Microsoft Entra External ID supports a variety of industry-standard protocols and authorization flows. To enable applications to interact with Microsoft Entra external ID, they must be registered in the Microsoft Entra External ID tenant. This registration allows applications to utilize Microsoft Entra's security features and enable provides single sign-on (SSO). This section outlines the features available for your applications.
The following table compares the features available for OAuth 2.0 and OpenID Connect authorization flows in each type of tenant.
- Authorization code
- Authorization code with Code Exchange (PKCE)
- Client credentials using v2.0 applications (preview)
- Device authorization
- Implicit grant
- OpenID Connect
- On-Behalf-Of flow
- Resource Owner Password Credentials (no) - For mobile and single page applications, use native authentication
Microsoft Entra supports (preview) SAML (Security Assertion Markup Language) relaying party applications, enabling seamless integration and secure single sign-on (SSO) for enterprise applications.
Microsoft Entra ID supports SP-initiated authorization flows. In an SP-initiated SAML flow, the user starts the authentication process from the Service Provider's (relying party) application.
The authorization request may include the following parameters:
- ForceAuthn (Boolean value) - if true, it means that the user will be forced to reauthenticate, even if they have a valid session with Microsoft Entra external ID.
- NameIDPolicy this element requests a particular name ID format in the response.
Application registration in Microsoft Entra external ID is essential for establishing a trust relationship between your application and Microsoft Entra external ID. By registering your application, you obtain a unique Application (client) ID, and in some cases application secret or certificate. The application registration configure necessary settings like redirect URIs and API permissions.
Administrator can: list, register, update, delete applications.
Microsoft Entra external ID supports authentication for various modern app architectures including:
- Web Apps: Traditional server-side web applications that serve web pages to users and use OAuth 2.0, OpenID Connect and SAML for authentication.
- Single-Page Apps (SPA): These apps have a single-page front end written primarily in JavaScript and use frameworks like Angular, React, or Vue.
- Mobile and Native Apps: Applications running on mobile devices or desktop environments, using MSAL for authentication.
- Web APIs: Backend services that expose APIs for consumption by other applications, secured using OAuth 2.0.
- Service, Daemon, and Script Applications: Background services or scripts that run without user interaction, using client credentials for secure access to APIs.
For mobile and single-page apps, Microsoft Entra’s native authentication allows you to have full control over the design of your mobile application sign-in experiences.
For confidential applications, like web apps that are capable of storing sensitive data, application registration credentials in Microsoft Entra external ID are essential for establishing a secure trust relationship with your application. These credentials verify your application's identity, enabling it to safely obtain tokens and access to web APIs. This section lists the supported application registration credentials you application can use.
Application registration in Microsoft Entra external ID supports multiple credentials to facilitate rotation. Rotating secrets involves creating new secrets and deleting old ones. This can be done manually through the Microsoft Entra admin center or automated using Graph API or PowerShell script.
TBD: confirmation. Microsoft Entra ID automatically generates a three-year valid X509 certificate when you create a SAML application through the Microsoft Entra Application Gallery. Administrators can manage these certificates through the Microsoft Entra admin center, PowerShell, or Microsoft Graph.
To prevent disruptions due to expired certificates, Microsoft Entra ID sends email notifications 60, 30, and 7 days before a SAML certificate expires.
Microsoft Entra ID allows you to delegate application creation and management permissions in several ways:
- Assigning Application Owners: This method allows you to grant someone the ability to manage all aspects of Microsoft Entra configuration for a specific application.
- Assigning built-in administrative roles like Application Developer role or custom role that grants broad application configuration permissions without access to other parts of Microsoft Entra external ID.
Microsoft Entra external ID's single sign-on (SSO) allows users to sign in using one set of credentials to multiple application. Using SSO means a user doesn't have to sign in to every application they use. With SSO, users can access all needed applications without being required to authenticate using different credentials.
When a user selects the "Stay signed in?" prompt during the sign-in process, a persistent authentication session is set allowing the user to remain signed in even after closing and reopening their browse. The KMSI setting can be enabled or disabled by administrators in the Microsoft Entra admin center.
