For workforce SSO where a customer's IT admin owns the tenant and you want email-domain routing, use Microsoft Entra ID instead.
Copy the redirect URI
In the Authdog console, select the project and environment, open Authentication > Providers, find Microsoft, and click Enable. Copy the redirect URI:
https://identity.authdog.com/api/v1/callback/<connectionId>Register the application
- Open the Azure portal and go to Microsoft Entra ID > App registrations.
- Select New registration.
- Name the application.
- Under Supported account types, choose Accounts in any organizational directory and personal Microsoft accounts unless you intend a single tenant.
- Under Redirect URI, select Web and paste the redirect URI from Authdog.
- Register, then copy the Application (client) ID.
- Open Certificates & secrets, create a client secret, and copy the secret Value immediately. Azure hides it after you leave the page.
Configure Authdog
| Field | Value |
|---|---|
| Client ID | Application (client) ID |
| Client Secret | The secret Value, not the secret ID |
Save, then toggle the connection active.
Authdog uses the common endpoint and requests user.read, then reads the profile from Microsoft Graph /v1.0/me. A single-tenant registration refuses users outside that tenant even though the request reaches Microsoft.
Test it
- Open hosted sign-in, or
https://identity.authdog.com/api/v1/signin/<connectionId>. - Select Continue with Microsoft.
- Test a personal account and a work account if your audience covers both.
- Confirm the user appears under Users.
Troubleshooting
| Symptom | Cause |
|---|---|
AADSTS50011 |
The redirect URI is missing, or registered under the wrong platform type |
AADSTS7000215 |
The secret ID was pasted instead of the secret value, or the secret expired |
AADSTS50020 |
The registration is single-tenant and the user is external |
AADSTS65001 |
An admin must grant consent for the tenant |
Related
| Read | To learn how to |
|---|---|
| Microsoft connector | The same setup in the connector catalog |
| Entra ID setup | Workforce SSO with domain routing |
| Marketplace | The listing for this integration |