Authdog

Entra

Last updated Sep 30, 2026
View as Markdown

Microsoft Entra ID is a first-class enterprise connection over OpenID Connect. It is the workforce path: a customer's IT admin owns the tenant, and Authdog routes users by email domain. Personal Microsoft accounts and the consumer OAuth button are the Microsoft connector.

Open the connection

In the Authdog console:

  1. Select the project and environment.
  2. Open Authentication > Providers with the Enterprise filter.
  3. Choose Microsoft Entra ID.
  4. Copy the redirect / callback URL Authdog displays and register it on the Entra app as a Web redirect URI.
  5. Follow the vendor guide linked from the connection form for the Entra-side app registration.

Configure OIDC

Enter:

Field Value
Connection name A name that shows in the Configured list
OIDC discovery URL The discovery document URL for the tenant, not a bare issuer that does not serve the document
Client ID Application (client) ID
Client secret The secret value from Entra

Scopes default to openid profile email. Add an extra scope only when a claim you need requires it. Leave Prompt on the IdP default unless you need an account picker or a forced re-authentication.

Route by email domain

In Email domains (for SSO discovery):

contoso.com

The entry matches that domain and its subdomains. Keep domains from overlapping other enterprise connections in the same environment. Only active connections participate in discovery.

Test it

  1. Use Test on the connection.
  2. Sign in with a user in the routed domain and confirm the subject and email claims.
  3. Exercise Entra conditional access. Those policies run at Entra, not in Authdog.
  4. Repeat in production. If you add a custom domain, update the redirect URI Entra has on file with the URL shown in the form.

Store the client secret only in Authdog and Entra. Do not put it in browser code.

Read To learn how to
Enterprise SSO OIDC fields and domain routing
Microsoft setup Personal and work accounts without domain routing
Marketplace The listing for this integration