Inspect Point supports Single Sign-On with Microsoft Entra ID (formerly Azure Active Directory). Your team signs in to the Inspect Point backend, the Technician Portal, and the iPad app using your own Microsoft credentials instead of passwords stored in Inspect Point.
To enable it, you will register one application in your Entra ID tenant and send us two values:
- Application (client) ID
- Directory (tenant) ID
Before you start, one thing to know: once Microsoft sign-in is enabled, the Inspect Point backend sign-in page shows only the Sign in with Microsoft button — the email and password fields, along with Remember me and Forgot password, are hidden. If you would rather keep email and password sign-in available alongside Microsoft sign-in, say so in your ticket and we can turn that on for you.
The Technician Portal and the iPad app are not affected by this — they always offer both Microsoft and password sign-in.
Before you begin: users and email addresses
Every backend user and technician in Inspect Point must have an email address that matches their UPN or Email in Entra ID. If the addresses do not match, that person will not be able to sign in with Microsoft. Both native accounts and guest accounts in your directory are supported.
Step 1: Register an application
In the Microsoft Entra admin center, go to Identity > Applications > App registrations and choose New registration.
- Name: anything you like, for example Inspect Point
- Supported account types: Accounts in this organizational directory only
- Redirect URI: leave this blank for now — you will add it in Step 2
Microsoft's full walkthrough is here if you need it: Register an application with the Microsoft identity platform.
Step 2: Add redirect URIs using the Single-page application platform
This is the step that most often goes wrong. Inspect Point's web sign-in uses MSAL.js, which requires redirect URIs to be registered under the Single-page application platform. Registering them under Web will cause sign-in to fail.
- Open your app registration and go to Manage > Authentication.
- Select Add Redirect URI (in some versions of the portal this is labelled Add a platform).
- Under Web applications, choose Single-page application. Do not choose Web.
- Enter your Inspect Point backend sign-in URL, replacing yoursubdomain with your own:
https://yoursubdomain.inspectpoint.com/users/sign_in
- Leave both Implicit grant and hybrid flows checkboxes — Access tokens and ID tokens — unchecked. Inspect Point uses the Authorization Code flow with PKCE, which does not use implicit grant.
- Select Configure.
- Select Add Redirect URI again, choose Single-page application a second time, and add the Technician Portal URL exactly as shown. This one is identical for every customer:
https://technicians.inspectpoint.com/auth/o365-callback
The Single-page application redirect URI panel should look like this:
If you have more than one Inspect Point subdomain, add a separate /users/sign_in URI for each one. The Technician Portal URI is only added once.
Note: the implicit grant settings apply to both the Web and Single-page application platforms. If you need to change them later, they are on the Settings tab of the Authentication page.
Step 3: Add the iOS platform for iPad sign-in
To allow technicians to sign in from the Inspect Point iPad app, add a second platform to the same app registration.
- Still on Manage > Authentication, select Add Redirect URI again.
- In the same platform picker shown above, under Mobile and desktop applications, choose iOS / macOS. Do not choose Mobile and desktop applications, which is the tile for Windows and classic device flows.
- Enter the Inspect Point Bundle ID. This is the only field on this screen:
com.inspectpoint.InspectPoint
- Select Configure. You do not need to enter a redirect URI — Entra generates it from the Bundle ID, and it will read
msauth.com.inspectpoint.InspectPoint://auth.
Step 4: Confirm API permissions
Under Manage > API permissions, confirm that Microsoft Graph > User.Read (delegated) is listed. This is added automatically on new app registrations and is used by the Technician Portal and the iPad app to read the signed-in user's profile. No admin consent is required for this permission.
Step 5: Send us your IDs
Open a ticket at support.inspectpoint.com and include:
- Application (client) ID — found on the app registration Overview page
- Directory (tenant) ID — also on the Overview page
- The Inspect Point subdomain or subdomains you want Single Sign-On enabled on
- Confirmation that your redirect URIs are registered under the Single-page application platform
That last point matters — it tells our team which sign-in configuration to enable for your account, so please include it.
Where Single Sign-On applies
Once we have configured your account, a Sign in with Microsoft button appears on all three Inspect Point sign-in screens:
-
Inspect Point backend — at
https://yoursubdomain.inspectpoint.com/users/sign_in - Technician Portal — at technicians.inspectpoint.com, after entering your subdomain
- iPad app — after entering your subdomain and tapping Continue
Each person can only sign in with Microsoft if their Entra ID UPN or Email matches their Inspect Point email address.
For step-by-step sign-in instructions to share with your technicians, see How to log into the Inspect Point app with Azure Directory.
Troubleshooting
| What you see | What to check |
|---|---|
AADSTS9002326: Cross-origin token redemption is permitted only for the 'Single-Page Application' client-type |
The redirect URI is registered under Web. Remove it and re-add it under Single-page application. The same URI cannot exist under both platforms. |
AADSTS50011: The redirect URI specified in the request does not match |
The URI in Entra does not exactly match the one Inspect Point sends. Check for a trailing slash, http instead of https, or a misspelled subdomain. |
| The Microsoft button on the Technician Portal does nothing, or sign-in fails only there |
https://technicians.inspectpoint.com/auth/o365-callback is missing from the Single-page application platform. See Step 2. |
| Sign-in works for some people but not others | Those users' Inspect Point email addresses do not match their Entra ID UPN or Email. |
The browser console shows interaction_in_progress
|
Close any other open Inspect Point tabs, clear the browser's session storage, and try again. |
Need help? Contact our Support Team at support@inspectpoint.com or submit a support ticket through the "Submit a request" link above.
Comments
0 comments
Article is closed for comments.