```html
This guide will walk you through setting up Single Sign-On (SSO) via Microsoft Entra ID. The configuration takes place in two main steps: preparation in Microsoft Entra ID and entering the data into the E-Coach administration interface.
⚠️ Only SuperAdmins have access to the configuration panel.
Step 1: Preparations in Microsoft Entra ID (App Registration)
Use the information from the Setup Help section on the right side of the configuration screen to complete the app registration in Microsoft Entra ID:
Redirect URI (Platform "Web"): Copy the displayed URI (e.g., https://app-tas-ecoach...) using the copy icon. Enter this into your Entra ID app registration under Authentication → Web → Redirect URIs.
Required Permissions (Scopes): Ensure that your app registration is assigned the permissions openid, profile, and email.
Recommended – Restrict access: To control who is allowed to sign in, navigate in Entra ID to the corresponding Enterprise Application. Set the option "Assignment required?" to "Yes" there, and then assign only the users or groups that should be granted access to E-Coach.
Step 2: Enter connection data in E-Coach
Now transfer the generated data from your Microsoft Entra ID app registration into the Connection to Microsoft Entra ID section:
Directory ID (Tenant): Enter your Tenant ID from Entra ID here.
Application ID (Client): Enter the Client ID of the app registration here.
Secret ID: Paste the ID of your created Client Secret here.
Secret expires on: Select the expiration date of your Client Secret using the calendar icon.
Value of the secret client key: Paste the actual value of the secret (Client Secret Value) here. Be careful not to accidentally enter the Secret ID here again.
Step 3: Configure sign-in options
Below the connection data, you will find two switches to control the sign-in behavior:
SSO enabled: Activate this switch so that users can sign into the system via Microsoft Entra ID.
Show sign-in form: If this switch is activated, users can continue to sign in regularly with their email and password alongside SSO.
Important note: If you deactivate the sign-in form while SSO is active, only SuperAdmins and technical users will be able to continue signing in with a password. All other users must compulsorily use the SSO method.
Step 4: Test and Save
Before completing the setup, it is recommended to verify the configuration:
Click the TEST CONNECTION button to ensure that communication with Microsoft Entra ID can be successfully established.
If the test was successful, click the blue SAVE button to finally apply the SSO setup.
Our support team is happy to help – contact us anytime via the Help Center.
```