Microsoft Entra ID sign-in
With Microsoft Entra ID sign-in, people click Sign in with Microsoft on the portal, sign in at Microsoft with their usual work account and any multi-factor checks your organisation requires, and arrive in the portal as their own Active Directory account. This page explains what you need and walks through the setup in Microsoft Entra and in the console.
What it does New in 2.1
- The portal sign-in page shows a Sign in with Microsoft button, or sends people straight to Microsoft if you choose.
- Microsoft confirms who the person is. Their Entra ID account policies, including conditional access and multi-factor authentication, apply at that point.
- DartRelay asks Microsoft which on-premises Active Directory account the person is synchronised from, checks that account in your domain, and signs them in as that domain account.
- From then on everything works exactly as for a password sign-in: their Active Directory groups decide what they see, and seats, addresses and auto-launch rules all apply as usual.
Microsoft sign-in applies to the portal. Administrators sign in to the console with their username and password as before.
Before you begin
- Hybrid accounts. Your users must be synchronised from on-premises Active Directory to Entra ID (for example with Microsoft Entra Connect Sync). A cloud-only Entra account has no Windows account to map to, and is refused with a message saying it is not linked to a Windows account.
- Domain Users switched on in Authentication → Authentication Methods.
- The users' domain on the Directories list. The on-premises domain the accounts come from must be on Authentication → Directories, enabled, and offered on the address people use. See Active Directory and multiple domains.
- A portal address on HTTPS that people's browsers can reach. Microsoft sends them back to this address after sign-in. See Endpoints and certificates.
- Rights in Entra. You need an Entra account that can register applications and grant admin consent.
Where it lives in the console
Microsoft Entra ID sign-in is set up as a pass on Authentication → Relay Pass. That page lists every way people can sign in with an outside provider, in the order their buttons appear on the sign-in page, with ▲ and ▼ to reorder them. Each Microsoft Entra ID pass has its own detail page with these cards:
- How to register DartRelay with Microsoft, including the redirect address and a Copy button.
- Connect: the pass's name, the tenant ID, the client ID and the client secret.
- Match to a Windows account: for Entra, this is always the synchronised on-premises account.
- Sign-in page: the button text, whether the button is on, and whether to send people straight to Microsoft.
- Windows logon: whether to log people on to hosts with a certificate instead of a password. This is covered on Relay Pass.
You can add more than one Microsoft Entra ID pass, for example one for each of two Entra tenants. Each gets its own button.
Step 1: register DartRelay in Microsoft Entra
First add a pass in DartRelay so you can copy its redirect address, then register the application at Microsoft.
- Add the pass. In the console, go to Authentication → Relay Pass and add a Microsoft Entra ID pass. Its detail page opens.
- Copy the redirect address. The registration card shows the redirect address for the address you are using the console on, ending in
/portal/signin-entra(further Entra passes end in/portal/signin-entra/followed by the pass's short name). Click Copy. If people reach the portal on a different address, use that address instead; it must match exactly. - Open App registrations. In the Microsoft Entra admin centre, go to Identity → Applications → App registrations and choose New registration.
- Name it and choose who may use it. Enter a name such as DartRelay. Under supported account types choose Accounts in this organizational directory only (single tenant).
- Add the redirect address. Under Redirect URI, choose the platform Web and paste the address you copied. Click Register.
- Note the two IDs. On the application's Overview page, copy the Application (client) ID and the Directory (tenant) ID.
- Create a client secret. Go to Certificates & secrets → Client secrets → New client secret, give it a description and an expiry, and click Add. Copy the secret's Value straight away; Microsoft shows it only once.
- Check the permission and grant consent. Go to API permissions. The Microsoft Graph delegated permission User.Read is normally present already; add it if it is not. Click Grant admin consent for your organisation so users are not asked to consent one by one.
DartRelay needs only User.Read. It uses it to read the signed-in person's own profile, which includes the on-premises account name, domain and security identifier that Entra Connect synchronised. No other directory data is read.
Client secrets expire. Put the expiry date in your calendar and create a new secret, then paste it into the pass, before the old one runs out.
Step 2: connect the pass
- Return to the pass's detail page under Authentication → Relay Pass.
- Fill in the Connect card. Enter a name (people will not see it unless you leave the button text empty), the Directory (tenant) ID, the Application (client) ID and the client secret value.
- Fill in the Sign-in page card. Set the button text if you want something other than the default, make sure the button is enabled, and decide whether to send people straight to Microsoft (see below).
- Save.
- Click Test sign-in on the Test card. It asks Microsoft for a token with the saved tenant, client ID and secret, which proves the three belong together. Fix any error it reports before going on.
