How to setup Single Sign On (SSO) with Azure AD

What is Single Sign On (SSO)

Definition: Single sign-on (SSO) is an authentication method that enables users to securely authenticate with multiple applications and websites by using just one set of credentials.

Specifically, SSO allows users of your organisation to log in to Spark with their usual credentials, typically the Microsoft Azure AD credentials they are using to log into their computer in the morning. The benefit is that they do not need to manage another account / password for Spark.

Additionally, this helps enforce all your security requirements (multi factor authentication, etc.) and easily prevents users who left the organisation continued access to Spark.

Setting Up SSO (Azure AD)

Below are the steps required to successfully set-up Single Sign On for your Spark workspace using Microsoft Azure AD.

Provide Email domains

Spark implementation of SSO relies on recognising email domains. We'll therefore need to understand all the domains potentially used by users of your organisation

See examples below:

Identify the Azure AD administrator

The first user to log into Spark with SSO need to have Azure AD administrative rights in order to approve the Spark application into your IT domain.

Step 1: Contact us at to provide the list of email domains and the name of your administrator

Configuration Session

Spark agent will setup the system for you and test with your administrator during an online meeting. This takes 15 minutes.

Step 2: Azure AD administrator and Spark agent organise a configuration session. 

Ready to go!

Once the administrator has approved Spark and testing is complete, users are ready to go!

Step 3: Users enter their email on the Spark login page, and be directed to their usual organisation's login page. 

Connecting your Azure account to your Applauz program

Next Steps...

Adding new users

Users can be invited to Spark by a workspace admin, or the workspace can be setup to allow users to join.

Removing users

If an employee leaves the business,  the users account will need to be manually removed from the Spark platform. Nevertheless, providing the account is disabled on your Azure AD already, the user will not be able to access Spark

Changing user licence / permissions

Changing a users licence / permissions (member, editor) is performed in Spark and is not related to SSO. 


  1. Spark does not support automatic provisioning from Azure AD groups

