SSO is available on the Penbox Enterprise plan only. If you would like to enable it, contact your Penbox representative.
Overview
Single Sign-On lets your users connect to Penbox with their existing company identity. Once enabled, your team signs in through your identity provider, and you keep control of access from your own side. Select your identity provider below and follow the setup steps. More methods are coming soon.- Microsoft Entra ID
Microsoft Entra ID (formerly Azure AD) lets your users sign in to Penbox with their company Microsoft account. An administrator of your Microsoft tenant creates an application registration and shares the resulting credentials with Penbox.
You need a Global Administrator of your Microsoft Entra tenant to complete these steps.
Step 1: Register the application in Microsoft Entra
Create the app registration
In the Microsoft Entra admin center, go to App registrations then New registration. Name it
Penbox SSO (or a name of your choice).Set the account type
Under supported account types, select Accounts in this organizational directory only (Single tenant).
Register and note the IDs
Click Register. From the Overview screen, note the Application (client) ID and the Directory (tenant) ID.
Create a client secret
Go to Certificates and secrets then New client secret. Copy the secret Value immediately (not the Secret ID, they are different) and note its expiry date.
Step 2: Share the credentials with Penbox
Send the following four items to Penbox through the secure link Penbox provided to you. Do not send these by email or chat.- Application (client) ID
- Client secret (the Value)
- Tenant primary domain (for example
yourcompany.onmicrosoft.comor your verified domain) - Directory (tenant) ID
After setup
Once Penbox receives and configures your credentials, your users will sign in to Penbox with their Microsoft account. Standard logins are disabled for your workspace, so Microsoft becomes the only way in.The client secret has an expiry date. Let Penbox know that date so renewal can be planned ahead of time and sign-in is never interrupted.