Entra ID
Overview
Your tenant can be configured to allow users to authenticate using their corporate Microsoft Entra ID credentials. This page will walk you through the configuration process.
Create an Authorization Source
Create App Registration
- Log in to your Microsoft Entra admin portal.
- From the left menu, click App registrations
- From the top menu, Click + New registration
- Create a Name for your application (e.g. KorGrid SSO)
- Supported Account types, select Single tenant only
- Redirect URI, select Web
- Enter the URL for your UI login (e.g., https://contoso.west1.korgrid.com)
- Click Register

Create Client Secret
- From the left menu of the app registration you just created, click Certificates & secrets
- From the top menu, Click + New client secret
- Enter a Description (e.g. KorGrid Secret)
- Expires, select your desired expiration date
- Click Add

Save the following information from Microsoft Entra:
- Tenant ID
- Overview -> Basic Information -> Tenant ID
- Client ID
- App registrations -> All applications -> KorGrid SSO -> Application (client) ID
- Client Secret
- App registrations -> All applications -> KorGrid SSO -> Certificates & secrets -> Client secrets -> KorGrid Secret -> Value
Configure UI
- From the Top Menu, click System -> Auth Sources
- From the left menu, click New
- Enter a Name for the source (e.g. Entra ID). This name will appear on the sign-in button on the login page
- In the Driver field, select Entra ID
- Enter the Tenant ID obtained from the previous section
- The Redirect URI should be the URL of your management UI (e.g. https://contoso.west1.korgrid.com)
- Enter Endpoint URL for user to logout session token
- Set to None to disable redirecting for logout.
- Otherwise, set to the Entra logout URL (e.g. https://login.microsoft.com/<tenant-id>/oauth2/v2.0/logout)
- Scope should typically be left at the default value. (openid profile email)
- Group Scope should be set to groups if you wish to auto-create users based on group membership.
- Enter the Client ID obtained from the previous section
- Enter the Client Secret obtained from the previous section
- Remote User Fields defines the list of fields used to initially find the Entra ID user. This field is auto populated with (sub,preferred_username,email nickname). This default list is typically sufficient for most implementations.
- To carry over group membership from Entra ID to KorGrid, check the Update Group Membership checkbox. Groups can be created manually using instructions in the next section.
User Auto-Creation Features (optional):
Users can be auto created upon initial login to the UI. This can be enabled for all Entra ID users or limited to users in a specified Microsoft 365 group.
- Auto-Create Users - If all users should be auto-created, enter *.
- Auto-Create Users in Group - To only auto-create users that are members of a specified group enter the groups Object ID.
- Microsoft 365 groups must first be created in the UI prior to users being auto created.
- Multiple group object ID's can be entered using the format: (ObjectID)|(ObjectID)|(ObjectID)
Options (recommended):
- Update Remote User - once the user is located in Entra ID, update the KorGrid user Remote Username field to the corresponding Entra unique ID.
Enabling the Update Remote User option will allow the system to store the user's unique object ID in the UI's user record so the unique identifier can subsequently be used for finding the Entra ID user; this is typically recommended since fields such as email address can sometimes change.
- Update User Email Address - Update user email address to match email address within Entra ID.
- Update User Display Name - Update user display name to match display name within Entra ID.
- Update Group Membership - Update the groups that a user is a member of. (A Group Scope is required for this to function.)

Add Microsoft 365 Groups to UI
Interfacing with Microsoft 365 groups requires a token on the Entra ID app registration and creation of groups within the UI.
Set up a Token Configuration in Entra ID
- Navigate to the App registration page for the application created in the previous section
- Click on Token Configuration on the left menu
- Click + Add groups claim
- Select all the group types boxes
- Set the ID, Access, and SAML tokens properties to sAMAccountName
- Click Add

Add Microsoft 365 Groups
- From the UI's Main Dashboard, click System from the left menu
- From the left menu, click Groups
- From the left menu, click New
- Enter the group Name to match the group name from Microsoft 365
- (Optional), You can specify an Email for the group. This email address will be used for sending subscription alerts and/or reports assigned to the group.
- Set the Identifier to the Object ID of the Microsoft 365 group
- Click Submit
Manually Add Users from Entra ID
- From the Top Menu, click System -> Users
- From the left menu, click New
- Authorization Source - Select Entra ID as the source from the dropdown list.
- Username - unique name; typically recommended to use the Entra ID user principal name.
- Remote Username - recommended to use the user's Entra ID object ID.
- Display Name - (optional) If Update User Display Name is enabled on the Entra ID auth source, the display name will automatically synchronize from Entra ID.
- Email Address - (optional) If Update User Email Address is enabled on the Entra ID auth source, the email address will automatically synchronize from Entra ID.
- Click Submit