How to Integrate Entra ID SSO with CallHippo

CH ST
Written by admin · Updated 2 Jul, 2026

Connecting Microsoft Entra ID (formerly Azure AD) to CallHippo lets your team sign in through your organization’s identity provider with a single, secure set of credentials.

The setup happens in three parts: activate the integration inside CallHippo, configure a SAML application in the Entra ID portal, and optionally enable user synchronization. Follow the sections in order.

Step 1: Activate the Entra ID SSO integration in CallHippo

  1. Log in to your CallHippo account.
  2. Open Integrations from the side menu, search for Entra ID SSO, and click Connect.
    CallHippo Integrations page showing EntraID SSO search result with a Connect button
  3. In the pop-up that appears, click Connect Now.
    Integration Setup popup for Microsoft Entra ID with a green Connect Now button
  4. The integration moves to an In Progress state.
    EntraID SSO integration card showing In Progress status after connecting
  5. The Integration Settings pop-up opens. The SSO SAML Settings tab shows the Recipient, ACS URL Validator, and ACS (Consumer) URL you will need in the Entra ID portal.
    CallHippo Integration Settings SSO SAML Settings tab showing Recipient, ACS URL validator and ACS URL
  6. The Configuration tab is where you will later paste the X.509 certificate text.
    CallHippo Integration Settings Configuration tab with an empty X.509 certificate text field

Step 2: Configure SSO in Microsoft Entra ID

  1. Log in to the Entra ID portal with an administrator account, go to Enterprise applications, and click New application.
    Microsoft Entra Enterprise applications page with the New application button highlighted
  2. Click Create your own application at the top of the gallery.
    Browse Microsoft Entra Gallery page with the Create your own application button highlighted
  3. Enter a name for the application, select Integrate any other application you don’t find in the gallery (Non-gallery), and click Create.
    Create your own application panel with app name entered and the non-gallery option selected
  4. On the application’s Overview page, open the Set up single sign on tile.
    Entra application Overview page with the Set up single sign on tile highlighted
  5. Choose the SAML single sign-on method.
    Select a single sign-on method screen with the SAML option highlighted
  6. In Basic SAML Configuration, set the Identifier (Entity ID) and Reply URL (ACS URL) using the values shown in the CallHippo SSO SAML Settings, then save.
    Basic SAML Configuration panel with Identifier Entity ID and Reply URL fields highlighted
  7. Under SAML Certificates, download the Certificate (Base64).
    SAML Certificates section with the Certificate Base64 Download link highlighted
  8. Open the downloaded certificate in a text editor, copy the certificate text, then return to the CallHippo Configuration tab, paste it into the X.509 certificate field, and save.
    CallHippo Configuration tab X.509 certificate field where the certificate text is pasted

Once the certificate is saved, the integration is successful. You can now assign the SSO application to CallHippo users in Entra ID, and it will appear in their app list.
Microsoft My Apps dashboard showing the CallHippo SSO application tile

When all configuration is complete and the required information is filled in, the CallHippo integration status shows as Integrated.
EntraID SSO integration card showing the Integrated status in CallHippo

Important notes on login behavior

  • Once the CallHippo and Entra ID integration is performed, sub-users cannot log in manually and must use SSO. This applies to the web, desktop, and mobile applications.
  • Only the Owner and Admins retain the ability to log in both manually and with SSO.

Step 3: Sync users between Entra ID and CallHippo (optional)

If you want to synchronize users, configure provisioning in Entra ID:

  1. Select your application from the application list.
    Entra Enterprise applications list used to select the CallHippo SSO application for provisioning
  2. Open the Provisioning section.
    CallHippo SSO application Overview with the Provisioning menu item highlighted
  3. Click New Configuration.
    Provisioning Overview with the New configuration button highlighted
  4. Set the authentication method to Bearer Authentication.
    New provisioning configuration authentication method dropdown with Bearer authentication selected
  5. Copy the Tenant URL and Secret Token from the CallHippo Configuration pop-up.
    CallHippo Configuration tab User Sync Configuration showing Tenant URL and Secret Token values
  6. Paste them into the Tenant URL and Secret token fields in Entra ID.
    New provisioning configuration with empty Tenant URL and Secret token fields highlighted
  7. Click Test Connection, then click Create.
    New provisioning configuration with credentials filled in and the Create button highlighted
  8. Open Provisioning again and expand the Mappings section.
    Provisioning page Mappings section listing Provision Microsoft Entra ID Groups and Users
  9. Open Provision Microsoft Entra ID Groups, set Enabled to No, click Save, then close the panel.
    Attribute Mapping for Provision Microsoft Entra ID Groups with Enabled set to No and Save highlighted
  10. Open Provision Microsoft Entra ID Users and configure the settings as shown (Enabled set to Yes).
    Attribute Mapping for Provision Microsoft Entra ID Users with Enabled set to Yes and Delete unchecked
  11. Review the attribute mappings between the SCIM attributes and Microsoft Entra ID attributes, then click Save and close the panel.
    Attribute Mappings table showing SCIM user attributes mapped to Microsoft Entra ID attributes
  12. Open the Settings section, set the Scope to Sync only assigned users and groups, set Provisioning Status to On, and click Save.
    Provisioning Settings with Scope set to Sync only assigned users and groups and Provisioning Status On

Auto-add and auto-remove users

Two toggles in the CallHippo integration pop-up control automatic user management:

  • Add: Enable this toggle so newly added Entra ID users are automatically created in CallHippo. Only users added to Entra ID after enabling the toggle are added automatically. Standard CallHippo user charges apply to additional users.
    CallHippo Configuration tab Permissions section with the Add toggle for auto-adding users highlighted
    Microsoft Entra Users page with the New user button highlighted
  • Delete: Enable this toggle so users are automatically removed from CallHippo when they are deactivated in Entra ID.
    CallHippo Configuration tab Permissions section with the Delete toggle for auto-removing users highlighted
    Entra user Overview page with the Edit link under Account status highlighted
    Entra user Properties page with the Account enabled checkbox highlighted

Note: User synchronization from Entra ID follows Entra ID’s provisioning schedule. Changes such as user additions and updates may take up to 40 minutes to reflect in CallHippo.

Need help setting up Entra ID SSO? Reach out to us at [email protected] and our team will assist you.
Still need a hand?

Can't find what you're looking for?

Our support team is here around the clock. Open a ticket or chat with us and we'll get you back on the call.