Яндекс.Метрика
SSO in Pachca with Azure OpenID

SSO in Pachca with Azure OpenID

In Azure Active Directory, go to App registrations.

App registrations in Azure AD

Click New registration.

Fill in the values as shown in the image. We'll give you the Web redirect URI during the integration. Click Register.

New app registration form in Azure

On the app screen:

  • Copy the Application (client) ID and the Directory (tenant) ID and send them to us.
  • Click Endpoints and send us the value of the OpenID Connect metadata document field.

Application and directory IDs in Azure

Go to Certificates & secrets.

Click New client secret and create a secret. Send us its value.

Pachca needs user data to work, so you need to set up passing it in the OpenID token.

Go to Token configuration.

Click Add optional claim.

Fill in the form as shown in the image.

Setting up OpenID token claims

We can agree on handling other fields in Pachca to fit your use case:

You can also pass any other text fields from your directory to Pachca, such as an employee's manager or birthday. To do this, send your request to support after you start setting up the integration.

‍

Click Add and select the checkbox.

Confirming app permissions

The app admin can set up their own, more granular policies for employee access to the Pachca app. This doesn't require any configuration changes on our side.

You're all set! Don't forget to send us the parameters listed in this guide, and we'll turn on SSO login for your company.

Test the setup

On the Pachca login screen, click With email

With email button on the Pachca login screen

Click Log in with SSO

Log in with SSO button

Enter your work email from AD in the field.

Entering your work email to log in with SSO

Sign in through your company's system.

Your email is filled in automatically.

If the user is already signed in to the domain, this step is skipped.

Signing in with Azure Active Directory

Setup complete! Your users can now log in to Pachca.

Updated: February 17, 2025

More in Administration

Accounts in Pachca
How Pachca is structured: the difference between an account, a user and a member profile
Inviting your team
How to invite your team to Pachca, the team chat app: two ways to add employees
Change your email in Pachca
How to change your email address in Pachca: a guide for employees and administrators
Errors when adding people by email
Common errors when adding users to Pachca by email and how to fix them
Managing members in Pachca
Managing members in Pachca: how to add, edit and remove people from your team
Group tags
Add employees to all the chats they need at once with group tags
Advanced administration via API
How to automate user administration in Pachca with the API: creating users, managing them and tags
Ports and addresses Pachca needs
Ports and addresses Pachca needs to work properly: setting up your corporate firewall
Storage in Pachca
Everything about file storage in Pachca: limits, managing storage space and working with documents
Setting up DLP in Pachca
Add an extra layer of protection for personal data, tokens and passwords
Internal/external file access
How to set up internal and external zones in Pachca to protect your company documents
Two-factor authentication (2FA)
How to turn on two-factor authentication in Pachca for extra account security
Import chats from Slack
How to import your chat history from Slack into Pachca: a step-by-step migration guide
Import chats from Mattermost
Pachca lets you move your chat history and files from Mattermost into your workspace.
Import chats from Telegram
If your team is moving to Pachca from Telegram, you can bring your chat history over to your team chat app.
Exporting messages from Pachca
How to export messages from Pachca: data format, settings and export limitations
SSO options in Pachca
Single sign-on (SSO) in Pachca: SAML, LDAP and Keycloak connection options and step-by-step guides
SSO in Pachca with LDAP
SSO in Pachca with Multifactor.ru
SSO in Pachca with Blitz Identity Provider
SSO in Pachca with Authentik
SSO in Pachca with Keycloak
SSO in Pachca with ADFS OpenID
This guide explains how to configure ADFS on Windows Server 2016 or later to connect it to Pachca.
SSO in Pachca with Google Workspace SAML
SSO in Pachca with Indeed IdP over SAML
SSO in Pachca with Yandex 360
SSO in Pachca with Yandex Identity Hub
BYOK: Bring Your Own Key in Pachca
How encryption with your own key (BYOK) works in the Pachca team chat app
Advanced encryption in Pachca
How to set up advanced encryption in Pachca for extra protection of your company data
Set up BYOK with HashiCorp Vault
Set up BYOK with Yandex KMS
Set up BYOK with Cloud.ru KMS