PageSourceSearch

https://docs.curri.com/assets/js/644e0065.c1096656.js

js curri.com collected 2026-09-24 10:26:36 UTC 21,424 bytes, 1 lines download raw bytes

1"use strict";(self.webpackChunk_curri_docs=self.webpackChunk_curri_docs||[]).push([[7227],{9840:(e,i,n)=>{n.r(i),n.d(i,{assets:()=>c,contentTitle:()=>d,default:()=>h,frontMatter:()=>o,metadata:()=>r,toc:()=>l});const r=JSON.parse('{"id":"sso/microsoft-entra-id","title":"Microsoft Entra ID (Azure AD)","description":"This guide walks IT and identity administrators through configuring Single Sign-On (SSO) between Microsoft Entra ID (formerly Azure AD) and Curri.","source":"@site/docs/sso/00-microsoft-entra-id.md","sourceDirName":"sso","slug":"/sso/microsoft-entra-id","permalink":"/docs/sso/microsoft-entra-id","draft":false,"unlisted":true,"tags":[],"version":"current","sidebarPosition":0,"frontMatter":{"title":"Microsoft Entra ID (Azure AD)","hide_title":true,"unlisted":true}}');var t=n(678),s=n(9787);const o={title:"Microsoft Entra ID (Azure AD)",hide_title:!0,unlisted:!0},d="Connecting Curri to Microsoft Entra ID (Azure AD)",c={},l=[{value:"How the integration works",id:"how-the-integration-works",level:2},{value:"Step 1: Register the application",id:"step-1-register-the-application",level:2},{value:"Step 2: Create a client secret",id:"step-2-create-a-client-secret",level:2},{value:"Step 3: API permissions",id:"step-3-api-permissions",level:2},{value:"Token claims",id:"token-claims",level:3},{value:"Step 4: User assignment (optional)",id:"step-4-user-assignment-optional",level:2},{value:"What to send Curri",id:"what-to-send-curri",level:2},{value:"Rollout",id:"rollout",level:2},{value:"Troubleshooting",id:"troubleshooting",level:2},{value:"Reference",id:"reference",level:2}];function a(e){const i={a:"a",admonition:"admonition",code:"code",h1:"h1",h2:"h2",h3:"h3",header:"header",li:"li",ol:"ol",p:"p",strong:"strong",table:"table",tbody:"tbody",td:"td",th:"th",thead:"thead",tr:"tr",ul:"ul",...(0,s.R)(),...e.components};return(0,t.jsxs)(t.Fragment,{children:[(0,t.jsx)(i.header,{children:(0,t.jsx)(i.h1,{id:"connecting-curri-to-microsoft-entra-id-azure-ad",children:"Connecting Curri to Microsoft Entra ID (Azure AD)"})}),"\n",(0,t.jsx)(i.p,{children:"This guide walks IT and identity administrators through configuring Single Sign-On (SSO) between Microsoft Entra ID (formerly Azure AD) and Curri."}),"\n",(0,t.jsxs)(i.p,{children:["Setup takes approximately 15 minutes in the Microsoft Entra admin center. Once you submit your application details using the ",(0,t.jsx)(i.a,{href:"#what-to-send-curri",children:"checklist"}),", Curri will complete the configuration and coordinate testing."]}),"\n",(0,t.jsx)(i.h2,{id:"how-the-integration-works",children:"How the integration works"}),"\n",(0,t.jsxs)(i.p,{children:["Curri uses ",(0,t.jsx)(i.strong,{children:"OpenID Connect (OIDC)"})," with the OAuth 2.0 authorization code flow. When a user enters a work email address associated with your organization at ",(0,t.jsx)(i.code,{children:"https://app.curri.com/login"}),", Curri redirects them to your Entra ID tenant to authenticate. Upon successful sign-in, Entra returns a signed ID token, Curri validates the signature against your tenant's published JSON Web Key Set (JWKS), and the user is authenticated."]