Use Microsoft Entra ID to enable Single Sign-On (SSO) for the Fax Portal with the OpenID Connect (OIDC) protocol. SSO is configured per Fax Portal tenant, and once enabled your users sign in through Microsoft Entra ID and get access to the Fax Portal without a separate Fax Portal password.
This configuration establishes trust between Microsoft Entra ID (Identity Provider) and Retarus (Service Provider). You register an application in Microsoft Entra ID and share its details with Retarus, who completes the connection on the backend.
📌 SSO matches each Microsoft Entra ID account to an existing Fax Portal user by email address. Users are not created automatically from your directory. You must add them to the Fax Portal before they can sign in via SSO. For more information, see Import users in bulk.
Microsoft Entra ID handles authentication, including any multi-factor authentication or conditional access policies you define. The Fax Portal remains responsible for authorization. Roles, user groups, and faxbox assignments are configured directly in the Fax Portal and are never imported from your directory.
Prerequisites
Before you contact Retarus to set up SSO, make sure you have:
-
Administrator access to the Microsoft Entra admin center
-
Each user’s email address available in your directory
-
Redirect URI from your Retarus implementation manager, added as a valid redirect URI on your Entra application
What information to share with Retarus
Send the following to your Retarus implementation manager so they can complete the SSO setup:
-
OpenID Connect metadata document URL (OpenID configuration endpoint)
-
Application (client) ID
-
Client secret value
📌 Treat the client secret as sensitive. Share it only with administrators from your own organization and the Retarus administrators you are working with.
Retarus configures the connection on the backend and confirms when SSO is active for your tenant. If your tenant does not yet have an administrator, Retarus can also provision an initial tenant administrator as part of this setup.
Adding users to the Fax Portal
Add each user to the Fax Portal before they sign in with SSO. Under Settings - Users, you can add users individually with Create User or import multiple users at once with Import under Manage via CSV. For details, see Create users and groups and Import users in bulk.
The Fax Portal email address for each user must match the email address Microsoft Entra ID returns for that user, so SSO can match the two accounts. Users created while SSO is active receive an SSO welcome email and are not asked to set a Fax Portal password.
Signing in with SSO
Once your Retarus implementation manager confirms that SSO is active for your tenant, users sign in through Microsoft Entra ID:
-
Any Microsoft Entra ID account whose email address matches a Fax Portal user can sign in.
-
A user whose email address is not yet in the Fax Portal cannot sign in until an administrator adds them.
For the general sign-in procedure, see Sign in to the Enterprise Fax Portal.
Signing in for the first time
When a user signs in through Microsoft Entra ID for the first time, the Fax Portal matches the Entra email address to the existing Fax Portal user and links the two identities. The user’s status changes from Pending activation to Active, and the user gets access according to the roles, user groups, and faxbox assignments already configured for them in the Fax Portal.
Each user’s identity is linked independently on their own first sign-in, so one user signing in does not affect any other user’s activation status.
When sign-in is rejected
If no Fax Portal user matches the Microsoft Entra ID account, the Fax Portal rejects the sign-in attempt and displays Unable to sign in. The user should contact their Fax Portal administrator to confirm they have been added.
If a user exists in the Fax Portal but has not been added to your organization’s Microsoft Entra ID tenant, Microsoft Entra ID rejects the sign-in instead. It reports that the account does not exist in the tenant and must first be added as an external user before the user can sign in.
Tenants without SSO
SSO applies only to the tenant it is enabled for. If your company has multiple Fax Portal tenants, users are redirected to Microsoft Entra ID only after selecting the SSO-enabled tenant during sign-in. Other tenants keep the standard Fax Portal sign-in with a password.