At SplitMetrics Acquire, we've made it easy to set up Single Sign-On (SSO) and provide your team with a secure and convenient way to access Acquire 🔐
By setting up SSO with Microsoft Entra ID (formerly Azure Active Directory), your team can use their organization credentials to sign in to SplitMetrics Acquire without needing a separate Acquire password.
Follow the steps below to configure the integration in Microsoft Entra ID.
☝️ To get started, you’ll need administrator access to your organization’s Microsoft Entra ID.
Log in to the Microsoft Entra admin center and navigate to:
Entra ID → App registrations → New registration
Create a new application registration.
A single-tenant configuration is sufficient for the SplitMetrics Acquire integration.
Open your newly created app registration and add a Web redirect URI.
Use the following URI exactly:
Make sure there are no extra spaces or characters in the URI.
⚠️ Important: The redirect URI must match exactly. Even a small difference can prevent the SSO login from working correctly.
In your app registration, navigate to:
Certificates & secrets → New client secret
Create a new client secret and make a note of its expiration date.
⚠️ Important: When sharing the credentials with SplitMetrics, we need the Client secret Value, not the Secret ID.
Keep the secret value secure and do not share it anywhere other than through the agreed secure channel.
In the left-hand menu of your app registration, go to:
API permissions → Add a permission
Then:
Select Microsoft Graph.
Select Delegated permissions.
Find the OpenId permissions section.
Select the following permissions:
openid
profile
email
Click Add permissions.
After adding the permissions, select:
Grant admin consent for <your tenant name> → Yes
Once consent has been granted, verify that the Status column shows Granted for <your tenant name> with a green checkmark for all three permissions.
💡 Note: A new Microsoft Entra app registration may also include the User.Read Microsoft Graph delegated permission by default. You can leave this permission enabled; it does not affect the SplitMetrics Acquire SSO setup.
⚠️ Important: Admin consent is not optional - it is mandatory and not providing it leads in users getting issues with logging in later - they may become blocked.
Next, go to:
Token configuration → Add optional claim
Select:
ID → email, given_name, family_name
Add the following claims:
email
given_name
family_name
⚠️ Important: SplitMetrics Acquire uses the email claim to identify users. Make sure the email attribute is populated for the users who will access Acquire.
❗ If some users do not have an email, first name, or last name populated in Microsoft Entra ID -please let our Support team know before completing the setup, this is crucial
Next, assign the users or groups who should have access to the application.
Go to:
Identity → Applications → Enterprise applications → All applications
Find the Enterprise Application corresponding to the app registration you created and assign the required users and/or groups.
You can also configure the application to allow access for all users, if this matches your organization's access policy.
Please confirm the email domain(s) that your users use to sign in to SplitMetrics Acquire.
For example:
yourcompany.com
If your organization uses several email domains, please provide all relevant domains.
Once you've completed the Microsoft Entra ID configuration, please share the following information with your dedicated Account Manager or our Support team:
Directory (tenant) ID — available under Entra ID → Overview
Application (client) ID — available under App registrations → Overview
Client secret Value — available under App registrations → Certificates & secrets
Email domain(s) used by your users to sign in
⚠️ Important: Please make sure you send the client secret Value, not the Secret ID.
We'll use these details to complete the SSO configuration on the SplitMetrics Acquire side.
Once everything is configured, we'll let you know so you can test logging in with your Microsoft account and start using secure, seamless access to Acquire ✨
Microsoft Entra client secrets have an expiration date. Once a secret expires, SSO authentication can stop working for all users in your organization.
To avoid an unexpected interruption, please keep track of the secret's expiration date and plan its renewal in advance.
How to rotate an expiring client secret
Microsoft Entra allows multiple active client secrets, so you can replace an expiring secret without interrupting access:
In Microsoft Entra ID, go to Certificates & secrets → New client secret and create a new secret.
Keep the existing secret active and securely share the new secret Value with the SplitMetrics Acquire Support team.
We'll update the SSO configuration on our side.
Test a real login to confirm that the new secret works.
Only after the new login has been successfully verified should you delete the old secret.
Please also confirm the new secret's expiration date with us so it can be tracked for future renewal.
💡 Tip: Never delete the old secret before the new one has been configured and successfully tested. Keeping the old secret active provides a safe rollback option if anything needs to be corrected.
❗ Platform automatic autofilling option:
When you sign in through any SSO, your first and last name are synced from your SSO provider to SplitMetrics Acquire.
By default, these names are updated on each login, so they can overwrite the first and last name currently set in Acquire.
If you need a different name to be displayed in Acquire, contact our Support team and we can disable this synchronization for your organization.
This behavior applies to SSO integrations in Acquire in general, including Microsoft Azure, Okta, and Amazon.
Pricing and Availability
SSO integration is available as a separately paid add-on.
For pricing and more information, please contact your Customer Success Manager.