When a user initiates a sign-out from an application (OpenID Connect and SAML) they are redirected to the Microsoft Entra logout endpoint. This ensures that the user's session is properly terminated both in the application and with Microsoft Entra ID.
Microsoft Entra uses front-channel Logout to ensure that when a user signs out from one application, they are also signed out from all other applications that participated in the single sign-on session. OpenID Connect back-channel logout is currently not supported.
Microsoft Authentication Library (MSAL) enables application developers to authenticate users and obtain security tokens to access secured web APIs, including our own web APIs or Microsoft Graph. MSAL supports both OpenID Connect and OAuth2 protocols and is compatible with various application architectures and platforms, such as .NET, JavaScript, Java, Python, Android, and iOS, making it versatile and suitable for a wide range of applications.
Microsoft Entra External ID manages user consent differently from Microsoft Entra ID for workforce, since it focuses primarily on secure and seamless authentication and authorization for external users. As a result, administrator consent is required. External users don't consent to application permissions.
Microsoft Entra external ID allows you to add a custom attribute (type of Boolean) to the sign-up page. Before completing the sign-up, users should read and accept your policies. For more information, learn how to collect user attributes during sign-up and configure a single-select checkbox. The text and the link to the policies can be localized.
Using the company branding you can add links to "Terms of Use" and "Privacy & Cookies". The text and the link to the policies can be localized.
Upon successful sign-in, users will be taken back to your application with a security token. These tokens (JWT and SAML) can be customized (per application), including:
- Customize claims issued in security tokens using claim mapping.
- Apply a transformation to a user attribute issued security tokens.
- Include claims from external systems using custom claims provider.
- Configure groups optional claims are (limited to the group object ID).
- Application roles are included in the security token by default.
- You can specify the lifetime of security tokens issued by the Microsoft Entra ID. However you cannot configure refresh and session token lifetimes.
Microsoft Entra external ID signing keys roll on periodically. In emergency situations, tenant administrators can update them immediately. The public keys are available via OpenID Connect discovery document and SAML/WS-Fed federation metadata document. All applications that use the Microsoft Entra external ID should be able to programmatically handle the key rollover process.
User accounts for your consumers and business customers are most commonly created when users sign up for your applications. However, you can also create user accounts in the Microsoft Entra admin center or by using Microsoft Graph.
There are two types of user accounts you can manage in your external tenant:
-
Customer account: Accounts that represent the customers who access your applications. They can NOT access Azure resources such as the Azure portal. A customer user can be a local account or external account.
- Local accounts are accounts that their credentials are managed in your Microsoft Entra external ID tenant, such as users who sign-in with a username and password, or username and one-time passcode.
- External accounts Are accounts which are managed by external identity providers like Facebook or Google.
-
Admin account: Users with work accounts can manage resources in a tenant, and with an administrator role, can also manage tenants. Users with work accounts can create new consumer accounts, reset passwords, block/unblock accounts, and set permissions or assign an account to a security group.
All tasks and features mentioned in this section are applicable to all types of accounts.
The user attributes you collect during sign-up are stored with the user's profile in your directory. You can choose from built-in user attributes or create custom user attributes.
-
Built-in user attributes, such as city, country/region, email address, and so on, are available in Microsoft Entra External ID. You can choose the built-in user attributes you want to collect during sign-up.
-
For any additional information you want to collect, you can create custom user attributes.
The self-service sign-up offers several input controls can be added to the sign-up page to collect the attributes, including text boxes, numeric text boxes radio buttons, and single select and multi-select check boxes.
In Microsoft Entra External ID, administrators with the appropriate permissions can access the Microsoft Entra Admin Center. This serves as the primary interface for administrators to manage users and perform various tasks. You can automate account management by using the Microsoft Graph user endpoint. The following features are available for account management:
- Create an external account
- Manage user profile info
- Reset a user's password.