}),"\n",(0,t.jsx)(i.p,{children:"Key integration characteristics:"}),"\n",(0,t.jsxs)(i.ul,{children:["\n",(0,t.jsxs)(i.li,{children:[(0,t.jsx)(i.strong,{children:"Standard OpenID Connect:"})," Curri follows standard OIDC specifications without proprietary extensions or custom client software."]}),"\n",(0,t.jsxs)(i.li,{children:[(0,t.jsx)(i.strong,{children:"Token-based identity:"})," User identity is established directly from the signed ID token. Only standard delegated Microsoft Graph permissions (",(0,t.jsx)(i.code,{children:"User.Read"}),") are requested for basic profile details; no directory-wide read permissions are required."]}),"\n",(0,t.jsxs)(i.li,{children:[(0,t.jsx)(i.strong,{children:"Just-in-Time (JIT) provisioning:"})," When a user signs in via Entra ID for the first time, Curri automatically provisions their account keyed to their email address. If an account already exists with that email, it is automatically linked."]}),"\n",(0,t.jsxs)(i.li,{children:[(0,t.jsx)(i.strong,{children:"No directory sync:"})," Curri does not synchronize directory objects or use SCIM. Disabling a user in Entra ID prevents new sign-ins through Microsoft SSO. It does not end a Curri session that is already active, and it does not block password sign-in if that remains enabled for your domains (see ",(0,t.jsx)(i.a,{href:"#rollout",children:"Rollout"}),")."]}),"\n",(0,t.jsxs)(i.li,{children:[(0,t.jsx)(i.strong,{children:"Tenant-governed security policies:"})," Multi-Factor Authentication (MFA), Conditional Access, device compliance, and session lifetimes are enforced entirely by your Entra ID tenant."]}),"\n",(0,t.jsxs)(i.li,{children:[(0,t.jsx)(i.strong,{children:"Single Logout (SLO):"})," Curri does not support Single Logout. Signing out of Curri does not end the user's Microsoft session, and signing out of Microsoft does not terminate an active 
1Curri session."]}),"\n"]}),"\n",(0,t.jsx)(i.h2,{id:"step-1-register-the-application",children:"Step 1: Register the application"}),"\n",(0,t.jsxs)(i.p,{children:["In the Microsoft Entra admin center, navigate to ",(0,t.jsx)(i.strong,{children:"Identity \u2192 Applications \u2192 App registrations"})," and select ",(0,t.jsx)(i.strong,{children:"New registration"}),"."]}),"\n",(0,t.jsxs)(i.table,{children:[(0,t.jsx)(i.thead,{children:(0,t.jsxs)(i.tr,{children:[(0,t.jsx)(i.th,{children:"Field"}),(0,t.jsx)(i.th,{children:"Value"})]})}),(0,t.jsxs)(i.tbody,{children:[(0,t.jsxs)(i.tr,{children:[(0,t.jsx)(i.td,{children:"Name"}),(0,t.jsxs)(i.td,{children:[(0,t.jsx)(i.code,{children:"Curri"})," (or your preferred display name)"]})]}),(0,t.jsxs)(i.tr,{children:[(0,t.jsx)(i.td,{children:"Supported account types"}),(0,t.jsxs)(i.td,{children:[(0,t.jsx)(i.strong,{children:"Accounts in this organizational directory only"})," (Single tenant)"]})]}),(0,t.jsxs)(i.tr,{children:[(0,t.jsx)(i.td,{children:"Redirect URI