What Microsoft Entra ID is
Microsoft Entra ID is Microsoft's cloud identity service, known as Azure Active Directory until 2023. It holds an organisation's users and groups, signs them in to Microsoft 365 and other apps, and applies Conditional Access policies such as requiring multi-factor authentication or a compliant device.
From the same family, Microsoft Entra External ID signs in consumers and business customers, and the Microsoft identity platform also accepts personal Microsoft accounts. Companies on Microsoft 365 already have their staff in Entra ID, which is why it is one of the identity providers our authentication module and backoffice connect to.
What it does in your platform
Authentication
Signs people in over OpenID Connect or SAML: staff and partners from your Entra tenant, customers through Microsoft Entra External ID if you run it, and anyone with a personal Microsoft account through the Microsoft button on your sign-in screen.
Admin backoffice
Signs your staff in to the backoffice with their work account, under the Conditional Access policies your IT team already set. App roles or group claims in the token decide what each person can do.
How the connection works
The backoffice and the module are registered as apps in your Entra tenant and talk to it over OpenID Connect. Microsoft Graph sends change notifications for users and groups to the platform, so access follows your directory.
An agent signs in
The backoffice sends them to Microsoft's sign-in page for your tenant, where your Conditional Access policies apply.
A token comes back
Entra ID returns a signed ID token with the agent's identity and the app roles you assigned to them or to their groups.
Roles open screens
The backoffice maps each app role to one of its roles, with permissions down to single actions and fields, and a second person's approval on sensitive ones.
IT changes something
When someone moves team or is disabled, Microsoft Graph sends a change notification for that user or group, so the platform can update their role or sign them out.
Every step is on record
Sign-ins appear in Microsoft Entra's own logs, and every action in the backoffice is logged with who did it, when and from where.
Next to other providers
Entra ID can run the staff side while customers sign in elsewhere, such as the module's own passkey sign-in, Auth0 or AWS Cognito, with the Microsoft button next to Google and Apple. Each side keeps its provider, and roles, sessions and the audit log stay on the platform.
The module speaks OpenID Connect and SAML, so if your company moves to another directory later, the backoffice follows with a configuration change and no new release.
When Microsoft Entra ID fits best
A strong fit when
- Your staff already sign in with Microsoft 365 work accounts.
- Your IT team manages access with Conditional Access and wants the backoffice under the same policies.
- Your customers include businesses and people who already have a Microsoft account.
Also worth a look
- Okta or Google Workspace, when your staff accounts live there instead.
- A customer identity platform such as Auth0 or AWS Cognito, when Microsoft is one sign-in option among several.
How we get you live
The tenant
We connect to the Entra ID tenant your company already runs, or help you set one up for the platform.
The app registrations
We register the backoffice and the customer apps in your tenant, define the app roles, and choose which accounts can sign in: your organisation's, other organisations' or personal Microsoft accounts.
The keys
Client secrets or certificates go into your platform's secrets and nowhere else. The apps only carry their public client identifiers.
A full test run
We test staff sign-in, role mapping and a disabled account end to end with test users before your team switches over.
