Brightest
  • πŸ‘‹Welcome to Brightest
  • Overview
    • πŸ’‘Brightest 101
    • πŸ”…New Client Onboarding Sequence
    • ✨Key Brightest Capabilities
  • Fundamentals
    • πŸ› οΈGetting set up
      • πŸ‘©β€πŸ’ΌGetting Started for Brightest Admins
      • πŸ“User Permissions
      • πŸ“¨Inviting Team Members
        • πŸ”‘Two-Factor Authentication
      • πŸ–ΌοΈOrganization Settings
        • πŸ“ΆESG and Sustainability Settings
      • πŸ”“Single Sign-on (SSO)
        • πŸ‡«πŸ‡²Microsoft SSO
        • πŸ‡«πŸ‡²Okta SSO
    • πŸ“‹Navigating Brightest
  • Product Guides
    • πŸ“ŠKPIs and Custom Metrics
      • ℹ️Creating a KPI
      • ℹ️Linking KPIs to Global licenses
      • πŸ—‚οΈOrganizing your KPIs
        • KPIs & Global licenses
      • πŸ’»Entering KPI data
    • 🎯Goals and Targets
      • β›³Setting Goals
      • Uploading Data to Goals
      • πŸ“‰Setting Environmental or Climate Related Targets
      • πŸ“ŠMateriality (single)
    • βš–οΈDouble Materiality
      • 🌐Double Materiality in Brightest
    • 🌎CSR & Impact
    • ⚑Actions
    • πŸ“₯Surveys
      • πŸ“‘How to make a survey
        • Survey form features
    • πŸ‘₯Partners
    • 🏒Assets
      • πŸ—οΈBulk Asset Creation
    • ☁️Carbon Accounting
      • πŸŒ₯️How Carbon Accounting Works in Brightest
      • βž—Emissions Factors
      • πŸ‘©β€πŸ”¬Configuring and Customizing Emissions Factors
      • 1️⃣Scope 1 GHG
      • 2️⃣Scope 2 GHG
      • 3️⃣Scope 3 GHG
    • 🌿Collecting and Importing Sustainability Data
      • πŸ‘£Uploading Asset Footprint Data
        • Using the Add Tool
          • Adding Water Data
          • Adding Fuel Data
          • Adding Waste Data
        • Uploading CSV Files
        • Uploading Utility Invoices
      • πŸš›Uploading Transit Data
      • πŸ’±Financial Transaction (Spend) Data
        • πŸ’ΈSpend Capabilities
      • πŸ›οΈProduct and Materials Data
    • 🚩Tags
    • πŸ“ESG & Sustainability Reporting
      • ESG Reporting Standards & Frameworks in Brightest
  • Use Cases
    • 🏭GHG Emissions Measurement
    • πŸ–₯️Brightest for IT Teams
  • Roadmap
    • πŸ”†Our Product Roadmap
  • FAQs and Support
    • ❓FAQs
    • πŸ“§Contact Us
Powered by GitBook
On this page
  1. Fundamentals
  2. Getting set up
  3. Single Sign-on (SSO)

Microsoft SSO

PreviousSingle Sign-on (SSO)NextOkta SSO

Last updated 11 months ago

To configure Brighest to use Microsoft Active Directory SSO, please follow these steps (and share this information with your IT department). For SSO, our application uses OpenID connect (OIDC) and OAuth 2.0 for Microsoft SSO. You will need to create a multi-tenant Microsoft application for SSO and provide us your application's:

  • Client (Application) ID

  • Secret β†’ Create a secret in β€œCertificates & secrets” and provide the value

You'll also need to set (add):

  • Set the app type to "Web"

  • Make sure β€œMulti-Tenant” is enabled

  • Microsoft graph permissions:

    • User.Read

    • email

    • openid

    • profile

Required Microsoft app authentication settings:

Required Microsoft Graph app roles and user permissions:

Brightest user roles and permissions are set (and scoped) at the license (environment) level. If your organization has a multi-license hierarchy (where licenses might represent different brands, business units, and/or regions), you may want to consider providing different Azure access URLs and app credentials to different licenses or business units to more tightly control which employees are allowed to access which license(s), depending on your user management goals.

A central, global business and/or IT administrator will be able to manage and provision all user roles and permissions on the Brightest side, while access credentials will be governed by your Azure Active Directory.

Callback url:

Logout url:

Once your information has been provided to the Brightest implementation team, we will create a secure, license-dedicated Microsoft SSO login URL for your users. This login URL can be found in your license’s team and user management portal (), or can be shared with teammates via email invitations generated from Brightest:

For any additional questions, or to discuss your specific use case, please speak to your Brightest Account Executive (AE), Account Manager (AM), implementation lead, or Brightest support ().

πŸ› οΈ
πŸ”“
πŸ‡«πŸ‡²
https://www.brightest.io/accounts/microsoft/login/callback/
https://www.brightest.io/logout/
https://www.brightest.io/manage/team/
support@brightest.io