Skip to main content
See All Integrations

Microsoft Entra ID

Use Microsoft Entra ID as the identity provider for Pomerium through OpenID Connect.

First-party Pomerium integration guide

Category
Identity Providers

Overview

Microsoft Entra ID is a cloud identity and access management service. It was formerly called Azure Active Directory. Pomerium has a named provider guide for Microsoft Entra ID and continues to use azure as the provider key.

Using Microsoft Entra ID as the identity provider gives protected applications one sign-in path. Each application does not need to implement the same external authentication flow. Pomerium can apply route policy from the authenticated identity and request context.

Microsoft Entra ID sends authenticated identity data toward Pomerium. Pomerium uses that data with route policy. Pomerium then sends only approved application traffic toward the protected service.

How it works

Register a web application in Microsoft Entra ID. Add the exact Pomerium redirect URI, create a client credential, and configure the Microsoft identity platform v2 issuer. Add only the claims and Microsoft Graph permissions that the deployment needs.

Configure Pomerium with the exact issuer or provider URL, client ID, and client secret. Use the Pomerium callback URL as an exact redirect URI. Request only the scopes and claims that access policy needs.

Test discovery, signing-key rotation, the authorization code flow, logout, and required claim mappings before production use. Keep provider credentials outside source control.

Example

A team registers Pomerium as an OpenID Connect client in Microsoft Entra ID. Users sign in through Microsoft Entra ID. Pomerium validates the identity response and applies route policy before it sends an approved request to a private application.

Considerations

  • Group claims contain IDs, not group names. Large memberships can use an overage response that needs separate handling.
  • Some Microsoft Entra ID accounts do not include an email claim. Directory sync and Microsoft Graph access are separate Enterprise concerns.
  • Microsoft Entra ID remains responsible for authentication, user lifecycle, and the identity data that it issues.
  • A standards-based OpenID Connect pattern is not evidence of a vendor-specific connector or partnership.

Sources and official resources

  • Azure Active Directory is now Microsoft Entra ID. Use the current Pomerium integration guide while keeping azure as the provider configuration key.

  • Use JumpCloud as the identity provider for Pomerium through OpenID Connect.

  • Use Duo Single Sign-On as the identity provider for Pomerium through OpenID Connect.

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo