This article shows you how you can set up the single sign-on for your organisation with your Microsoft Entra ID. To set up the connection you need to have a Pro-Account and reach out to the Agriplace team to enable the function. If you connect the Microsoft Entra ID your colleagues can sign in to Agriplace using their Microsoft work credentials. That allows you to easily onboard colleagues to Agriplace.
To be able to set up the connection you need to have:
- A Microsoft Entra ID tenant
- Admin access to that tenant
- Agriplace Chain account with Owner permissions
Ho to set it up?
Step 1: Start SSO Setup on Our Platform
- Log in to your Agriplace Chain account
- Go to Company Settings -> Company security
-
Click "Connect Microsoft Entra
- You’ll receive:
- Entity ID
- Reply URL
Step 2: Register a New Enterprise Application in Entra
- Go to the Entra portal
- Navigate to Applications -> Enterprise applications
- Click "+ New application"
- Choose "Create your own application"
- Name it something like YourBestPlatform - SSO, select Integrate any other application, and click Create.
Step 3: Set Up SAML SSO
- Once the app is created, go to Single sign-on → choose SAML.
- Under Basic SAML Configuration, click Edit and fill in Entity ID and Reply URL you got the the step above
- Save your changes.
Step 4: Configure Attributes & Claims
This step is required to ensure correct user mapping and access.
This step ensures that your user data (like name, email, and locale) is sent from Microsoft Entra ID to Agriplace Chain. Without these claims, users may not be created correctly, and their sessions may lack required context.
- Go to Attributes & Claims.
- Click Edit.
- Add or update the following claims(you will also need to make the names shorter):
- Remove any default claims that conflict or duplicate the above
-
Enable “Emit claim as a JWT” for the following:
emailaddress
-
name
This ensures the values will be available in the JWT token passed to your platform via Cognito.
- For Unique User Identifier, ensure it's configured as:
Enable users access
Step 5: Download SAML Metadata
- Scroll to SAML Certificates section
- Copy App Federation Metadata Url
Step 6: Upload Metadata to Our Platform
- Go back to your Agriplace Chain SSO setup screen, click “next”
- Paste the App Federation Metadata Url
- Click “Enable”.
Our system will validate the metadata and automatically configure the SSO connection in the background.
Now you have access to the sign-up URL to use to login to Agriplace Chain via Microsoft Entra!
After completing the SSO setup, the final step is to verify your email domains and associate them with your organisation’s identity provider. This allows us to automatically detect users from your company based on their email and route them through the correct login flow.
Verifying domains is highly recommended, since it will lead to better UX for users.
With domain verification:
- Users from your company are automatically redirected to your Microsoft SSO login.
- No need for them to remember or choose a specific login method.
- Only authorized organizations can claim a domain—improving security.
Step-by-Step: Domain verification
Step 1: Go to Domain Verification Settings
- Go to Company Settings → Company security → Domain verification
Step 2: Add Your Company Domain(s)
- Enter your domain (e.g.
agriplace.com
). - Click “Add domain”.
Our platform will generate a unique DNS TXT record for you to add to your domain’s DNS configuration.
Step 3: Add the DNS TXT Record
- Log in to your domain registrar (e.g. GoDaddy, Namecheap, Cloudflare, etc.).
- Navigate to the DNS management page.
- Add the provided TXT record:
Type | Name / Host | Value |
---|---|---|
TXT | agriplace-chain-verification | <dns token value> |
- Save the changes. DNS updates may take up to 30 minutes to propagate, but often go through faster.
Step 4: Verify the Domain
- Go back to Agriplace Chain → Domain Verification page.
- Click “Verify” next to your domain.
We’ll check your DNS record and confirm ownership.
Once verified, your domain will appear as "Verified" and be linked to your organisation.
Troubleshooting
- You do not see the “Create Microsoft Entra” button
- Make sure you have enabled the feature flag for a tenant
- Make sure you are the account owner
- Entra setup is failing
- Make sure you are providing the correct “App Federation Metadata Url”
- New Agriplace Chain users are missing theirs email/name
- Make sure you correctly set up Attributes & Claims
For other questions contact Agriplace Support chainsupport@agriplace.com
Comments
0 comments
Please sign in to leave a comment.