SSO Integration

Microsoft 365 SSO + Entra ID for Peoplifi UAE

Peoplifi supports SAML 2.0 SSO with Microsoft 365 and Entra ID. SCIM keeps Peoplifi in sync with your Entra directory automatically, approved time-off pushes to Outlook calendars, and Conditional Access policies (MFA, compliant device, named locations) flow through SAML assertions.

Try Peoplifi Free for 7 Days

How it works

  1. IT admin creates an Enterprise Application in Entra ID using the Peoplifi gallery template
  2. SAML 2.0 configured with Peoplifi's ACS URL + Entity ID
  3. SCIM provisioning enabled
  4. Employees sign in with 'Continue with Microsoft'
  5. Time-off pushes to Outlook

Features

SAML 2.0 SSO
SCIM 2.0 user + group provisioning
Group-based role mapping
Outlook calendar sync
Conditional Access supported
Audit logs
JIT account creation

Setup Guide

  1. Entra ID → Enterprise Applications → New → search 'Peoplifi'
  2. Configure SAML, upload Entra metadata to Peoplifi
  3. Enable SCIM with Peoplifi tenant URL + bearer token
  4. Assign UAE users / groups to the Peoplifi app
  5. Test login

Frequently Asked Questions

Does this support Microsoft 365 GCC High?

GCC is supported on Business / Enterprise plans. GCC High and DoD environments need an enterprise contract.

How does this work for hybrid Azure AD / on-prem Active Directory environments?

The Peoplifi integration uses cloud-based Entra ID (formerly Azure AD) for SCIM and SSO. Hybrid customers running Azure AD Connect to sync from on-prem AD will see those synced users available for SCIM provisioning to Peoplifi. The integration doesn't directly read on-prem AD.

Are Conditional Access policies enforced for Peoplifi sign-in?

Yes. Because Peoplifi delegates authentication entirely to Entra ID via SAML, any Conditional Access policy you configure in Entra ID — MFA requirements, named-location restrictions, device compliance, sign-in-risk-based policies — applies automatically to Peoplifi sign-ins.

Deep dive: Microsoft 365

Why Microsoft 365 SSO matters for UAE enterprise customers

Microsoft 365 (formerly Office 365) is one of the most widely-deployed enterprise productivity suites in the UAE — particularly common in financial services, government-adjacent organisations, healthcare, professional services, and large corporates. For HR-tech adoption, integrating with Microsoft 365 / Entra ID provides several enterprise-grade benefits: SAML 2.0 SSO with Conditional Access enforcement; SCIM 2.0 user lifecycle automation; group-based role mapping through Microsoft 365 groups or Entra ID security groups; integration with Microsoft Teams for HR communications; and alignment with the security frameworks UAE enterprises have already deployed.

SAML 2.0 architecture and Entra ID integration

The Peoplifi-M365 integration uses SAML 2.0 federated authentication through Entra ID (formerly Azure Active Directory). When an employee attempts to sign in to Peoplifi, the application redirects to Entra ID; Entra ID applies any configured Conditional Access policies (MFA, device compliance, location restrictions, sign-in risk evaluation); on success, Entra ID returns a signed SAML assertion to Peoplifi which creates a session. The Peoplifi app is available in the Entra ID Application Gallery, simplifying setup compared to manual SAML configuration. Users can launch Peoplifi from their MyApps portal or sign in directly at Peoplifi's URL.

SCIM 2.0 for lifecycle automation

Beyond authentication, the integration supports SCIM 2.0 for full user lifecycle automation. New hires added to Entra ID groups (typically 'Peoplifi Users' or similar) are auto-provisioned in Peoplifi within minutes with name, email, manager, department, and other configured attributes. Profile changes flow automatically: department transfers, manager changes, title updates. Deprovisioning is the most security-critical workflow — when an employee is offboarded in Entra ID, their Peoplifi access is suspended within minutes, preventing the orphaned-account exposure that less-integrated stacks struggle with. SCIM provisioning is configured through Entra ID's Enterprise Applications interface with the Peoplifi tenant URL and bearer token.

Conditional Access and security policy enforcement

One of the most valuable benefits of Microsoft 365 integration is Conditional Access policy enforcement. UAE enterprise customers typically have sophisticated Conditional Access configurations including (1) **MFA requirements** — universal or risk-based MFA. (2) **Named-location restrictions** — limiting sign-ins to corporate office IP ranges or approved geographies. (3) **Device-compliance enforcement** — only managed and compliant devices can access SaaS apps. (4) **Sign-in-risk evaluation** — Microsoft Defender for Identity flags suspicious sign-in patterns. (5) **Application-specific policies** — different policies for different SaaS applications based on data sensitivity. Because Peoplifi delegates authentication entirely to Entra ID, all these policies apply to Peoplifi sign-ins automatically. The security teams that have invested in Microsoft 365 Defender / Conditional Access infrastructure benefit fully without separate Peoplifi configuration.

Microsoft Teams integration

For UAE customers using Microsoft Teams as their primary collaboration platform, Peoplifi integrates with Teams for HR communications similar to the Slack integration. Features include leave-request slash commands within Teams chat, approval notifications via Teams adaptive cards, weekly out-of-office summaries posted to designated Teams channels, and birthday/anniversary announcements. The Teams integration uses the same OAuth-based authentication as the SSO integration, supporting the identity model UAE enterprise customers already trust.

Ready to connect Microsoft 365 to Peoplifi?

Start free 7-day trial