The Microsoft connector signs users in with a personal Microsoft account, a work or school account, or both, depending on the app registration. For workforce SSO where a customer's IT admin owns the tenant and you want email-domain routing, use [Microsoft Entra ID](/marketplace/entra/setup) instead.

## Copy the redirect URI

In the [Authdog console](https://console.authdog.com), select the project and environment, open **Authentication > Providers**, find **Microsoft**, and click **Enable**. Copy the redirect URI:

```url
https://identity.authdog.com/api/v1/callback/<connectionId>
```

## Register the application

1. Open the [Azure portal](https://portal.azure.com) and go to **Microsoft Entra ID > App registrations**.
2. Select **New registration**.
3. Name the application.
4. Under **Supported account types**, choose *Accounts in any organizational directory and personal Microsoft accounts* unless you intend a single tenant.
5. Under **Redirect URI**, select **Web** and paste the redirect URI from Authdog.
6. Register, then copy the **Application (client) ID**.
7. Open **Certificates & secrets**, create a client secret, and copy the secret **Value** immediately. Azure hides it after you leave the page.

> **Caution**
>
> Client secrets expire, up to 24 months. When the secret expires, every sign-in through this connector fails at the token exchange.

## Configure Authdog

| Field | Value |
| --- | --- |
| **Client ID** | Application (client) ID |
| **Client Secret** | The secret **Value**, not the secret ID |

Save, then toggle the connection **active**.

Authdog uses the `common` endpoint and requests `user.read`, then reads the profile from Microsoft Graph `/v1.0/me`. A single-tenant registration refuses users outside that tenant even though the request reaches Microsoft.

## Test it

1. Open hosted sign-in, or `https://identity.authdog.com/api/v1/signin/<connectionId>`.
2. Select **Continue with Microsoft**.
3. Test a personal account and a work account if your audience covers both.
4. Confirm the user appears under **Users**.

## Troubleshooting

| Symptom | Cause |
| --- | --- |
| `AADSTS50011` | The redirect URI is missing, or registered under the wrong platform type |
| `AADSTS7000215` | The secret ID was pasted instead of the secret value, or the secret expired |
| `AADSTS50020` | The registration is single-tenant and the user is external |
| `AADSTS65001` | An admin must grant consent for the tenant |

## Related

| Read | To learn how to |
| --- | --- |
| [Microsoft connector](/docs/connectors/microsoft) | The same setup in the connector catalog |
| [Entra ID setup](/marketplace/entra/setup) | Workforce SSO with domain routing |
| [Marketplace](/marketplace/microsoft) | The listing for this integration |
