Skip to main content

Integrate Kisi with Azure Active Directory

Customers who don't yet have SSO set up can still import users from their Azure Active Directory by manually setting up the integration. We recommend, however, setting up SSO to allow your Kisi users to log in with their single, existing credentials.

info

Kisi organizations are limited to one SSO and one SCIM integration. Depending on your needs, you can combine SSO and SCIM integrations with one or more user directory integrations within the same Kisi organization.

To be able to set this integration up, you need to have global admin permissions in Azure.

  1. Sign in to Kisi
  2. Open the Settings and click on Integrations > Add Integration
  3. Enter a name, open the Type dropdown and select Azure Active Directory User Import
  4. Click Authorize with Microsoft and you’ll be redirected to the Microsoft Authentication screen
  5. Sign in with your Microsoft account that has admin privileges
  6. Click Accept to allow the integration read access
  7. Once back in Kisi, select the Active Directory Group
  8. In the User Email Property section, choose between User Principal Name and Mail as the attribute you want to use for this integration and that contains the user's email address in Azure AD. The default value is User Principal Name.
  9. Define if the import should be done into a Kisi group or as users only
  • For the group option, map the Azure Group to the Kisi Group. A Kisi Group is needed to share access to your place(s) with your users.
  • For the users only option, users will be imported but won't receive an invitation email from Kisi or have any access in your place(s).
  1. Click Add

The integration will be set up immediately. Everyone in the Azure Active Directory Group will get an email notification that Kisi access has been shared with them, unless you chose to import as users only.