Microsoft Entra ID (formerly Azure AD) connects to Authdog over OpenID Connect. Entra stays the system of record for your workforce; Authdog fronts your application and consumes the ID token.

## Copy the redirect URL

In the [Authdog console](https://console.authdog.com), select the project and environment, open **Authentication > Providers**, find **Microsoft Entra ID**, and click **Enable**. Copy the **Redirect / Callback URL**:

```url
https://identity.authdog.com/api/v1/callback/<connectionId>
```

Each environment has its own connection id, so its own redirect URL.

## Register the application in Entra

1. In the Entra admin center, open **Identity > Applications > App registrations** and click **New registration**.
2. Set a name, keep **Accounts in this organizational directory only**, and add a **Web** redirect URI with the Authdog callback URL.
3. Under **Certificates & secrets**, create a client secret and copy its value — it is shown once.
4. Copy the **Application (client) ID** from the Overview page.
5. Note the **OpenID Connect metadata document** URL, e.g. `https://login.microsoftonline.com/<tenant-id>/v2.0/.well-known/openid-configuration`.

## Configure Authdog

| Field | Value |
| --- | --- |
| **Client ID** | Application (client) ID |
| **Client secret** | The secret value from Certificates & secrets |
| **Discovery URL** | The OpenID Connect metadata document URL (the `/.well-known/openid-configuration` suffix is optional) |
| **Email domains** | Domains routed to this connection, e.g. `acme.com` |

Save, then toggle the connection **active**.

## Test the connection

1. On the saved connection, click **Test connection**. Authdog validates the required fields, then fetches the discovery document and confirms it carries `authorization_endpoint`, `token_endpoint`, and `jwks_uri`. Failures come back with named codes — `unreachable` when the document cannot be fetched, `missing_endpoint` when it is the wrong document.
2. Then run a real login: open the **Login URL**, complete the Entra prompt, and confirm the user appears under **Users** with an Entra identity linked.

## Rotate the secret

Entra client secrets expire. When one does:

1. Create a new secret under **Certificates & secrets**.
2. Paste it into the connection's **Client secret** field and save.

No downtime: the old secret keeps working until Entra expires it. Secret rotations are recorded in the environment audit log.

## Troubleshooting

| Symptom | Cause |
| --- | --- |
| `unreachable` fault on discovery | Wrong tenant id in the discovery URL, or the app registration was deleted |
| `missing_endpoint` fault | The URL points at a v1 endpoint or a non-OIDC document — use the v2.0 metadata URL |
| `AADSTS700016` | The client ID does not exist in this tenant |
| `AADSTS50011` | The redirect URI is not registered on the app registration |
| User looped back to sign-in | Email domain not listed on the connection |

## Related

| Read | To learn how to |
| --- | --- |
| [Enterprise SSO](/docs/sso) | Understand the SSO model and discovery |
| [SCIM provisioning](/docs/concepts/provisioning) | Sync Entra users and groups over SCIM |
| [Okta](/docs/sso/okta) | Connect Okta over SAML instead |
