---
title: MS Azure AD OIDC
slug: ms-azure-ad-oidc
description: Configure OIDC single sign-on with Microsoft Azure AD to authenticate organization users.
image: https://archbee-image-uploads.s3.amazonaws.com/oAyFj2GHlBeBVWF5OAir2/e_qHb1m7hHbasnTc0QETS_1.png
docTags: 
createdAt: 2025-02-03T13:28:13.882Z
---

:::hint{type="info"}
This feature is available to Enterprise customers.
:::

The following manual configuration creates an OIDC SSO configuration for your Enterprise organization.

## Prerequisites

- `Owner` or `admin` role in an Enterprise organization
- Administrative access to your organization's Microsoft Azure AD portal

## Supported features

This configuration supports the following:

- Service provider initiated SSO
- Single Log Out \[optional]

## Configuration steps

Before configuring SSO, you need to assign a namespace and make files of your service provider certificate and private key. These steps provide the information you need to enter later.

### Create your namespace in Make

::::WorkflowBlock
:::WorkflowBlockItem
Click **Organization** in the left sidebar.
:::

:::WorkflowBlockItem
Click the **SSO** tab.
:::

:::WorkflowBlockItem
Under **Namespace**, enter the namespace you want for your organization. For example, `acmecorp`. Your organization members enter this namespace when they log in via SSO.
:::

:::WorkflowBlockItem
Under **SSO type**, select **Oauth2**.
:::

:::WorkflowBlockItem
Copy the **Redirect URL** and save it in a safe place. You will use this later when you create your SAML integration in the Microsoft Azure AD portal.
:::
::::

### Create an OIDC application in the MS Azure portal

::::WorkflowBlock
:::WorkflowBlockItem
Log in to the [Microsoft Azure portal](https://azure.microsoft.com/en-in/) and navigate to the Azure Active Directory.

![MS Azure portal](https://api.archbee.com/api/optimize/yAufeXqD1oGWOPBNi5MAm-tD6CsOpNFHk6XV8ajr8R5-20250212-104942.png)
:::

:::WorkflowBlockItem
In the left navigation, click **Enterprise applications.**

::Image[]{src="https://api.archbee.com/api/optimize/yAufeXqD1oGWOPBNi5MAm-plGd2Ny-t1DL-eWQw36Ui-20250212-105215.png" size="40" width="317" height="599" position="flex-start" alt="MS Azure Enterprise applications" darkWidth="317" darkHeight="599" showCaption="false"}
:::

:::WorkflowBlockItem
Click **+ New Application**.
:::

:::WorkflowBlockItem
Click **+ Create your own application**.
:::

:::WorkflowBlockItem
Enter a name for your app and select **Register an application to integrate with Azure AD (App your're developing)**.
:::

:::WorkflowBlockItem
Click **Create**.
:::

:::WorkflowBlockItem
Enter and select the following:

| **Field on the Register an application page** | **Required information**                                                                                                                                                                           |
| --------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Name                                          | Enter a name for your OIDC SSO app.                                                                                                                                                                |
| Supported account types                       | Select the optoin that is best for your user case.<br />For example, use **Accounts in this organizational directory** only if your application is only for internal use within your organization. |
| Redirect URI (optional)                       | Although Microsoft marks this field as optional, successful implementation with Make requires the following:<br />Select a platform - Web - https\://next.integromat.com/sso/login                 |


:::

:::WorkflowBlockItem
Click **Register**.
:::
::::

### Create your client credentials in the MS Azure portal

::::WorkflowBlock
:::WorkflowBlockItem
In the Microsoft Azure AD portal go to **Home > Enterprise applications > \{your OIDC app} > Single Sign-on** and click **Go to application**.
:::

:::WorkflowBlockItem
Under **Essentials**, find **Application (client) ID**. Copy this value and save it in a secure place. This is the required information for the **Client ID** field in your Make SSO configuration.
:::

:::WorkflowBlockItem
In the left navigation under **Manage**, click **Certificates & secrets**.
:::

:::WorkflowBlockItem
Click **+ New client secret**.
:::

:::WorkflowBlockItem
In the new dialog box, enter a short description and click **Add**.
:::

:::WorkflowBlockItem
Find the new client secret on the list. Copy the **Value** and save it in a secure place. This is the required information for the **Client secret** field in your Make SSO configuration.
:::
::::

