This guide shows administrators how to configure Microsoft Entra SSO in ProjectMark, and how end users sign in.
Using Okta or another SAML provider? See the companion Enterprise SSO & SCIM - Setup & Provisioning Guide, which covers SAML connections, Okta Universal Logout, certificate expiry monitoring, and SCIM provisioning. The setup mechanics below (settings location, domains, enforcement, SCIM tab) are shared by all providers.
How users sign in
ProjectMark uses email-first login. There is no separate "Sign in with Microsoft" button.
- Go to https://app.projectmark.com/client/login
- Enter your work email address
- Click Continue
- If your organization has SSO configured, you are redirected to Microsoft to sign in
- Select your work account if prompted, and complete any Microsoft sign-in steps (such as MFA)
If you see a password field instead of a Microsoft redirect, your organization may not have SSO enforced yet, or your domain may not be verified. Contact your ProjectMark administrator.
Open SSO settings
- Log in to ProjectMark at https://app.projectmark.com/client
- In the main left navigation, click Settings (gear icon)
- In the Settings sidebar, expand Security
- Click Single Sign-On
Recommended setup order
- Connection — create your Microsoft Entra connection
- Domains — verify your email domain
- Test sign-in with a pilot user at https://app.projectmark.com/client/login
- SSO activity — confirm the login succeeded
- Enforcement — turn on Enforce SSO when ready
You can go directly to any tab:
Connection: https://app.projectmark.com/client/settings/security/sso/connection
Domains: https://app.projectmark.com/client/settings/security/sso/domains
Enforcement: https://app.projectmark.com/client/settings/security/sso/enforcement
SCIM: https://app.projectmark.com/client/settings/security/sso/scim
SSO activity: https://app.projectmark.com/client/settings/security/sso/sign-in-activity
Tabs other than Connection are disabled until you create an SSO connection.
Connection tab
URL: https://app.projectmark.com/client/settings/security/sso/connection
What it does: Connects ProjectMark to your Microsoft Entra (Azure AD) tenant.
First-time setup
- Go to the Connection tab
- Under Connect your identity provider, click Microsoft Entra ID
- Click Continue
- Fill in the form:
- Tenant ID — your Microsoft Entra tenant ID (GUID). Find it in Azure Portal → Microsoft Entra ID → Overview → Tenant ID.
- Email domain — your company email domain only (e.g.
yourcompany.com), not a full email address.
- Click Save connection
Auto-discover from current users — use this if you are unsure of your Tenant ID and already have users in ProjectMark who have signed in with Microsoft before.
After saving
The Connection tab shows:
- Setup status — whether your domain is verified (green = ready)
- Last successful login
- Connection status — Active or Inactive
Click Edit connection to update your Tenant ID. Click Delete connection to remove SSO entirely.
If you see a warning that your tenant ID is not pinned, edit the connection and enter your specific Tenant ID GUID.
Domains tab
URL: https://app.projectmark.com/client/settings/security/sso/domains
What it does: Registers and verifies the email domains your users sign in with. SSO will not work for a domain until it is verified.
Add and verify a domain
- Go to the Domains tab
- In Add email domain, enter your domain (e.g.
yourcompany.com) - Click Add domain
- The Verify email domain window opens
- Copy the Host and Value for the DNS TXT record
- Add the TXT record in your DNS provider
- Wait for DNS to propagate (may take up to a few hours)
- Click Verify
When verified, the domain status shows verified.
You can add multiple domains for one tenant. Use Remove to delete a domain, or Verify to re-open the verification window for pending domains.
Enforcement tab
URL: https://app.projectmark.com/client/settings/security/sso/enforcement
What it does: Controls whether users must sign in with SSO or can still use a ProjectMark password.
Enforce SSO toggle
- OFF — Users may see a password field at login unless they have previously signed in via Microsoft. SSO is optional.
- ON — All users on verified domains must sign in through Microsoft. Password login is blocked. Users may see: "Your organization requires SSO." on the login page.
How to turn on enforcement
- Go to the Enforcement tab
- Toggle Enforce SSO on
- Confirm in the dialog
Test SSO with a pilot account before turning on enforcement. Make sure your domain is verified first.
SCIM tab
URL: https://app.projectmark.com/client/settings/security/sso/scim
What it does: Sets up automatic user provisioning — creating, updating, and deactivating ProjectMark users from your identity provider.
This tab shows your SCIM endpoint URLs, token management, and provisioning quota. Generate a SCIM token here and configure it in your Microsoft Entra provisioning settings.
SSO activity tab
URL: https://app.projectmark.com/client/settings/security/sso/sign-in-activity
What it does: Shows a log of SSO sign-in attempts — successes and failures.
Use the filters to search by date range, event type, result, and provider. Click Export CSV to download the log.
Use this tab when troubleshooting a user who cannot sign in — search for their email and review the failure reason shown.
Troubleshooting
User sees a password field instead of Microsoft
- Enforce SSO is off and the user has not signed in via Microsoft before → turn on Enforce SSO on the Enforcement tab, or have the user complete one Microsoft sign-in
- Domain not verified → complete DNS verification on the Domains tab
- No connection configured → set up SSO on the Connection tab
User cannot complete Microsoft sign-in
- Confirm the correct Tenant ID is saved on the Connection tab
- Make sure the user enters their work email and selects the matching Microsoft account
- Check the SSO activity tab for the failure reason
- If login timed out, start again from https://app.projectmark.com/client/login
User signed in but the app is not loading
- Sign out fully from ProjectMark
- Close all ProjectMark browser tabs
- Sign in once at https://app.projectmark.com/client/login — do not retry multiple times
How to Install and Authorize ProjectMark in Microsoft Admin Center
To unblock ProjectMark at the admin level, you'll need to be signed in with a Microsoft 365 admin account. If you're not an admin, reach out to your IT team for help.
- Go to: ProjectMark on Microsoft AppSource
- Click “Get it now”.
- In the Microsoft 365 Admin Center, go to Settings > Integrated Apps.
- Search for ProjectMark SSO and click it.
- Check the box: “Allow your organization to use ProjectMark”.
This step installs and authorizes ProjectMark at the organizational level, allowing your users to access the app.
However, depending on your company’s Microsoft security policies, this might not be enough on its own and you may also need to approve data access permissions separately in Microsoft Entra or Azure.
How to Approve Admin Consent Requests in Microsoft Azure/Entra
Sometimes, when a user signs in with Microsoft SSO for the first time, Microsoft may ask for admin consent. This happens when your organization requires explicit approval before apps can access certain data, like user profiles.
To review and approve those requests:
Need help?
Contact ProjectMark support at support.projectmark.com.