We connect sign-in for your application to your Microsoft Entra ID directory, formerly known as Azure Active Directory.

When staff already have a Microsoft work account, a separate password for the business system is one more thing to forget and one more account to remember to close. Signing in with Entra ID means one identity, your existing security policies such as multi-factor authentication, and access that ends the moment IT disables the account.

What we build with it

  • Single sign-on for staff
  • Central account deactivation when someone leaves
  • Group-based role assignment

How it works

  1. A user clicks sign in with Microsoft on the application.
  2. They are sent to Microsoft's sign-in page, where your organisation's policies, such as multi-factor authentication, apply.
  3. Microsoft returns a signed token confirming who the user is and, where configured, their group memberships.
  4. The system checks the token, matches the user to their account and gives them the roles linked to their groups.

Data exchanged

  • User identity and email
  • Group membership
  • Authentication tokens

What is needed to set it up

  • An Entra ID tenant
  • An app registration with redirect URIs
  • Admin consent for requested scopes

Good to know

  • The business system never sees the user's Microsoft password. It only receives a signed confirmation from Microsoft.
  • Conditional access and multi-factor rules are enforced by Microsoft, so your IT team manages them in one place.
  • Sign-in depends on Microsoft being reachable. We usually keep a separate emergency administrator login for that case.