### Configure tokens and optional claims in the MS Azure portal

::::WorkflowBlock
:::WorkflowBlockItem
In the left navigation under **Manage**, click **Token Configuration**.
:::

:::WorkflowBlockItem
Click **+ Optional claim**.
:::

:::WorkflowBlockItem
In the new dialog box, select **ID**.
:::

:::WorkflowBlockItem
A list appears. Select **Email**.
:::
::::

### Add API permissions in the MS Azure portal

::::WorkflowBlock
:::WorkflowBlockItem
In the left navigation under **Manage**, click **API Permissions**.
:::

:::WorkflowBlockItem
Click **+ Add permission**.
:::

:::WorkflowBlockItem
In the new dialog box, click **Microsoft Graph**.
:::

:::WorkflowBlockItem
Click **Application permissions**.
:::

:::WorkflowBlockItem
Use the search bar to find `User.Read.All`.
:::

:::WorkflowBlockItem
Select `User.Read.All` and click **Add permissions**.
:::
::::

### Add users to your application in the MS Azure portal

To provide access to your organization members, you need to add these users to your app in the MS Azure portal.

::::WorkflowBlock
:::WorkflowBlockItem
In the Microsoft Azure AD portal go to **Home > Enterprise applications > \{your OIDC app}**.
:::

:::WorkflowBlockItem
Click **Users and groups**.
:::

:::WorkflowBlockItem
Click **+ Add user/group** to add the users you want to access your Make organization.
:::
::::

### Update the SSO in Make

::::WorkflowBlock
:::WorkflowBlockItem
Click **Organization** in the left sidebar.
:::

:::WorkflowBlockItem
Click the **SSO** tab.
:::

:::WorkflowBlockItem
Enter the following information:

| **Field**                       | **Value**                                                                                                                                                                                                                                                                                                                               |
| ------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| User information URL            | `https://graph.microsoft.com/v1.0/me`                                                                                                                                                                                                                                                                                                   |
| Client ID                       | Enter the **Application (client) ID&#x20;**&#x79;ou copied in step 2 of [how to create your client credentials](docId\:VH6038lSPDoXXxc-U4vmg)**.**                                                                                                                                                                                      |
| Token URL                       | `https://login.microsoftonline.com/1234etc/oauth2/v2.0/token`                                                                                                                                                                                                                                                                           |
| Login scopes                    | `User.Read.All`                                                                                                                                                                                                                                                                                                                         |
| Scopes separator                | Enter a single space.                                                                                                                                                                                                                                                                                                                   |
| Authorize URL                   | To find your Authorize URL:<br />1) In the MS Azure portal, go to **Home > Enterprise applications > \{your OIDC app} > Single Sign-on&#x20;**&#x61;nd click **Go to application.**
2)  Click **Endpoints**. A window appears.
3) Find **OAuth 2.0 authorization endpoint (v1)**. Copy and paste this URL into your Make configuration. |
| Client secret                   | Enter the **Value&#x20;**&#x79;ou copied in step 6 of [how to create your client credentials](docId\:VH6038lSPDoXXxc-U4vmg)**.**                                                                                                                                                                                                        |
| User infomration IML resolve    | `{"id":"{{id}}","email":"{{mail}}","name":"{{givenName}}"}`                                                                                                                                                                                                                                                                             |
| Redirect URL                    | No action required                                                                                                                                                                                                                                                                                                                      |
| Team provisioning for new users | Select an option based on your needs.                                                                                                                                                                                                                                                                                                   |
:::

:::WorkflowBlockItem
Click **Save**.
:::
::::

:::hint{type="info"}
You will receive an email with the subject "Activation complete: SSO ready for your organization" upon successful activation. If you encounter any issues while logging in using SSO, disable SSO using the "one-time link" (valid for 24 hours).&#x20;
:::



## Service provider initiated SSO

::::WorkflowBlock
:::WorkflowBlockItem
Go to [make.com](https://make.com).&#x20;
:::

:::WorkflowBlockItem
Click **Sign in with SSO**.
:::

:::WorkflowBlockItem
Enter the namespace you chose for your organization.
:::

:::WorkflowBlockItem
Log in using your Microsoft credentials and consent to Make's access to your user data.
:::
::::

