Prompt
How do I let users sign in with Microsoft on my website?
Latest observation
To let users sign in with Microsoft on your website, you typically use Microsoft Entra ID / Microsoft identity platform with OpenID Connect (OIDC) or OAuth 2.0.
Typical approach
- Register your app in the Microsoft Entra admin portal.
- Configure a redirect URI for your website.
- Use Microsoft’s sign-in endpoint to send users to Microsoft login.
- Handle the callback on your server after login.
- Validate the ID token and create your own session.
1) Register the application
Go to the Microsoft Entra admin center:
Create an App registration:
- Choose a name
- Select supported account types:
- Single tenant: only your org
- Multitenant: any Entra ID account
- Personal Microsoft accounts: if you want Outlook/Hotmail/MSN users too
- Add a Redirect URI like:
https://yourdomain.com/auth/microsoft/callback
You’ll get:
- Client ID
- Tenant ID (if relevant)
If your app is a server-side web app, also create a:
- Client secret
2) Send users to Microsoft login
Use the authorization endpoint:
https://login.microsoftonline.com/{tenant}/oauth2/v2.0/authorize
Common {tenant} values:
common= work/school + personal Microsoft accountsorganizations= work/school accounts onlyconsumers= personal Microsoft accounts only- or your specific tenant ID
Example URL:
https://login.microsoftonline.com/common/oauth2/v2.0/authorize?
client_id=YOUR_CLIENT_ID&
response_type=code&
redirect_uri=https%3A%2F%2Fyourdomain.com%2Fauth%2Fmicrosoft%2Fcallback&
response_mode=query&
scope=openid%20profile%20email%20offline_access&
state=RANDOM_CSRF_TOKEN
Important scopes:
openid= required for sign-inprofile= basic profile infoemail= email address when availableoffline_access= if you need refresh tokens
3) Handle the callback
After login, Microsoft redirects back with a code.
Your server exchanges it for tokens at:
https://login.microsoftonline.com/{tenant}/oauth2/v2.0/token
You’ll send:
client_idclient_secretcoderedirect_urigrant_type=authorization_code
Then you’ll receive:
- id_token: confirms the user’s identity
- access_token: for calling Microsoft APIs
- optionally refresh_token
4) Validate the sign-in
On your backend:
- verify the ID token signature
- verify issuer, audience, expiration
- check the
statevalue to prevent CSRF
Then create your own app session/cookie for the signed-in user.
5) Use a library instead of hand-rolling it
Recommended libraries:
Node.js
- msal-node
- Or Passport with OpenID Connect strategy
Python
- msal
- Authlib
ASP.NET Core
- Built-in Microsoft authentication middleware
PHP / Ruby / Java
- Use an OIDC client library
Example: ASP.NET Core
This is one of the easiest stacks for Microsoft login.
builder.Services.AddAuthentication(OpenIdConnectDefaults.AuthenticationScheme)
.AddMicrosoftIdentityWebApp(builder.Configuration.GetSection("AzureAd"));
Then configure:
"AzureAd": {
"Instance": "https://login.microsoftonline.com/",
"TenantId": "common",
"ClientId": "YOUR_CLIENT_ID",
"ClientSecret": "YOUR_CLIENT_SECRET",
"CallbackPath": "/signin-oidc"
}
If you only want “Sign in with Microsoft” for users
Use OIDC sign-in.
If you also need to access Microsoft APIs
Use OAuth 2.0 scopes like:
- Microsoft Graph:
User.Read - Mail/calendar permissions if needed
Security tips
- Always use HTTPS
- Use and validate state
- Use PKCE for public clients/SPAs
- Never expose a client secret in frontend code
- Prefer MSAL libraries when possible
If you want, I can give you:
- a step-by-step setup for your exact stack, or
- a working code example in Node.js, Python, PHP, or ASP.NET Core.
If you tell me your backend/frontend tech, I’ll tailor it.