSThYCAjO_mrbytypj5ziwr12f5t9vak6th21z0izs4w.png" size="82" isUploading="false" initialPath="assets/MrBytYPJ5ZIWR12f5T9vAK6th21z0izs4w.png" githubPath="en/General Settings and Configuration/Single Sign-On/MS Entra ID/assets/MrBytYPJ5ZIWR12f5T9vAK6th21z0izs4w.png" position="flex-start" showCaption="false"}
:::

:::WorkflowBlockItem
Go to **Applications / App registrations**

![](https://api.qa.archbee.co/api/optimize/zICxj0dnLereb6UUrBA3-/ImwaNg7_8vmLzfcMR43Bl_7uf3g8uunnrwlzc4lwj2gcql-pbaqpoicw.png)
:::

:::WorkflowBlockItem
Click the **New registration&#xA0;**&#x74;ab.

::Image[]{src="https://api.qa.archbee.co/api/optimize/zICxj0dnLereb6UUrBA3-/91rjVkFg6yKTh8-uulpiF_pkk4gusbx-sutd5eljtfcdi324eyoye0hw.png" size="87" isUploading="false" initialPath="assets/pKK4gUSBx-sUtD5eLjTfCdi324EyOYe0hw.png" githubPath="en/General Settings and Configuration/Single Sign-On/MS Entra ID/assets/pKK4gUSBx-sUtD5eLjTfCdi324EyOYe0hw.png" position="flex-start" showCaption="false"}
:::

:::WorkflowBlockItem
### Application Setup

1. Enter application name (example: Profile EMR Application).
2. Select the "...single tenant" option.
3. Select **Web&#xA0;**&#x6F;ption from dropdown for Redirect URL section.
4. Add URL: **https\://**&#x73;erver pat&#x68;**/idp/signin-oidc**
   - **Note:&#xA0;**&#x54;he URL above is an example. Please replace "server path" with your own **Server&#xA0;**&#x66;ound on the Profile **Server Login&#xA0;**&#x73;creen.
5. Click the **Register&#xA0;**&#x62;utton

::Image[]{src="https://api.qa.archbee.co/api/optimize/zICxj0dnLereb6UUrBA3-/bUKr8QdJP-or89qBZVuVw_ysgycvyrjw0wbkv1f7ezzovpljgvaj3bwq.png" size="98" isUploading="false" initialPath="assets/ySgYCvYrJW0WBkV1f7ezzOVPlJgvaj3bwQ.png" githubPath="en/General Settings and Configuration/Single Sign-On/MS Entra ID/assets/ySgYCvYrJW0WBkV1f7ezzOVPlJgvaj3bwQ.png" position="flex-start" showCaption="false" indent="2"}

6. After clicking **Register**, the screen should look like this:

::Image[]{src="https://api.qa.archbee.co/api/optimize/zICxj0dnLereb6UUrBA3-/ufO9i3O0koZxCPD20x8Cx_u5od7iemv3eunrc9oyte43m8o3juxwnbg.png" size="92" isUploading="false" initialPath="assets/U5Od7iemv3EuNrc9Oyte43m8O3_jUxwnbg.png" githubPath="en/General Settings and Configuration/Single Sign-On/MS Entra ID/assets/U5Od7iemv3EuNrc9Oyte43m8O3_jUxwnbg.png" position="flex-start" showCaption="false" indent="2"}
:::

:::WorkflowBlockItem
### Collect \[Application (client) ID] & \[Authority URL] values.You will copy the **Application (client) ID&#xA0;**&#x61;nd **Authority URL&#xA0;**&#x66;rom your Microsoft Entra ID configuration. These identifiers are crucial for establishing a secure connection between Profile and Microsoft Entra ID, allowing Profile to authenticate and interact with Entra ID correctly. Make sure to store these details securely, as they will be required during the setup process within Profile.

1. Click on the application name that was created. In the next screen you will see the Overview page for the selected Application and the Application (client) ID is visible.Copy and save the value of **Application (client) ID** as it will be needed later to configure Profile.

::Image[]{src="https://api.qa.archbee.co/api/optimize/zICxj0dnLereb6UUrBA3-/Vjo6-TjiRxukxPUgnyEET_gm2n5p50a3ckrxgdogv91uuxi-gluaqrta.png" size="100" isUploading="false" initialPath="assets/Gm2N5p50A3ckrxGdogV91uuxI-GLuAqrtA.png" githubPath="en/General Settings and Configuration/Single Sign-On/MS Entra ID/assets/Gm2N5p50A3ckrxGdogV91uuxI-GLuAqrtA.png" position="flex-start" showCaption="false" indent="2"}

2. Click on the **Endpoints** tab.Copy and save the value of the field name **Authority URL: (Accounts in this organizational directory only)** as it will be needed later to configure Profile.