- Try it. Open the portal sign-in page in a private browser window, click the Microsoft button and sign in as a synchronised user. You should land on My Resources with that person's resources.
| Field | What it does | Default |
|---|---|---|
| Name / short name | Identify the pass in the console. The short name forms part of the redirect address for second and later Entra passes. | — |
| Tenant ID | Your Entra tenant's Directory (tenant) ID. It must be your own tenant; the shared values common, organizations and consumers are refused. | — |
| Client ID | The Application (client) ID of the registration. | — |
| Client secret | The secret value. Stored encrypted and never shown again; leave the box empty to keep the saved secret. | — |
| Button text | The words on the sign-in button. | Sign in with Microsoft |
| Enabled | Shows or hides this pass's button and allows or refuses its sign-ins. | On |
| Send people straight to Microsoft | Opening the sign-in page goes directly to Microsoft. Only one pass can have this; turning it on for one turns it off for the others. | Off |
Sending people straight to Microsoft
With this on, people who open the portal are taken to Microsoft without seeing DartRelay's sign-in page. Staff who need the ordinary username and password form can add ?signin=1 to the sign-in address. The form is also shown when there is an error to display, and for a few minutes after somebody signs out, so signing out does not silently sign them straight back in.
The button in your theme
Shipped themes show the Microsoft button under the Sign in button of the sign-in block, at the same width. In your own themes the sign-in block has a setting to show or hide it and to change its label. See Building the sign-in and home pages.
Choosing which buttons appear on each address New in 2.1
If you serve several organisations on different addresses, each can show a different set of sign-in buttons. Go to Appearance → Tenancy & Branding, open the address, choose Access, and use Sign-in buttons on this address.
| Setting | Choices | Default |
|---|---|---|
| Which passes | Every pass whose button is on, or Only these with a tick box for each pass. With none ticked, the address shows only the password form. | Every pass whose button is on |
| Send people straight to a sign-in | As each pass says, Never, or a particular pass that this address offers. | As each pass says |
An address can narrow the list, never widen it: a pass whose button is off on the Relay Pass page never appears. This is enforced, not just hidden: a bookmark to a pass the address does not offer returns to the sign-in page with "Microsoft sign-in is not available".
How a Microsoft account is matched to a Windows account
After Microsoft confirms the person, DartRelay reads the on-premises account name, domain and security identifier that Entra Connect synchronised for them, and then:
- finds that domain on the Directories list among the domains offered on this address;
- looks the account up in your Active Directory and checks that it exists, is enabled, and has the same name and security identifier;
- applies the address's sign-in rules, as for any sign-in;
- signs the person in as
DOMAIN\name.
Checking Active Directory, not only what Entra says, means an account that has been disabled on-premises but not yet synchronised is still refused.
Launching resources after a Microsoft sign-in
DartRelay never sees the person's password when they sign in with Microsoft. That matters for how they are logged on to hosts:
- Resources with Fixed Credentials work exactly as usual.
- Resources with Pass-Through need the person's Windows logon. By default the portal asks for their Windows password once, in a small prompt, the first time they launch such a resource; later launches in the same sign-in do not ask again.
- With Relay Pass certificate logon switched on for the pass, there is no prompt at all: DartRelay logs the person on with a short-lived certificate. See Relay Pass.
In a pool of several DartRelay servers, the Windows password given at the prompt is held on the server that asked for it. A launch handled by another server may ask once more.
Signing out
Signing out of the portal ends the DartRelay session. It does not sign the person out of Microsoft, in the same way as most web applications that use Microsoft sign-in. On a shared computer, people should also sign out of their Microsoft account or close the browser.
If something goes wrong
| Message or problem | Cause and fix |
|---|---|
| Test sign-in fails. | The tenant ID, client ID and secret do not belong together, or the secret has expired. Copy them again from the app registration and create a new secret if needed. |
| Microsoft shows an error about the redirect URI. | The redirect address registered in Entra does not exactly match the address the person is using. Add the exact address (including https:// and the path) under Authentication in the app registration. |
| "Not linked to a Windows account." | The person is a cloud-only Entra user. Only accounts synchronised from on-premises Active Directory can sign in this way. |
| Refused because the domain is not available. | The account's on-premises domain is not on Authentication → Directories, is disabled, or is not offered on this address. |
| Refused because the account is disabled or does not match. | The account is disabled in Active Directory, or Entra holds out-of-date details for it. Check the account and let Entra Connect synchronise. |
| "Microsoft sign-in is not available." | The pass is switched off, or this address does not offer it. Check the pass's Enabled setting and the address's Sign-in buttons on this address card. |
| The button does not appear. | The pass is disabled or incomplete, Domain Users is off, the address does not offer the pass, or your theme's sign-in block hides the Microsoft button. |
| Pass-Through resources keep asking for the Windows password. | Expected without Relay Pass. It asks once per sign-in (and once per server in a pool). Switch on certificate logon for the pass to remove the prompt. |
Every Microsoft sign-in, successful or refused, is written to System → Audit Log with the reason.
Related pages
Relay Pass
Log on to hosts with a certificate, with no password prompt.
OpenID Connect
Okta, Google and other sign-in providers.
Active Directory
The Directories list every Microsoft sign-in is matched against.
Tenancy & Branding
Per-address sign-in settings.
