LeadFuel
FeaturesPricingBlogDownloadROI Calculator
Sign InGet Started
Made forThe trade show floor

LeadFuel

Capture every booth conversation. Enrich every lead. Automate every follow-up. Stop leaving revenue on the trade show floor.

Get Started →Sign In
Product
  • Features
  • Pricing
  • Integrations
  • Download
  • Blog
  • ROI Calculator
Company
  • About
  • Security
  • Contact
  • Support
Legal
  • Terms of Service
  • Privacy Policy
Contact
  • hello@lead-fuel.com
© 2026 LeadFuel · All rights reserved
Built for operators who own event ROI
Back to Support

SSO Setup (Azure AD)

Enable single sign-on so your team signs in to LeadFuel with their corporate Microsoft credentials.

15 minutes (plus DNS propagation)5 steps

Before You Start

  • A LeadFuel Enterprise plan
  • Admin access in LeadFuel
  • Someone who can add a DNS TXT record for your email domain
  • A Microsoft Entra administrator who can approve LeadFuel for your organization
1

Open Security Settings

Go to Settings → Security in your LeadFuel dashboard. This page is only visible on the Enterprise plan.

You do not create an app registration in Azure. LeadFuel is a pre-registered Microsoft application; your organization only needs to verify its email domain, provide its tenant ID, and approve LeadFuel once.

If you don't see the Security tab, your account may be on a different plan. Check Settings → Billing to confirm you're on Enterprise.

2

Configure and Verify Your Email Domain

In the Allowed Email Domain field, enter your organization's email domain — for example, acme.com — and click Save Settings.

The page then shows a DNS TXT record (name _leadfuel-sso.acme.com, value starting leadfuel-sso-verify=). Add it at your DNS host, then click Verify domain. DNS changes can take a few minutes to propagate.

This proves the domain is yours so no other LeadFuel customer can route your sign-ins to their account. Until it's verified, the Enable SSO toggle stays disabled.

Use your primary corporate email domain. If your company uses multiple domains, contact support and we can help configure additional domains.

3

Enter Your Microsoft Tenant ID

In the [Microsoft Entra admin center](https://entra.microsoft.com), open Overview and copy the Tenant ID — a GUID like 2f1a7c9e-4b3d-4e8a-9c21-0f6d5e8b7a10.

Paste it into Microsoft Entra Tenant ID in LeadFuel and click Save Settings. LeadFuel uses it to make sure every SSO sign-in comes from your tenant, not just from any Microsoft account with a matching email domain.

Use the GUID form only. The `yourcompany.onmicrosoft.com` form will not work.

4

Enable SSO

Toggle Enable SSO to on and click Save Settings. This activates single sign-on for users with your verified email domain.

Leave Enforce SSO (disable password login) off until you have tested. When enforced: - Users can only sign in via their Microsoft corporate account. This works on the web dashboard and in the iPhone app, which hands sign-in to Microsoft the same way the web does. The macOS desktop app still uses a password or a Transcription Key, so check who relies on it before you enforce - The admin who configured SSO retains password access as an emergency backdoor - SSO-only users who need a password can use the Forgot password flow while enforcement is off

5

Approve LeadFuel in Microsoft and Test

Have a Microsoft administrator open a private/incognito browser window, go to the LeadFuel sign-in page, enter their work email, and click Sign in with Azure AD.

Microsoft shows a consent screen listing what LeadFuel requests (sign in, read name and email). Tick Consent on behalf of your organization and click Accept. That one-time approval covers everyone in your organization.

Alternatively, after any user's first attempt, LeadFuel appears under Entra admin center → Enterprise applications; open it, go to Permissions, and click Grant admin consent.

Test without enforcing SSO first. Once you've confirmed sign-in works for a few team members, you can enable enforcement.

Troubleshooting

I don't see the Security tab in Settings
The Security settings page is only available on the Enterprise plan. Go to Settings → Billing to check your current plan, or contact your account administrator.
SSO sign-in fails with an error
Check three things: the email domain is verified (Settings → Security shows a green check), the Microsoft Entra Tenant ID is the GUID form (not yourcompany.onmicrosoft.com), and a Microsoft administrator has approved LeadFuel for your organization. If Microsoft shows 'Need admin approval', an admin must grant consent in Entra admin center → Enterprise applications → LeadFuel → Permissions.
The Enable SSO toggle is greyed out
Your email domain is not verified yet. Add the DNS TXT record shown under the domain field at your DNS host, wait a few minutes, then click Verify domain.
New users aren't appearing in my team
Users are automatically provisioned when they first sign in via SSO. They must actually complete the sign-in flow — just having Azure AD access doesn't create their LeadFuel account. Once they sign in, they appear in Settings → Team Members with the 'member' role.
I enforced SSO and locked myself out
The admin who configured SSO always retains password access as an emergency backdoor. Go to the sign-in page, enter your email, and you'll see both the Azure AD button and the password field. Use your LeadFuel password to sign in.
Can I disable SSO after enabling it?
Yes. Go to Settings → Security and toggle Enable SSO off. Users will revert to password login. SSO-only users (those who never set a password) will need to use the 'Forgot password' flow to create one.

Need more help?

Check other tutorials or reach out to our team.

All TutorialsContact Us