Azure SSO
Associate Azure AD Groups with Solsta Teams
You can link an existing Microsoft Entra ID (Azure AD) security group to a Solsta Team. This lets any member of that group be automatically enrolled into the associated Solsta Team, inheriting its roles and entitlements.
Requirements
Before you begin, please ensure:
- You have admin rights in your Azure tenant to manage Groups and Enterprise Apps
- Solsta is registered as an application in your Azure AD. References: How to register an app in Microsoft Entra ID
- Your organization’s SSO integration with Solsta is enabled. If this hasn’t been set up for your organization, please open a support ticket to initiate the process.
- You have the Organization Admin role in Solsta
Redirect URI:
Use this URI when you register the Solsta App in Azure:
https://snxd.auth0.com/login/callback
Key Concepts & Sync Behavior
To ensure a smooth deployment, administrators should note the following behavior regarding user visibility and provisioning:
- Just-In-Time (JIT) Provisioning: Solsta uses JIT provisioning. This means a user will not appear in the Solsta team list until they have successfully launched and logged into the Solsta desktop client.
- No Invites Required: When using Azure AD group synchronization, you do not need to send manual email invites. The AD group membership acts as the authorization.
- The "First Launch" Sequence:
- Admin maps the AD group to a Solsta Team
- Admin notifies users they are cleared to log in
- User launches the Solsta client and authenticates via SSO
- The user’s record and team membership are then created and become visible in the Solsta UI for organization admins
Obtain Group ID from Azure Active Directory
This process walks you through creating a new security group. If you already have a group, skip to Step 5.
- Go to Manage Azure Active Directory
- Click on Groups under the Manage section
- Click on New Group, then fill out the fields from New Group screen.
Note that the Group Type MUST be set to Security. - Click continue/save to create the Group.
- Find the Group in the group list and copy the value from the Object ID column
Note: The Group ID can also be found from the Group properties screen when clicking on the Group.
Optional – Restrict Access
If your plan supports it, you can restrict which groups Solsta may read. See Manage users and groups assignment to an application – Entra ID.
Connect SSO Group to Solsta Team
- Log in to Solsta as an Organization Admin
- From the navigation pane, click on Teams
- Click on the Create Team button on the top right
- Fill out the Name field and (optional) Description and Picture URL fields
- Paste the Group Name or ID into the SSO Group Link field
- Click Ok

Note: An SSO Group can only be linked to a team when that team is initially created. You are not able to edit an existing team in Solsta to connect it to an SSO group. You can always delete existing groups and create new ones in order to link a new group. The name and description of existing teams can be edited by clicking the Edit button from the Actions column of the Team screen
Verify the Sync
Because users appear only after their first login, use the following steps to verify the connection:
- Confirm the Azure Object ID in Solsta matches the ID in the Azure Portal exactly
- Ask a "pilot" user from the AD group to launch the Solsta client and log in
- Refresh the Solsta Admin UI (refresh button or navigating away and back to the Team page). The pilot user should now appear within the designated Team.

Result
Once the team sync is verified, the setup is live. Instruct the rest of the team to download and launch the Solsta client.
When any member of that Azure group signs in through SSO, they are automatically added to the linked Solsta Team and granted the same entitlements.
