Skip to main content

Identity providers (Entra ID)

For Owners and Operators (or an IdentityProviderManager Role) connecting the Microsoft Entra ID tenant that Studio deployments sign in through; Viewers and IdentityProviderViewers read the list. Connect once; the console then provisions sign-in for each new deployment and searches your directory to assign people.

Before you start: this is the second Entra set-up. The first, a SAML Enterprise Application for the console itself, was done at install (Sign in with Entra ID). This page is the multi-tenant application registration. Whoever clicks Connect is sent to Microsoft to grant admin consent for your tenant.

Read the list​

Open Identity & Access Management → Identity Providers. Columns are Tenant, Type ("Microsoft Entra ID"), Status (Connected, Revoked or Consent failed, with " · Secret expires in N day(s)" or " · Secret expired" appended within 30 days of expiry) and Connected.

Connect a tenant: Microsoft's side​

Click Connect identity provider. The instructions card lists what to do in the Entra admin center first:

  1. Start a new app registration: App registrations → New registration; any name.
  2. Make it multi-tenant, with this redirect URI: supported account types "Accounts in any organizational directory (Any Microsoft Entra ID tenant - Multitenant)", platform Web, and the Redirect URI shown (your console's origin followed by /org-api/identity-providers/callback). "If Entra asks which tenants may use the application, choose Allow all tenants (Entra pre-selects a restricted option)."
  3. Copy the Application (client) ID from the registration's Overview.
  4. Add the five Application permissions (Microsoft Graph, Application permissions, not Delegated): Application.ReadWrite.OwnedBy, Application.Read.All, User.Read.All, Group.Read.All, AppRoleAssignment.ReadWrite.All, then Grant admin consent.
  5. Create a client secret under Certificates & secrets and copy its Value immediately; it is shown once.

Connect a tenant: the console's side​

In Identity Provider Configuration (set up once; saving also updates the shared credential every connected tenant uses):

  1. Provider type: Microsoft Entra ID.
  2. Client ID: the Application (client) ID. A value that is not a GUID is refused.
  3. Client secret: the secret's Value. If one is already configured, leave blank to keep it. A value with spaces or line breaks is refused (usually a browser autofill).
  4. Click Connect, sign in to Microsoft and grant admin consent. Microsoft returns you to the tenant's detail page.

The tenant's display name is read from Microsoft Graph; there is nothing to type. The consent link is valid for 15 minutes. If the return fails, the list says why (consent declined, an incomplete return, credentials not configured, an expired attempt, Microsoft unreachable, tenant details unreadable) and what to do.

Read and delete a tenant​

The header shows Tenant name, Tenant ID, Status, Connected and Deployments (how many are linked). Connection is read-only; linking to a deployment happens on the deployment's Identity view or in the wizard (Deployment detail).

Delete removes AlphaAgent's record of the connection only; it does not revoke the Enterprise Apps Microsoft created in your tenant. Type the tenant name to confirm. A tenant linked to deployments cannot be deleted; unlink them first.

Manage the Platform setup credentials​

Every tenant's page carries Credentials: one Entra application credential shared by every tenant. It shows the Client ID (last four characters), Expires (the date, whether "from Microsoft" or "entered by hand", and days remaining or "expired N days ago"; "Not recorded" if unknown) and Last updated. From 30 days before expiry a warning appears; after it, single sign-on provisioning, directory search and assignments fail until the secret is updated.

To rotate the secret:

  1. Click Update credentials (needs IdentityProviderManager, or Owner or Operator).
  2. Enter the Client ID and paste the new Client secret (its Value, not its Secret ID).
  3. Optionally set Secret expiry (optional), used only if Microsoft cannot report it; secrets last at most 24 months.
  4. Click Save. The secret is verified with Microsoft before anything is replaced; a rejected secret changes nothing.

Success reads "Verified with Microsoft and saved." with the expiry recorded from Microsoft when it allows that read, otherwise from your entry. With no tenant connected yet it saves unverified and the first connection uses it. Every update is written to Audit.

What you should see​

  • A connected tenant: Connected in the list, a consent time on its page, and the tenant shown as "<tenant> (Microsoft Entra ID)" in the deployment wizard's Identity provider step, on a linked deployment's Overview and Identity view, and on unlinked deployments' Identity view.
  • A healthy credential: no suffix on Status and no warning under Credentials.

Notes​

  • Microsoft Entra ID is the only provider type.
  • Directory search or assignments failing: check Credentials for an expired secret.
  • A deployment's SSO provisioning failing with entra_credentials_unavailable is a platform credential problem for AlphaAgent; saml_auto_provisioning_failed usually clears on Resume (Failure codes).