Prompt
I’m building an internal tool and need Microsoft Entra ID sign-in
Latest observation
Oct 6, 2026
OpenAI APIWeb search: off
To add Microsoft Entra ID (Azure AD) sign-in to an internal tool, the usual path is:
- Register an app in Entra ID
- Add authentication to your app
- Handle sign-in tokens / session
- Restrict access to your org/users/groups if needed
Quick approach
If your app is:
- Web app: use OpenID Connect
- Single-page app (SPA): use MSAL.js
- Backend/API: validate JWT access tokens
- Desktop/mobile: use the relevant MSAL library
Setup in Microsoft Entra ID
- Go to Microsoft Entra admin center
- Navigate to Identity > Applications > App registrations
- Click New registration
- Set:
- Name
- Supported account types: usually Single tenant for internal tools
- Redirect URI:
- Web app:
https://yourapp.com/auth/callback - Local dev:
http://localhost:3000/auth/callbackor similar
- Web app:
- Save and note:
- Application (client) ID
- Directory (tenant) ID
Then:
- Go to Authentication
- Enable the appropriate platform
- For web apps, add redirect URIs
- For SPA, configure CORS / auth settings as needed
- Go to Certificates & secrets
- Create a client secret if your app is a server-side web app
- Prefer certificates for production if possible
- Go to API permissions
- Add Microsoft Graph permissions if you need user profile/group info
- Grant admin consent if required
Recommended auth flow
For a server-side web app
Use OpenID Connect Authorization Code Flow.
Typical flow:
- User clicks Sign in
- Redirect to Microsoft login
- Microsoft returns an authorization code
- Your backend exchanges code for tokens
- Store session on your app side
For SPA
Use Authorization Code Flow with PKCE via MSAL.js.
Example: Microsoft identity platform endpoints
Tenant-specific authority:
https://login.microsoftonline.com/<tenant-id>/v2.0
Authorize endpoint:
https://login.microsoftonline.com/<tenant-id>/oauth2/v2.0/authorize
Token endpoint:
https://login.microsoftonline.com/<tenant-id>/oauth2/v2.0/token
Important security notes
- Use single-tenant if this is only for your org
- Validate:
- issuer
- audience
- signature
- token lifetime
- Use HTTPS
- Don’t put client secrets in frontend code
- If you need role-based access, consider:
- App roles
- Group claims
- app-side authorization checks
If you want a library suggestion
Tell me your stack and I can give a copy-paste setup for:
- Node.js / Express
- Python / Django / Flask
- ASP.NET Core
- React / Next.js
- Vue
- Java / Spring
- Go
If you want, I can also give you a step-by-step Entra app registration + code example for your exact stack.