- Delete user's account
- Restore or remove a recently deleted user.
- Disable accounts to prevent the new user from being able to sign in.
- Assign application roles to users and groups to control who has access to content and functionality in the application.
- Add users to security groups.
- Reset their email or phone multi-factor authentication
Microsoft Entra External ID provides a self-service profile editing, enabling users to update their profile information securely. Profile edit is performed within your applications by calling the Microsoft Graph API /me endpoint using "delegated permissions" with the user tokens.
Application administrators can configure multifactor authentication (MFA) to allow users to edit their profiles securely. This ensures that only authorized users can make changes to their profiles.
An administrator or an application with appropriate permissions can delete a user account from the directory. After you delete a user, the account remains in a suspended state for 30 days. During that 30-day window, the user account can be restored, along with all its properties.
- Microsoft Entra ID sign-in logs provide comprehensive information to assist administrators in monitoring and managing user activities. These logs include detailed data about both the user and the client.
- Application user activity offers data analytics on the activity of users for registered applications in your tenant.
- Microsoft Entra activity logs include audit logs, which is a comprehensive report on every logged event in Microsoft Entra ID. Changes to applications, groups, users, and licenses are all captured in the Microsoft Entra audit logs.
The following table lists the authentication methods and external identity providers for primary authentication and multifactor authentication (MFA) for external users.
| Method | Sign-in | Sign-up | Password reset | MFA |
|---|---|---|---|---|
| Email with password | Yes | Yes | ||
| Email one-time passcode | Yes | Yes | Yes | Yes |
| SMS-based authentication | Yes | |||
| Apple federation (preview) | Yes | Yes | ||
| Facebook federation (preview) | Yes | Yes | ||
| Google federation (preview) | Yes | Yes | ||
| Microsoft personal account (via OpenID Connect federation | Yes | Yes | ||
| OpenID Connect federation | Yes | Yes | ||
| SAML/WS-Fed to confirm with Bora | Yes | Yes |
Administrators with certain roles can enable Multi-Factor Authentication (MFA) through conditional access policies for individual users and security groups. When a user signs in and is prompted for MFA, they must complete the MFA challenges.
Microsoft Entra external ID simplifies user sign-up, sign-in, and password reset processes through a unified interface. Users have the option to sign-up or sign-in with a username, reset their password, or sign-in using an external account such as Facebook or Google.
Admin can:
- Set up user sign-in options, such as email and password or email and one-time passcode.
- Enable or disable the self-service password reset option.
- Set up the external identity providers available to users, such as Google and Facebook.
- TBD, Disable the sign-up option.
Applications can initiate the authorization request with the sign-up flow by using the 'prompt=create' query parameter. You can also use the 'login_hint' query parameter to provide an email address. If given, Microsoft Entra external ID fills in the sign-up email address, requiring the user to only validate their email and enter profile details.
Apps can include the 'login_hint' query parameter with the user's sign-in name in the authorization request. Microsoft Entra external ID fills in the sign-in name, while the user only needs to provide the password or enter the verification code.
When a user attempts to sign in and users are already signed in within the same web browser, an account selector will be displayed. This will prompt users to choose the account with which they wish to sign in.
The automatic filling of SMS verification codes into sign-in page is typically a feature provided by the operating system of the device rather than Microsoft Entra ID itself. For example, both iOS and Android have features that can detect SMS messages containing verification codes and offer to auto-fill them into the appropriate field Microsoft Entra ID.
Upon successful sign-in, users are redirected back to the application with a security token. In instances where an error occurs during the authentication process, users may be redirected to an error page within the application, or the authentication process will be terminated and an error page which details the issue and provides necessary actions for resolution.
The sign-in and sign-up pages can be branded (per application) to create a consistent appearance with your application. This includes customizing elements such as the background image, background color, favicon, layout, header, footer, labels and links, sign-in page text, and uploading custom CSS files for further tailoring of the sign-in experience.
Administrator can: list, create, update, delete custom brandings.