platform"}),(0,t.jsx)(i.td,{children:(0,t.jsx)(i.strong,{children:"Web"})})]}),(0,t.jsxs)(i.tr,{children:[(0,t.jsx)(i.td,{children:"Redirect URI"}),(0,t.jsx)(i.td,{children:(0,t.jsx)(i.code,{children:"https://app.curri.com/api/auth/callback/<company>"})})]})]})]}),"\n",(0,t.jsxs)(i.p,{children:["The redirect URI is assigned by Curri and is unique to your organization. Be sure to use the exact value provided by Curri; any discrepancy in casing or an extra trailing slash will fail with ",(0,t.jsx)(i.code,{children:"AADSTS50011"}),"."]}),"\n",(0,t.jsx)(i.h2,{id:"step-2-create-a-client-secret",children:"Step 2: Create a client secret"}),"\n",(0,t.jsxs)(i.p,{children:["Under your new application registration, navigate to ",(0,t.jsx)(i.strong,{children:"Certificates & secrets \u2192 Client secrets \u2192 New client secret"}),"."]}),"\n",(0,t.jsxs)(i.ul,{children:["\n",(0,t.jsxs)(i.li,{children:["Add a description (e.g., ",(0,t.jsx)(i.code,{children:"Curri SSO"}),") and select the longest expiration period permitted by your organization's policy. Curri requires the updated secret whenever it rotates; an expired secret will immediately prevent user sign-ins until replaced."]}),"\n",(0,t.jsxs)(i.li,{children:["Copy the secret ",(0,t.jsx)(i.strong,{children:"Value"})," immediately upon creation. It is only displayed once. (Do not copy the ",(0,t.jsx)(i.strong,{children:"Secret ID"}),"; Curri requires the secret ",(0,t.jsx)(i.strong,{children:"Value"}),")."]}),"\n",(0,t.jsxs)(i.li,{children:["Record the ",(0,t.jsx)(i.strong,{children:"expiration date"})," and include it when submitting credentials to Curri so both teams can plan the rotation."]}),"\n"]}),"\n",(0,t.jsx)(i.admonition,{type:"note",children:(0,t.jsx)(i.p,{children:"Curri currently does not support certificate-based credentials for this integration."})}),"\n",(0,t.jsx)(i.h2,{id:"step-3-api-permissions",children:"Step 3: API permissions"}),"\n",(0,t.jsxs)(i.p,{children:["Under ",(0,t.jsx)(i.strong,{children:"API permissions"}),", verify that the registration includes the following delegated permissions:"]}),"\n",(0,t.jsxs)(i.table,{children:[(0,t.jsx)(i.thead,{children:(0,t.jsxs)(i.tr,{children:[(0,t.jsx)(i.th,{children:"API"}),(0,t.jsx)(i.th,{children:"Permission"}),(0,t.jsx)(i.th,{children:"Type"})]})}),(0,t.jsxs)(i.tbody,{children:[(0,t.jsxs)(i.tr,{children:[(0,t.jsx)(i.td,{children:"Microsoft Graph"}),(0,t.jsx)(i.td,{children:(0,t.jsx)(i.code,{children:"openid"})}),(0,t.jsx)(i.td,{children:"Delegated"})]}),(0,t.jsxs)(i.tr,{children:[(0,t.jsx)(i.td,{children:"Microsoft Graph"}),(0,t.jsx)(i.td,{children:(0,t.jsx)(i.code,{children:"profile"})}),(0,t.jsx)(i.td,{children:"Delegated"})]}),(0,t.jsxs)(i.tr,{children:[(0,t.jsx)(i.td,{children:"Microsoft Graph"}),(0,t.jsx)(i.td,{children:(0,t.jsx)(i.code,{children:"email"})}),(0,t.jsx)(i.td,{children:"Delegated"})]}),(0,t.jsxs)(i.tr,{children:[(0,t.jsx)(i.td,{children:"Microsoft Graph"}),(0,t.jsx)(i.td,{children:(0,t.jsx)(i.code,{children:"User.Read"})}),(0,t.jsx)(i.td,{children:"Delegated"})]})]})]}),"\n",(0,t.jsxs)(i.p,{children:["Entra ID assigns ",(0,t.jsx)(i.co
