Prompt
I need login with Microsoft for B2B customers
Latest observation
To support “Login with Microsoft” for B2B customers, you usually want to use Microsoft Entra ID (Azure AD) as an identity provider, not the consumer Microsoft account flow.
Typical setup
1) Create an app registration
In Microsoft Entra admin center:
- Go to App registrations
- Register your app
- Add your app’s redirect URI
- Configure client secret or certificate if needed
2) Use OpenID Connect / OAuth 2.0
For sign-in, use:
- Authorization Code Flow with PKCE for web/mobile apps
- OpenID Connect for authentication
3) Allow B2B users
B2B customers can sign in if:
- Their organization uses Microsoft Entra ID
- They are invited as guest users to your tenant, or you configure multi-tenant sign-in
- They authenticate with their work account
4) Multi-tenant vs single-tenant
- Single-tenant: only users from your Entra tenant can sign in
- Multi-tenant: users from other Microsoft organizations can sign in
- For B2B scenarios, multi-tenant is commonly used
Authority / endpoints
You’ll usually use one of these authorities:
-
Single tenant
https://login.microsoftonline.com/{tenant-id}/v2.0 -
Multi-tenant
https://login.microsoftonline.com/organizations/v2.0 -
Common
https://login.microsoftonline.com/common/v2.0
(supports work/school accounts and, depending on configuration, broader account types)
For B2B work accounts, organizations is often the safest choice.
Recommended claims to request
Use scopes like:
openidprofileemailoffline_accessif you need refresh tokens- API scopes if your app calls your backend
Important B2B note
If your customers are external organizations, you may need:
- Tenant restrictions
- Cross-tenant access settings
- Or an invitation flow for guest users
Example sign-in URL pattern
https://login.microsoftonline.com/organizations/oauth2/v2.0/authorize
With parameters like:
client_idresponse_type=coderedirect_uriscope=openid profile emailstatenonce
If you want, I can give you:
- a step-by-step Microsoft Entra setup, or
- code examples for ASP.NET / Node.js / React / Python.