You can create a personalized sign-in experience for users who sign in using a specific browser language by customizing the branding elements for that browser language. This customization overrides any configurations made to the default branding.
Text can be added to the bottom of the sign-in page. This text can be used to communicate additional information, such as help desk contact details or legal statements.
- 1,024 characters maximum
- Use Markdown syntax to format text including: Hyperlinks, bold, italics and underline.
Microsoft provides the translations for 36 languages including languages that are read right-to-left, such as Arabic and Hebrew, are displayed in the opposite direction compared to languages that are read left-to-right.
Microsoft Entra external ID uses the browser's language settings to determine the language for the sign-in experience. If the browser is set to a specific language, that language will be used for the sign-in page.
Applications can specify a locale parameter (ui_locales and mkt) in the authentication URL to enforce a particular language.
Smart lockout helps lock out bad actors that try to guess your users' passwords or use brute-force methods to get in.
Microsoft Entra ID enforces password policies to enhance security and ensure robust password practices.
TBD: check which features are available in MEEID
Arkose Labs' New Account Fraud Solution is designed to combat the creation of fraudulent accounts to ensure the security of your application while maintaining a seamless onboarding experience for legitimate users.
Cloudflare Web Application Firewall (Cloudflare WAF) to protect your organization from attacks, such as distributed denial of service (DDoS), malicious bots, Open Worldwide Application Security Project (OWASP) Top-10 security risks, and others
Authorization in an app refers to the process of determining what actions a user is allowed to perform within the application.
Role-based access control (RBAC) is a popular mechanism to enforce authorization in applications. When an organization uses RBAC, an application developer defines roles for the application. An administrator can then assign roles to different users and groups to control who has access to content and functionality in the application. Then, applications that receive the access token in a request can then make authorization decisions based on the values in the roles claim.
Application developers can use security groups to implement Role-based access control (RBAC) in their applications, where the memberships of the user in specific groups are interpreted as their role memberships. When an organization uses security groups, a groups claim is included in the token with all of the groups to which the user is assigned. Apps that receive the access token then make authorization decisions based on the values in the groups claim.
App roles and groups both store information about user assignments in the Microsoft Entra directory. Another option for managing user role information that is available to developers is to maintain the information in the user's profile, like 'job title' or outside of the directory in a custom data store, using custom claims provider.
Applications registered in a Microsoft Entra tenant are, by default, available to all users of the tenant who authenticate successfully. However, it's possible to configure application to restrict access to certain set of users or apps. Unassigned users cannot complete the sign-in process.
To manage Microsoft Entra External ID, specific permissions are required. These permissions are typically assigned through built-in roles or custom roles in Microsoft Entra external ID.
Users can be searched in the Microsoft Entra admin center by name, email address, or other attributes. For more complex queries, such as finding users who signed in with social accounts, use Microsoft Graph API or PowerShell.
The authentication request from the application to Microsoft Entra external ID does not contain personal data. Developers have the option to include the “log-in hint” parameter in the authentication request. The use of domain hint is optional.
Microsoft Entra audit logs provide a comprehensive report on every logged event within your Microsoft Entra ID tenant. These logs help determine who made changes to applications, users, groups, conditional access policies and more.
The logs contain information about the activity, like the application or individual that made the changes, the target object, the modified properties and more.
Audit logs are retained for seven days. You can effectively download or export the audit logs in Microsoft Entra ID for compliance, monitoring, and analysis purposes.
The sign-in logs provide detailed records of all sign-in activities within Microsoft Entra external ID. Sign-in logs capture details such as the date and time of the sign-in, the user's identity, the application used, the device and browser information, and the sign-in status (success or failure).
Sign logs are retained for seven days. You can effectively download or export the sign logs in Microsoft Entra ID for compliance, monitoring, and analysis purposes.
The “Application user activity” feature provides data analytics on user activity and engagement for registered applications in your tenant. You can use this feature to view, query, and analyze user activity data in the Microsoft Entra admin center and Graph API. This feature can help you uncover valuable insights that can aid strategic decisions and drive business growth.