1de,{children:"User.Read"})," (Delegated) by default to new application registrations, which is sufficient for basic profile retrieval. If your organization requires admin consent for delegated permissions or you wish to prevent individual user consent prompts, click ",(0,t.jsx)(i.strong,{children:"Grant admin consent for [your organization]"}),"."]}),"\n",(0,t.jsx)(i.p,{children:"Curri does not request application permissions and does not access any data beyond the signing-in user's basic profile."}),"\n",(0,t.jsx)(i.h3,{id:"token-claims",children:"Token claims"}),"\n",(0,t.jsx)(i.p,{children:"Curri reads only standard claims present in every default Entra ID token:"}),"\n",(0,t.jsxs)(i.ul,{children:["\n",(0,t.jsxs)(i.li,{children:[(0,t.jsx)(i.code,{children:"email"})," (or ",(0,t.jsx)(i.code,{children:"preferred_username"})," when formatted as an email)"]}),"\n",(0,t.jsxs)(i.li,{children:[(0,t.jsx)(i.code,{children:"oid"})," (user Object ID)"]}),"\n",(0,t.jsxs)(i.li,{children:[(0,t.jsx)(i.code,{children:"tid"})," (tenant Directory ID)"]}),"\n",(0,t.jsxs)(i.li,{children:[(0,t.jsx)(i.code,{children:"ver"})," (token version)"]}),"\n"]}),"\n",(0,t.jsxs)(i.p,{children:[(0,t.jsx)(i.code,{children:"given_name"})," and ",(0,t.jsx)(i.code,{children:"family_name"})," are used, when present, to prefill the profile form on first sign-in. Nothing else is read: no group claims, roles, or custom or extension attributes."]}),"\n",(0,t.jsxs)(i.p,{children:[(0,t.jsx)(i.strong,{children:"Do not add optional claims, custom claims, or a claims-mapping policy to this application."})," Curri needs none of them, and a claims-mapping policy on the service principal without a matching application-specific signing key causes Entra ID to reject every sign-in with ",(0,t.jsx)(i.code,{children:"AADSTS50146"}),". If your tenant applies a claims-mapping policy to new enterprise applications by default, remove it from the Curri service principal."]}),"\n",(0,t.jsx)(i.h2,{id:"step-4-user-assignment-optional",children:"Step 4: User assignment (optional)"}),"\n",(0,t.jsxs)(i.p,{children:["Under ",(0,t.jsx)(i.strong,{children:"Identity \u2192 Applications \u2192 Enterprise applications \u2192 Curri \u2192 Properties"}),", configure ",(0,t.jsx)(i.strong,{children:"Assignment required?"}),":"]}),"\n",(0,t.jsxs)(i.ul,{children:["\n",(0,t.jsxs)(i.li,{children:[(0,t.jsx)(i.strong,{children:"Yes (Recommended for staged rollout):"})," Only users or security groups explicitly assigned under ",(0,t.jsx)(i.strong,{children:"Users and groups"})," can sign in."]}),"\n",(0,t.jsxs)(i.li,{children:[(0,t.jsx)(i.strong,{children:"No:"})," Any active user in your directory can sign in."]}),"\n"]}),"\n",(0,t.jsxs)(i.p,{children:["If assignment is required, unassigned users attempting to sign in will receive error ",(0,t.jsx)(i.code,{children:"AADSTS50105"})," on Microsoft's sign-in page."]}),"\n",(0,t.jsx)(i.h2,{id:"what-to-send-curri",children:"What to send Curri"}),"\n",(0,t.jsx)(i.p,{children:"Send the following details to your Curri onboarding contact over a secure channel. To protect your tenant credentials, avoid transmitting client secrets over plaintext email."