Werk #1000007: Single sign-on (SSO) with Microsoft Entra ID
| Component | Authentication |
| Title | Single sign-on (SSO) with Microsoft Entra ID |
| Date | Jul 10, 2026 |
| Level | Major Change |
| Class | New Feature |
| Compatibility | Compatible - no manual interaction needed |
You can now enable single sign-on (SSO) for your Checkmk Cloud, letting your users log in through your organization's identity provider instead of a separate email and password. Microsoft Entra ID is the officially supported identity provider.
How to set it up
SSO is configured from two new tabs in the user administration panel:
- Single sign-on — register your identity provider and enable SSO.
- Domains — add and verify the email domains that SSO applies to.
Before you can enable SSO, two prerequisites must be met:
- At least one verified domain. Add your domain (for example
company.com) and prove ownership by creating the DNS TXT record shown in the Domains tab. SSO can only ever apply to verified domains. - At least one break-glass user. A break-glass user is exempt from SSO and always logs in with email and password. This is your emergency access: if your identity provider is ever misconfigured, the break-glass user can still log in and fix it. Requiring one guarantees that SSO can never lock everyone out of your Checkmk Cloud.
Once both are in place, enable SSO from the Single sign-on tab.
How your users log in
SSO is scoped to domains, not individual users — there is nothing to configure per user. Once SSO is enabled, anyone whose email address belongs to one of your verified domains is automatically redirected to your identity provider to authenticate. New team members with a company email address are covered without any extra setup.
Break-glass users are the exception and continue to log in with email and password.