::Image[]{src="https://api.qa.archbee.co/api/optimize/zICxj0dnLereb6UUrBA3-/So1prCRIE_VFv-M446QT6_xo-tefen94daes5n4zlyah4rs5votuax7w.png" size="100" isUploading="false" initialPath="assets/Xo-tEfEN94daES5n4zLYAh4Rs5votUAX7w.png" githubPath="en/General Settings and Configuration/Single Sign-On/MS Entra ID/assets/Xo-tEfEN94daES5n4zLYAh4Rs5votUAX7w.png" position="flex-start" showCaption="false" indent="2"}
:::

:::WorkflowBlockItem
### Client Secret SetupThe Client Secret acts as a password that allows Profile to authenticate security with Microsoft Entra ID. Once generated, this secret must be copied and stored safely, as it will be used in the configuration process to ensure a secure connection between the two systems. 

1. Go to **Certificates & secrets&#xA0;**&#x61;nd click **+New client secret**.When creating an application secret, you will be prompted to choose an expiration period. Please ensure the selected expiry aligns with your organization’s security and credential rotation policies. Common durations include 6 months, 12 months, or 24 months, depending on internal compliance requirements.**Note**: Once the secret expires, authentication to Profile with Microsoft Entra ID will fail unless a new secret is generated. Be sure to create a new secret before the current one expires, and update the corresponding secret settings in Profile to avoid any service disruption.
2. Copy and save the client secret value, because it is visible *one time only* when the secret is added. Ensure you copy this value *at this time* as it will be needed later to configure Profile. Once you copy this value, it will become your **Application Client Secret**.

::Image[]{src="https://api.qa.archbee.co/api/optimize/zICxj0dnLereb6UUrBA3-/Qu6-5ehBfyap_6UDVgUON_vvsdvhh9tgl8dygvcxnal8cakwtmu2pww.png" size="96" isUploading="false" initialPath="assets/vvSDVhh9TgL8DYGv_CXnAl8CakwTmu2pww.png" githubPath="en/General Settings and Configuration/Single Sign-On/MS Entra ID/assets/vvSDVhh9TgL8DYGv_CXnAl8CakwTmu2pww.png" position="flex-start" showCaption="false" indent="2"}
:::

:::WorkflowBlockItem
### Platform Configuration SetupWe need to setup platform configurations for the new application to ensure proper integration with Microsoft Entra ID. These configurations define how the application communicates with the identity provider, including supported authentication protocols, redirect URIs, and other essential settings.

1. Go to **Authentication**
2. Click **+Add a platform**
3. Select **Web**

::Image[]{src="https://api.qa.archbee.co/api/optimize/zICxj0dnLereb6UUrBA3-/QW7wSPMfgxk5LKkZ4sN3m_iy8lo7wharl5rlhbf3qvevc48bjh3-qr5w.png" size="100" isUploading="false" initialPath="assets/iY8LO7wHarl5rLHbf3QVevC48bJh3-Qr5w.png" githubPath="en/General Settings and Configuration/Single Sign-On/MS Entra ID/assets/iY8LO7wHarl5rLHbf3QVevC48bJh3-Qr5w.png" position="flex-start" showCaption="false" indent="2"}

4. Verify the URL is **https\://**&#x73;erver pat&#x68;**/idp/signin-oidc&#xA0;**&#x77;here the Profile server will connect to. This would be the same URL as in step 4. 

::Image[]{src="https://api.qa.archbee.co/api/optimize/zICxj0dnLereb6UUrBA3-/MxpAxhu9vvPDQQ2OMEozG_sjmvylox5rylrwod1wjp5qtkttyotq45gg.png" size="100" isUploading="false" initialPath="assets/SjMVYLOx5rYlRwOD1Wjp5QTkttyOTQ45gg.png" githubPath="en/General Settings and Configuration/Single Sign-On/MS Entra ID/assets/SjMVYLOx5rYlRwOD1Wjp5QTkttyOTQ45gg.png" position="flex-start" showCaption="false" indent="2"}
:::

::::WorkflowBlockItem
### Token Configuration for User AuthenticationTo enable the Profile system to securely identify and authenticate users logging in via Microsoft Entra ID, we need to configure token generation and include the necessary 'claims'. These claims, such as user attributes provide critical information that the Profile system uses for authentication and authorisation purposes. 