}),"\n",(0,t.jsxs)(i.table,{children:[(0,t.jsx)(i.thead,{children:(0,t.jsxs)(i.tr,{children:[(0,t.jsx)(i.th,{children:"Item"}),(0,t.jsx)(i.th,{children:"Description"}),(0,t.jsx)(i.th,{children:"Where to find it"})]})}),(0,t.jsxs)(i.tbody,{children:[(0,t.jsxs)(i.tr,{children:[(0,t.jsx)(i.td,{children:(0,t.jsx)(i.strong,{children:"Application (Client) ID"})}),(0,t.jsx)(i.td,{children:"Application GUID"}),(0,t.jsx)(i.td,{children:"App registrations \u2192 Curri \u2192 Overview"})]}),(0,t.jsxs)(i.tr,{children:[(0,t.jsx)(i.td,{children:(0,t.jsx)(i.strong,{children:"Directory (Tenant) ID"})}),(0,t.jsx)(i.td,{children:"Directory GUID"}),(0,t.jsx)(i.td,{children:"App registrations \u2192 Curri \u2192 Overview"})]}),(0,t.jsxs)(i.tr,{children:[(0,t.jsx)(i.td,{children:(0,t.jsx)(i.strong,{children:"Client Secret Value"})}),(0,t.jsx)(i.td,{children:"The secret string copied in Step 2"}),(0,t.jsx)(i.td,{children:"Certificates & secrets (Value column)"})]}),(0,t.jsxs)(i.tr,{children:[(0,t.jsx)(i.td,{children:(0,t.jsx)(i.strong,{children:"Client Secret Expiration"})}),(0,t.jsx)(i.td,{children:"Expiration date of the secret"}),(0,t.jsx)(i.td,{children:"Certificates & secrets"})]}),(0,t.jsxs)(i.tr,{children:[(0,t.jsx)(i.td,{children:(0,t.jsx)(i.strong,{children:"Corporate Email Domains"})}),(0,t.jsxs)(i.td,{children:["All email domains your users sign in with (e.g., ",(0,t.jsx)(i.co
1de,{children:"example.com"}),", ",(0,t.jsx)(i.code,{children:"contractor.example.com"}),"). Curri routes sign-in by domain, so users on an unlisted domain are not offered Microsoft SSO."]}),(0,t.jsx)(i.td,{children:"\u2014"})]}),(0,t.jsxs)(i.tr,{children:[(0,t.jsx)(i.td,{children:(0,t.jsx)(i.strong,{children:"Designated Test Users"})}),(0,t.jsx)(i.td,{children:"Email addresses of 1\u20132 test users"}),(0,t.jsx)(i.td,{children:"Internal team"})]})]})]}),"\n",(0,t.jsx)(i.h2,{id:"rollout",children:"Rollout"}),"\n",(0,t.jsx)(i.p,{children:"During onboarding, Curri can maintain standard email-and-password sign-in alongside Microsoft SSO for your organization. Once your test users confirm that SSO operates as expected, let Curri know your rollout preference:"}),"\n",(0,t.jsxs)(i.ol,{children:["\n",(0,t.jsxs)(i.li,{children:[(0,t.jsx)(i.strong,{children:"Dual authentication:"})," Users may sign in using either Microsoft SSO or their existing password."]}),"\n",(0,t.jsxs)(i.li,{children:[(0,t.jsx)(i.strong,{children:"Enforce SSO only:"})," Password authentication is disabled for your domains, requiring all users to authenticate through Microsoft Entra ID."]}),"\n"]}),"\n",(0,t.jsx)(i.admonition,{type:"note",children:(0,t.jsx)(i.p,{children:"Curri will only enable SSO-only mode after at least one successful Microsoft sign-in has been verified for your tenant."})}),"\n",(0,t.jsx)(i.h2,{id:"troubleshooting",children:"Troubleshooting"}),"\n",(0,t.jsxs)(i.p,{children:["If a sign-in fails after the user authenticates with Microsoft, Curri's login screen displays the diagnostic details returned by Entra ID: the ",(0,t.jsx)(i.code,{children:"AADSTS"})," error code, error description, ",(0,t.jsx)(i.strong,{children:"Correlation ID"}),", ",(0,t.jsx)(i.strong,{children:"Trace ID"}),", and timestamp."]