How can we help?
Microsoft Entra ID SSO: overview and prerequisites
LocoDELEGATIONS can use Microsoft Entra ID (formerly Azure Active Directory) to provide secure single sign-on for council users.
Who this guide is for
This guidance is intended for council IT administrators who manage Microsoft Entra ID applications, security groups and credentials.
What the integration provides
- Single sign-on using council-managed Microsoft identities.
- Just-in-Time provisioning: a LocoDELEGATIONS account is created automatically when an authorised user signs in for the first time.
- Role-based access using nominated Microsoft Entra security groups.
- The option for the council to restrict authentication to users or groups assigned to the enterprise application.
What the integration does not provide
SCIM provisioning is not currently supported. Microsoft Entra security groups are used for authentication and authorisation checks; the groups themselves are not provisioned into LocoDELEGATIONS.
Before you begin
- Confirm the council-specific LocoDELEGATIONS web address with LocoSOFT.
- Use an account with sufficient Microsoft Entra administration privileges.
- Identify the council groups that will receive Administrator and Editor access.
- Choose a client-secret expiry period that complies with the council’s security policy.
- Arrange a secure method with LocoSOFT for transferring the required identifiers and secret.
Important: Do not place real tenant IDs, application IDs, group IDs or client-secret values in public documentation or ordinary support correspondence. Contact support@locosoft.co.nz to coordinate setup.
