🔒 Permissions: Only Admins can configure the SSO connection inside Minikai. Assigning people to Minikai in your identity provider is managed by whoever administers your directory there, often the same IT team. Learn more about roles →
With Single Sign-On, two separate systems decide whether someone gets in: your identity provider decides whether they're allowed to attempt sign-in at all, and Minikai decides whether they have an account once they do. This article walks through both, using Microsoft Entra ID as the example, since it's what our customers currently use.
When to use this
A colleague can't sign in and you're not sure whether the problem is in Entra or in Minikai.
You're onboarding a new starter and need to know exactly where to add them.
You want to understand what "assigning" someone to Minikai in Entra actually does.
How it works: two gates
Someone needs to clear both before they can use Minikai.
Gate 1, your identity provider. Once SSO is connected, Minikai shows up as an Enterprise Application in your Entra tenant. If assignment is required for that application, Entra's default for most enterprise apps, a user has to be assigned, directly or through a group, before Entra will issue them a sign-in for Minikai. Someone who isn't assigned sees an access-denied page from Microsoft; Minikai is never involved at that point.
Gate 2, Minikai. Even once Entra lets someone through, Minikai still needs an existing account for them. Minikai doesn't create one on first sign-in alone; Directory Sync is what creates accounts and assigns roles once SSO is active.
Step 1: Assign the person in Entra
In the Entra admin centre, open Enterprise Applications, find Minikai, and go to Users and groups → Add user/group.
Assigning someone to the Minikai group in Entra does both jobs at once: it clears the sign-in gate and, via Directory Sync, creates their account with the right role.
Step 2: Confirm their account via Directory Sync
Minikai uses SSO and Directory Sync together: SSO lets your team sign in with their existing work credentials, and Directory Sync creates accounts and assigns roles when people are added to the mapped group in your directory.
Once someone is added to the group, their account is provisioned typically within a few minutes. If you need them ready sooner, you can trigger an on-demand sync: in Entra, open Enterprise Applications → Minikai → Provisioning and use Provision on demand.
If you haven't set up Directory Sync yet, see Setting up SSO and Directory Sync.
Step 3: Have them sign in
Once both gates are clear, they can go to minikai.com/app and sign in with their usual Microsoft work account. See Signing in and accessing Minikai for what to expect.
⚠️ SSO and Directory Sync work together: SSO controls how people sign in; Directory Sync controls who has an account and what role they hold. Setting up both means one action in your identity provider, adding someone to the right group, handles everything from there.
Tips
Set up Directory Sync alongside SSO. See Setting up SSO and Directory Sync. One action in Entra, assigning someone to the group, handles both gates at once and is the simplest setup to maintain going forward.
Check Entra first when someone can't sign in. An access-denied page from Microsoft means it's an Entra assignment problem, not a Minikai one.
ℹ️ Good to know: Other identity providers work the same way in principle. Okta calls it assigning the application to a user or group; Google Workspace controls it through OU or group-based app access. Entra is the example here since it's what our customers currently use.
Need help?
Not sure whether a sign-in problem is on the Entra side or the Minikai side? Message us through the Help Desk in the app or email [email protected].