}),"\n",(0,t.jsxs)(i.p,{children:["When requesting support from Curri, please provide these details. You can also search the ",(0,t.jsx)(i.strong,{children:"Correlation ID"})," directly in ",(0,t.jsx)(i.strong,{children:"Microsoft Entra ID \u2192 Monitoring \u2192 Sign-in logs"})," to inspect your tenant's detailed audit logs."]}),"\n",(0,t.jsxs)(i.table,{children:[(0,t.jsx)(i.thead,{children:(0,t.jsxs)(i.tr,{children:[(0,t.jsx)(i.th,{children:"Code"}),(0,t.jsx)(i.th,{children:"Meaning"}),(0,t.jsx)(i.th,{children:"Recommended Resolution"})]})}),(0,t.jsxs)(i.tbody,{children:[(0,t.jsxs)(i.tr,{children:[(0,t.jsx)(i.td,{children:(0,t.jsx)(i.code,{children:"AADSTS50011"})}),(0,t.jsx)(i.td,{children:"Reply URL mismatch"}),(0,t.jsx)(i.td,{children:"The redirect URI configured in Entra ID does not match the URI provided by Curri. Verify casing and ensure there are no trailing slashes."})]}),(0,t.jsxs)(i.tr,{children:[(0,t.jsx)(i.td,{children:(0,t.jsx)(i.code,{children:"AADSTS700016"})}),(0,t.jsx)(i.td,{children:"Application not found in directory"}),(0,t.jsx)(i.td,{children:"The Application (Client) ID or Directory (Tenant) ID sent to Curri is incorrect, or the application was created in a different tenant."})]}),(0,t.jsxs)(i.tr,{children:[(0,t.jsx)(i.td,{children:(0,t.jsx)(i.code,{children:"AADSTS7000215"})}),(0,t.jsx)(i.td,{children:"Invalid client secret"}),(0,t.jsx)(i.td,{children:"The client secret value provided to Curri is incorrect, or the Secret ID was submitted instead of the secret Value."})]}),(0,t.jsxs)(i.tr,{children:[(0,t.jsx)(i.td,{children:(0,t.jsx)(i.code,{children:"AADSTS7000222"})}),(0,t.jsx)(i.td,{children:"Client secret expired"}),(0,t.jsx)(i.td,{children:"The client secret has expired. Generate a new secret in Entra ID and securely provide the updated Value to Curri."})]}),(0,t.jsxs)(i.tr,{children:[(0,t.jsx)(i.td,{children:(0,t.jsx)(i.code,{children:"AADSTS65001"})}),(0,t.jsx)(i.td,{children:"Consent required"}),(0,t.jsx)(i.td,{children:"Grant admin consent for the requested delegated permissions in Step 3."})]}),(0,t.jsxs)(i.tr,{children:[(0,t.jsx)(i.td,{children:(0,t.jsx)(i.code,{children:"AADSTS50105"})}),(0,t.jsx)(i.td,{children:"User not assigned"}),(0,t.jsxs)(i.td,{children:["Assign the user or group in ",(0,t.jsx)(i.strong,{children:"Enterprise applications \u2192 Curri \u2192 Users and groups"}),", or set ",(0,t.jsx)(i.strong,{children:"Assignment required?"})," to ",(0,t.jsx)(i.strong,{children:"No"}),"."]})]}),(0,t.jsxs)(i.tr,{children:[(0,t.jsx)(i.td,{children:(0,t.jsx)(i.co
