Adding Honestly from the gallery
- Sign in to the Microsoft Entra admin center as at least a Cloud Application Administrator.
- Browse to Entra ID > Enterprise apps > New application.
- In the Add from the gallery section, type Honestly in the search box.
- Select Honestly from results panel and then add the app. Wait a few seconds while the app is added to your tenant.
- Open Honestly Enterprise Application and select ‘2. Set up single sign on’

1. Copy Honestly field ‘Honestly Entity ID’ to Azure field ‘Identifier (Entity ID)’
2. Copy Honestly field ‘Honestly ACS URL’ to Azure field ‘Reply URL (Assertion Consumer Service URL)’
7. In Azure:1. Copy Azure field ‘Login URL’ to Honestly field ‘Your provider’s SSO URL’
2. Copy Azure field ‘Microsoft Entra Identifier’ to Honestly field ‘Your provider’s Entity ID’


-
- Download SAML Certificate ‘Certificate (Base64)’.
- Open with text editor and copy contents(including ‘-----BEGIN CERTIFICATE-----’ and ‘-----END CERTIFICATE-----’ to Honestly field ‘x509 Certificate’


Name ID: send the email address
Honestly identifies the person who signs in by the Name ID in the SAML response, and it expects that Name ID to be their email address — the same address they use as a user in Honestly. In the Honestly enterprise app in Entra, open Attributes & Claims and set Unique User Identifier (Name ID) to the Email address format with the source user.mail. Entra’s default is user.userprincipalname. If the value it sends is not the user’s email address, or does not match the email address stored in Honestly, sign-in fails with Not authenticated.Leave token encryption turned off in the Entra enterprise app. Honestly reads unencrypted SAML assertions; it cannot open encrypted ones, so an encrypted response is rejected.
User and group assignment (important)
For your SSO integration to work correctly, you need to assign all relevant users and/or groups to the Honestly app in your identity provider (in Microsoft Entra ID). Only users and groups that are explicitly assigned to the SSO setup will be able to sign in to your Honestly organization. Make sure that all roles that require access to Honestly (for example, admins, HR, managers, employees) are correctly assigned in the identity provider. If assignments are missing, affected users will not be able to log in, even if SSO is technically configured correctly.Assigning a user in Entra is only half of the requirement. SSO does not create Honestly users. A person can only sign in if they already exist as a user in the Honestly account. If they are assigned in Entra but not yet a user in Honestly, sign-in ends with User does not exist.
SSO types with Honestly
There are two main SSO types you can use with Honestly: 1. Honestly-initiated SSO In this flow, users start the login directly on the Honestly login page. Flow: - Users enter their email address on the Honestly login page. - No password needs to be entered in Honestly. - Authentication is handled by the identity provider. This option is useful if users are used to logging in directly via the Honestly login page. 2. Identity Provider-initiated SSO (IdP-initiated) In this flow, users start the login directly from the identity provider (for example, Microsoft Entra ID) instead of the Honestly page. Flow: - Users click the Honestly app in the identity provider. - The email address is automatically passed from the identity provider to Honestly. - Users do not need to manually enter their email address in Honestly. This option is particularly convenient if you want to manage access centrally via your identity provider (for example, via an app portal or dashboard). Note on the “User Access URL” (for IdP-initiated login) In your identity provider, you can find a User Access URL (or similarly named URL) in the configuration of the Honestly app. This URL is used when users start the login directly via the identity provider (IdP-initiated login). Make sure that this URL is configured correctly and is accessible for the intended users and/or groups so that the login flow works smoothly.User Access URL (for IdP-initiated login)
In the properties overview, you can find the User Access URL in your Identity Provider. This URL (or a shortened version) is required to correctly configure the login flow and enable users to access Honestly. The following Link will take you to further explanation of the interface (if you are routed to the German page, you can switch to English by clicking on the respective button in the top right-hand corner).When sign-in doesn’t work
Start in Entra. Open the Honestly enterprise app, go to Single sign-on and use Test single sign-on. Entra shows the exact AADSTS error, which is the fastest way to the cause. If the response reaches Honestly, Honestly shows one of these four messages:When Entra rolls its signing certificate, the new certificate has to be saved in Honestly again under Settings → Single Sign-On → x509 Certificate. Until it is, sign-in ends with Not authenticated.