> ## Documentation Index
> Fetch the complete documentation index at: https://docs.cedarai.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Microsoft

> Configure Microsoft (Azure AD) SSO for Cedar.AI with IdP- and SP-initiated flows.

## Overview

After registering your organization, all users will transition to the new login method. Notify users in advance to ensure a smooth changeover.

<Steps>
  <Step title="Open ARMS and navigate to Settings">
    Sign in to ARMS, go to <b>Settings</b>, then select <b>Sign-in options</b>.
  </Step>

  <Step title="Enter tenant code (optional shortcut)">
    Enter your Cedar tenant code (e.g., <code>[https://accounts.cedarai.com/login?tenant=ABCD](https://accounts.cedarai.com/login?tenant=ABCD)</code>).
  </Step>

  <Step title="Choose Microsoft and authenticate">
    Select <b>Microsoft</b> as the provider, click <b>Log in with Microsoft</b>, and authenticate with an org-linked user.

    <img src="https://mintcdn.com/cedaraiinc/3XL8_nY45kQdoBAs/images/sso/microsoft.png?fit=max&auto=format&n=3XL8_nY45kQdoBAs&q=85&s=b65e0ba0d818d791a4eb0466ed879e98" alt="Microsoft configuration" style={{maxWidth: '680px', borderRadius: '8px'}} width="832" height="376" data-path="images/sso/microsoft.png" />
  </Step>
</Steps>

### Gradual rollout

If you'd like to phase in SSO while keeping a fallback to Cedar identity for select users, enable gradual rollout. See [Gradual rollout](/user-docs/sso/gradual-rollout) for details.

### Tips & potential issues

* Users who need access must belong to the same Azure AD tenant as the initial authenticating user.
* Users must still be assigned to a Cedar user group with sufficient permissions.

<Note>Need help? Email [support@cedarai.com](mailto:support@cedarai.com).</Note>
