Connect Apps to Microsoft Entra ID (Azure AD)
Microsoft Entra ID is the new name for Azure Active Directory (Azure AD). Microsoft renamed the product in 2023; existing Azure AD configurations and integrations continue to work without change. This page uses the current name, but you may still see "Azure AD" in older portals or documentation.
Prerequisite
Create a Microsoft Entra ID account here
Setup a tenant by completing Quickstart: Set up a tenant
Register an application by completing Quickstart: Register an application with the Microsoft identity platform
Choose "Supported account types", the following options are supported:
Single tenant only - <your tenant> (Accounts in this organizational directory only)
Multiple Entra ID tenants (Accounts in any organizational directory - Multitenant)
Any Entra ID tenant + Personal Microsoft accounts (Multitenant and personal Microsoft accounts, e.g. Skype, Xbox)
"Personal accounts only" is not supported yet. Remember the account type chosen as this affects the configuration on Authgear portal
Configure "Redirect URI" with
https://<YOUR_AUTHGEAR_ENDPOINT>/sso/oauth2/callback/azureadv2. See How to add a redirect URI to your application.Follow this section to add a client secret. Remember to record the secret value when you add the client secret, as it will not be displayed again. This will be needed for configure OAuth client in Authgear.
Redirect URI has the form of /sso/oauth2/callback/:oauth_provider_alias. The oauth_provider_alias is the OAuth Provider Alias configured for this provider in Authgear Portal.
Configure Sign in with Microsoft through the portal
In the portal, go to Authentication > Social / Enterprise Login.
Enable Sign in with Microsoft
Fill in Client ID with Application (client) ID of your just created Microsoft Entra ID application.
Fill in Client Secret" with the secret you get after creating a client secret for your Microsoft Entra ID application.
For Tenant field:
If single tenant (first option) is chosen, fill in the Directory (tenant) ID of your Microsoft Entra ID application.
If multi tenant (second option) is chosen, fill in the string literal
organizations.If multi tenant and personal account (third option) is chosen, fill in the string literal
common.
Save the settings.
🎉 Done! You have just added Microsoft Entra ID (Azure AD) Login to your apps!
Force Login page
Microsoft Entra ID automatically logs in to the same account without requiring a username and password. To prevent this behaviour, you can use the prompt=login parameter to force Microsoft Entra ID to show the login page. See our guide on using the prompt=login parameter in Authgear SDKs to learn more.
Last updated
Was this helpful?