Skip to main content

Guides

Help center

Short, illustrated guides for the redaction path, Fast Track, cases, integrations, and compliance.

All articles
Enterprise
5 min read

Microsoft Entra ID SSO and SCIM

Firm IT runbook: guided SSO in Organization profile → Security, Enforce SSO, Directory Sync (SCIM), and group → org role recipes.

How it works

Plan entitlement

You can buy it

Admin enablement

Settings → Modules

Available

Nav and APIs show it

Users sign in through Clerk to your IdP. Matter walls stay separate from SCIM.

Audience: firm IT / IAM. Plan: Enterprise (SSO entitlement). Northdocs SSO is delivered via Clerk Enterprise Connections (SAML or custom OIDC). Enterprise org admins configure the connection in Organization profile → Security. Do not paste domains or IdP metadata into Northdocs Settings; that wizard owns those steps. Microsoft EASIE (domain-only, no SAML app) is staff-assisted: Northdocs approves the email domain after ownership is confirmed. Public mailbox domains (Gmail, Outlook.com, and similar) cannot be used for SSO. A verified mailbox at the domain (Clerk affiliation) is not proof of domain ownership. SSO requires DNS TXT ownership or staff approval.

What you get: guided SAML/OIDC setup (Entra, Okta, Google Workspace, custom SAML, or custom OIDC); Enforce SSO (org setting); JIT user creation on first SSO login; SCIM via Clerk Directory Sync on the enterprise connection (ask Northdocs to enable per tenant); group → Clerk admin or member, then a Northdocs role (admin, member, reviewer, viewer, security, billing). Matter/ethical walls are separate from SCIM.

Prerequisites: Enterprise plan (or admin license/override); Northdocs org admin with org:sys_entconns:manage (default Admin role); permission to publish a DNS TXT record for the claimed email domain; IdP admin access. Trial does not include SSO. If a bake-off/POC needs Entra SSO, email sales@northdocs.com.

Flow: User → Northdocs sign-in → Clerk → your IdP (SAML or OIDC) → Clerk session → Northdocs org.

Self-serve (Enterprise admins): Settings → Single sign-on → Set up SSO → Open Security tab. If Security is missing, use Enable guided setup, or ask Northdocs to enable self-serve enterprise SSO for your organization. In Security: add and verify the email domain (DNS TXT), pick the identity provider, exchange metadata or OIDC credentials, run the test sign-in, then activate. Enforce SSO stays locked until a connection is active and you have signed in with the identity provider, so you cannot lock the workspace by turning it on too early.

Entra in the Security wizard: pick Microsoft Entra. Clerk shows ACS URL and Entity ID to paste into a non-gallery Entra SAML app (or the OIDC redirect URI if you choose OIDC). Map Unique User Identifier to mail/UPN. Assign users/groups. Complete the Clerk test step before you activate.

Classic Entra SAML (what IT does in Entra while the Clerk wizard is open): (1) Enterprise applications → New application → Create your own (Non-gallery) → name e.g. Northdocs. (2) Single sign-on → SAML. (3) Paste Clerk ACS URL and Entity ID. (4) Map Unique User Identifier to mail/UPN. (5) Assign users/groups. (6) Supply Entra metadata URL or file back in Clerk Security. (7) Pilot login from the Clerk test step.

Northdocs org steps: confirm pilot users land in the correct Clerk organization; assign org roles for the pilot cohort; when the Enforce SSO switch unlocks (active connection and your own SSO sign-in), enable it; document break-glass (at least two IdP-assigned admins).

Directory Sync (SCIM): Northdocs does not host its own SCIM endpoint. Clerk is the SCIM service provider. Northdocs mirrors Clerk organization membership via webhooks. Enable: confirm SAML/OIDC connection is live → Clerk Dashboard → SSO connections → firm connection → Directory sync → Enable SCIM → paste Endpoint URL + Bearer token into Entra Provisioning (Automatic) → map userName, names, email, active → turn On. Prefer Push Groups + the role recipe below. Prefer disabling JIT once Directory Sync is the source of truth. Test joiner, mover, and leaver.

Group → role recipe (create in Entra): Northdocs-Admins → Clerk org:admin (Northdocs Admin, billable). All other groups map to Clerk org:member. Then set the Northdocs role in Settings → Members: Member or Reviewer (billable), Viewer, Security, or Billing (complimentary). Clerk on our plan cannot store reviewer or other custom roles. Put break-glass practice leads in Admins (at least two). IT / DPO → Security. Finance → Billing. Disclosure QC → Reviewer. Prefer mutually exclusive membership.

Assign the groups to the Enterprise application. In Entra Provisioning, include groups in scope (Push Groups). In Clerk Directory sync, map Northdocs-Admins → org:admin and every other group (or default) → org:member.

After a group change in Entra, wait for SCIM + Clerk, then confirm the Northdocs role in Settings → Members. Admin requires both Clerk admin and the Northdocs admin role. Other roles are stored only in Northdocs.

Acceptance tests: joiner to Members lands as member; after join, set Reviewer, Viewer, Security, or Billing in Settings → Members (SCIM cannot assign those); elevator to Admins can open Settings → Organization / connectors; leaver removes membership and revokes sessions; Enforce SSO blocks password path.

Joiner/mover/leaver without SCIM (JIT only): assign Entra app → user SSO once → set role manually; on leaver remove Entra assignment and Clerk org membership promptly.

MFA: enforce in Entra Conditional Access for the Northdocs app. Do not rely on Northdocs-native MFA when SSO is enforced.

Troubleshooting: redirect loop / Audience error → Entity ID matches Clerk; user not in org → Clerk membership / domain rules; SSO required error → Enforce SSO on and password path used; wrong role → set intended role (min of DB and Clerk).

Security notes: document residency remains EU even when IdP is Entra; connector credentials are admin-only to mutate; prefer folder-scoped DMS roots after SSO go-live.

Contacts: sales@northdocs.com (IT onboarding), legal@northdocs.com (security).

Related articles

Still need a hand?