1de,{children:"AADSTS53003"})}),(0,t.jsx)(i.td,{children:"Blocked by Conditional Access"}),(0,t.jsx)(i.td,{children:"A tenant Conditional Access policy prevented sign-in. Review your Entra sign-in logs to identify which policy was evaluated."})]}),(0,t.jsxs)(i.tr,{children:[(0,t.jsx)(i.td,{children:(0,t.jsx)(i.code,{children:"AADSTS50146"})}),(0,t.jsx)(i.td,{children:"Missing custom signing key"}),(0,t.jsx)(i.td,{children:"A claims-mapping policy is assigned to the Curri service principal without an application-specific signing key. Remove the policy from the enterprise application."})]}),(0,t.jsxs)(i.tr,{children:[(0,t.jsx)(i.td,{children:(0,t.jsx)(i.code,{children:"AADSTS90002"})}),(0,t.jsx)(i.td,{children:"Tenant not found"}),(0,t.jsx)(i.td,{children:"The tenant ID Curri has on file for your organization is incorrect. Contact Curri; this is corrected on our side."})]})]})]}),"\n",(0,t.jsx)(i.p,{children:"If a user enters their email address and is prompted for a password instead of being redirected to Microsoft, either their email domain has not yet been registered with Curri or the integration is awaiting activation."}),"\n",(0,t.jsx)(i.h2,{id:"reference",children:"Reference"}),"\n",(0,t.jsxs)(i.table,{children:[(0,t.jsx)(i.thead,{children:(0,t.jsxs)(i.tr,{children:[(0,t.jsx)(i.th,{children:"Property"}),(0,t.jsx)(i.th,{children:"Details"})]})}),(0,t.jsxs)(i.tbody,{children:[(0,t.jsxs)(i.tr,{children:[(0,t.jsx)(i.td,{children:"Sign-in URL"}),(0,t.jsx)(i.td,{children:(0,t.jsx)(i.code,{children:"https://app.curri.com/login"})})]}),(0,t.jsxs)(i.tr,{children:[(0,t.jsx)(i.td,{children:"Redirect URI"}),(0,t.jsx)(i.td,{children:(0,t.jsx)(i.code,{children:"https://app.curri.com/api/auth/callback/<company>"})})]}),(0,t.jsxs)(i.tr,{children:[(0,t.jsx)(i.td,{children:"Protocol"}),(0,t.jsx)(i.td,{children:"OpenID Connect (OIDC), OAuth 2.0 Authorization Code Flow (Confidential Client)"})]}),(0,t.jsxs)(i.tr,{children:[(0,t.jsx)(i.td,{children:"Requested Scopes"}),(0,t.jsx)(i.td,{children:(0,t.jsx)(i.code,{children:"openid profile email User.Read"})})]}),(0,t.jsxs)(i.tr,{children:[(0,t.jsx)(i.td,{children:"Token Validation"}),(0,t.jsx)(i.td,{children:"ID token signature validated against tenant JWKS via OpenID Connect discovery; issuer verified"})]}),(0,t.jsxs)(i.tr,{children:[(0,t.jsx)(i.td,{children:"User Provisioning"}),(0,t.jsx)(i.td,{children:"Just-in-Time (JIT) provisioning on first sign-in, keyed to email address"})]}),(0,t.jsxs)(i.tr,{children:[(0,t.jsx)(i.td,{children:"Single Logout (SLO)"}),(0,t.jsx)(i.td,{children:"Not supported"})]}),(0,t.jsxs)(i.tr,{children:[(0,t.jsx)(i.td,{children:"Microsoft Reference"}),(0,t.jsx)(i.td,{children:(0,t.jsx)(i.a,{href:"https://learn.microsoft.com/en-us/entra/identity-platform/v2-oauth2-auth-code-flow",children:"OAuth 2.0 authorization code flow"})})]})]})]})]})}function h(e={}){const{wrapper:i}={...(0,s.R)(),...e.components};return i?(0,t.jsx)(i,{...e,children:(0,t.jsx)(a,{...e})}):a(e)}},9787:(e,i,n)=>{n.d(i,{R:()=>o,x:()=>d});var r=n(6166);const t={},s=r.createContext(t);function o(e){const i=r.useContext(s);return r.useMemo(function(){return"function"==typeof e?e(i):{...i,...e}},[i,e])}function d(e){let i;return i=e.disableParentContext?"function"==typeof e.components?e.components(t):e.components||t:o(e.components),r.createElement(s.Provider,{value:i},e.children)}}}]);

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.