Single Sign-On (SSO) for Intranet Access Works with Active Directory or Entra ID
SSO makes it easy for staff to access your intranet without entering another password. SimplifyIT supports both domain-joined Active Directory environments and Microsoft Entra ID (formerly Azure AD), so you can choose the best fit for your infrastructure.
Option 1: Active Directory (Domain-Joined)
- Users must be logged into a domain-joined workstation
- Intranet runs on Windows Server (IIS) and reads Windows authentication context
- No passwords stored - uses built-in identity
- Compatible with Integrated Windows Authentication
Option 2: Entra ID (Azure AD)
- Redirects users to Microsoft login page
- Supports multi-factor authentication and conditional access
- No domain join required - great for hybrid or cloud-first orgs
- Integrates with Entra enterprise applications and OAuth2 flows
- Fully supported in our role-based access controls
Other Supported Scenarios
- Mixed authentication - AD for internal users, Entra for external or branch staff
- Fallback login with intranet-only credentials (if desired)
- Full audit trail of manual logins
Benefits of Intranet SSO
- No password fatigue or forgotten login pages
- Improved compliance with fewer attack surfaces
- Simplified onboarding and offboarding
- Instant permission sync from AD or Entra
Common Questions
Do you set up SSO for us?
Yes. We handle all SSO configuration - whether you're using local Active Directory or Microsoft Entra ID. There's nothing extra to install or configure on your end.
Can we use both AD and Entra at once?
Yes. Many clients use domain login for on-site staff and Entra for remote, branch, or hybrid users.
What happens if a user doesn't have AD or Entra access?
You can enable fallback intranet credentials for select users (like vendors or part-time staff). Those logins are still tracked and permissions-controlled.
Does this integrate with MFA?
If you're using Entra ID, it automatically respects your organization's MFA settings - including conditional access and risk-based policies. You can also enable manual MFA for manual logins.