1. Go to **Token configuration&#xA0;**&#x70;age.
2. Click on **+Add optional claim**
3. Select **ID** for Token Type and check the following:
   1. **email**
   2. **fwd**
   3. **preferred\_username**
4. Click **Add&#xA0;**

::Image[]{src="https://api.qa.archbee.co/api/optimize/zICxj0dnLereb6UUrBA3-/HuoSwR29rFfXo-jGHA4rv_cu4kbv3k36xehhzuzl1qmuvjksvll39-lg.png" size="100" isUploading="false" initialPath="assets/cu4kBv3k36XEhHZuzl1QMuvJksVLL39-Lg.png" githubPath="en/General Settings and Configuration/Single Sign-On/MS Entra ID/assets/cu4kBv3k36XEhHZuzl1QMuvJksVLL39-Lg.png" position="flex-start" showCaption="false" indent="2"}

:::Paragraph{indent="1"}
This ensures all Tokens generated from Microsoft Entra ID will include the user's Microsoft Entra ID email address, fwd (IP Address) and their preferred username.
:::

5. A pop-up **Add optional claim&#xA0;**&#x61;ppears. Select the **Turn on the Microsoft Graph email permission (required for claims to appear in token)** checkbox and click **Add**.
::::

:::WorkflowBlockItem
###  Conditional Access PoliciesWe recommend considering implementing Conditional Access policies tailored to your organization's needs. Conditional Access helps control how and when users access the Profile application, adding layers of protection based on factors like user risk, device compliance, and location. For guidance on setting up conditional Access policies refer to Microsoft's documentation:[https://learn.microsoft.com/en-us/entra/identity/conditional-access/overview](https://learn.microsoft.com/en-us/entra/identity/conditional-access/overview)
:::

:::WorkflowBlockItem
### Assigning Users and Groups in Microsoft Entra ID for Profile AccessAfter creating the Profile application in Microsoft Entra ID, you can assign access through the "Users and Groups" section. This step controls which users or groups within your organization can access Profile.To ensure the newly added **Profile&#xA0;**&#x61;pplication is governed by these User and Group policies:

1. Go t&#x6F;**&#xA0;Applications / Enterprise Applications**.
2. Select your **Profile&#xA0;**&#x61;pplication.
3. Click o&#x6E;**&#xA0;Properties**.
4. For **Assignment required?&#xA0;**:
   - If you’re deploying the Profile application and want only selected clinicians or staff to access it initially, set **Assignment required?** to **Yes&#xA0;**&#x61;nd assign those users/groups. 
   - If it's meant to be broadly accessible to all users in your organization, leave it as **No**.
:::
:::::

Lastly, assigning access in Entra ID alone does not grant a user access to Profile. To enable access, a corresponding user account must exist and be linked in Profile to establish a one-to-one link with the Entra ID user. 

### 11. Conclusion

With all steps completed above, you should have recorded:

- **Authority URL** (used for **MS Entra ID Org site (root)** in Profile settings) 
  - See step 5b
- **Application (client) ID** (used for **Client ID&#xA0;**&#x20;in Profile settings) 
  - See step 5a
- **Application Client Secret&#xA0;**(used for **Client Secret** in Profile Settings) 
  - See step 6

All three values will be used in configuring Microsoft Entra ID settings within Profile.

# Learn More

For more information on Microsoft Entra ID in Profile please click on the article links below: for 

- [Microsoft Entra ID in Profile](docId:7vBBYDxhIcV4CIg1vbcWD)
- [Microsoft Entra ID in Profile: FAQ](docId\:BcQmJgnOCa-MMuINnxwJQ)
- [How to Add Single Sign-On MS Entra ID License in Profile](docId\:wiKAAADVi80fASeTQMUKv)
- [How to Configure Single Sign-On (SSO) for Microsoft Entra ID in Profile](docId:1zwBi7NJEDkcJkBfMnPyZ)
- [How to Configure Existing Users for Single Sign-On (SSO) with Microsoft Entra ID in Profile](docId\:Dx0Y5TYBX-QkQ2ROhI0z-)
- [How to Add new Users to Profile for Single Sign-On (SSO) with Microsoft Entra ID in Profile](docId\:InFKWTP01GtHumhdrkB2n)
- [How to Prevent Users from Using Microsoft Entra ID Single Sign-On (SSO) as a Login Method](docId\:Z9BjONEx05g1ui4JOlQBK)
- [How to Enforce Users to Only Use Single Sign-On (SSO) Microsoft Entra ID as a Login Method](docId\:DVJ52aQrMnTx_m09uCStU)
- [How to Configure a Profile User's Application Shortcut to Use Single Sign-On (SSO) (Microsoft Entra ID) Login Method](docId\:s0_SfCMDuO3B2oQE2f9JF)
