# Azure AD (Entra)

> Part of the NocoDB documentation (Product docs > Account & Billing > Authentication ☁ > OpenID Connect). Index of all pages: https://nocodb.com/llms.txt. Any docs page is available as Markdown by adding `.md` to its URL.

URL: https://nocodb.com/docs/product/account-settings/authentication/oidc-sso/azure-ad
Last updated: 2026-09-25

Learn how to configure Azure AD as an identity provider for NocoDB.

This article briefs about the steps to configure Azure AD as Identity service provider for NocoDB

### NocoDB, Retrieve `Redirect URL`

1. Go to `Account Settings`
2. Select `Authentication (SSO)`
3. Click on `New Provider` button
4. On the Popup modal, Specify a `Display name` for the provider; note that, this name will be used to display the provider on the login page
5. Retrieve `Redirect URL`; this information will be required to be configured later with the Identity Provider

<img alt="OIDC SSO Configuration" src={__img0} placeholder="blur" />
<img alt="OIDC SSO Configuration" src={__img1} placeholder="blur" />
<img alt="OIDC SSO Configuration" src={__img2} placeholder="blur" />

### Azure AD, Configure NocoDB as an Application

1. Sign in to your [Azure account](https://portal.azure.com/#allservices) and navigate to `Azure Active Directory` under `Azure Services`.
2. Access `Manage Tenants` from the navigation bar, select your directory, and click `Switch`.
3. On your directory's homepage, click `+ Add` > `App Registration` from the navigation bar.
4. On the `Register an application` page,
   * Provide your application's name.
   * Set `Accounts in this organizational directory only` as the `Supported account types`.
   * Choose `Web` as the Application type
   * Add the `Redirect URL` under `Redirect URIs`.
   * `Register`
5. On your application's homepage,
   * Copy the `Application (client) ID`
   * Click `Add a certificate or secret` under `Client credentials` section
   * On `Certificates & secrets` page, go to `Client secrets` section
   * Click `New client secret`
   * On `Add a client secret` page,
     * Add a description for the secret
     * Set expiration as required
     * `Add`
   * Copy the `Value` of the newly created secret
6. On your application's homepage,
   * Go to `Endpoints` tab
   * Open `OpenID Connect metadata document` URL & copy `authorization_endpoint`, `token_endpoint`, `userinfo_endpoint` & `jwks_uri` from the JSON response
7. Configuring scopes
   * Go to `API permissions` tab
   * Click `Add a permission`
   * On `Request API permissions` page,
     * Select `Microsoft Graph` from `Microsoft APIs`
     * Select `Delegated permissions`
     * Select `openid` `profile` `email` `offline_access` from `Select permissions` dropdown
     * From `Users` dropdown, select `User.Read`
     * `Add permissions`
   * Click `Grant admin consent for this directory` from the `API permissions` page

### NocoDB, Configure Azure AD as an Identity Provider

On NocoDB, open `Account Settings` > `Authentication` > `OIDC`. On the "Register OIDC Identity Provider" modal, insert the following information:

* Insert `Application (client) ID` retrieved in step (7) above as `Client ID`
* Insert `Value` of the newly created secret retrieved in step (7) above as `Client Secret`
* Insert `authorization_endpoint` retrieved in step (8) above as `Authorization URL`
* Insert `token_endpoint` retrieved in step (8) above as `Token URL`
* Insert `userinfo_endpoint` retrieved in step (8) above as `Userinfo URL`
* Insert `jwks_uri` retrieved in step (8) above as `JWK Set URL`
* Set `Scope` as `openid` `profile` `email` `offline_access`

For Sign-in's, user should be able to now see `Sign in with <SSO>` option.

<img alt="SAML SSO Configuration" src={__img3} placeholder="blur" />

<Callout type="info">
  Post sign-out, refresh page (for the first time) if you do not see `Sign in with SSO` option
</Callout>

<Callout type="info">
  For more common questions and troubleshooting, see our 

  [SSO FAQ](/docs/product/account-settings/authentication/FAQs)

  .
</Callout>

For information about Azure AD API Scopes, refer [here](https://learn.microsoft.com/en-us/azure/active-directory/develop/v2-permissions-and-consent#offline_access)

## Availability

* OIDC SSO is available on **NocoDB Cloud** (Business plan and above) and licensed self-hosted deployments (Business plan and above). For access, please reach [**out to sales**](https://cal.com/nocodb/sales).
* For users on **Business plan**, the SSO configuration menu is available under **Settings** > **Single Sign-On (SSO)** in the workspace sidebar. Refer [here](/docs/product/account-settings/authentication#business-plan) for more details.
* **Domain Verification Required for Cloud Plans**: Before configuring OIDC SSO, you must verify your domain in NocoDB (required for both Business and Enterprise plans in the cloud). Only users with email addresses from verified domains can sign in via SSO. See [Domain Verification](/docs/product/account-settings/authentication#domain-verification) for details.

---

## Related pages

- [Okta](https://nocodb.com/docs/product/account-settings/authentication/oidc-sso/okta.md): Learn how to configure Okta as an identity provider for NocoDB.
- [Auth0](https://nocodb.com/docs/product/account-settings/authentication/oidc-sso/auth0.md): Learn how to configure Auth0 as an identity provider for NocoDB.
- [Ping Identity](https://nocodb.com/docs/product/account-settings/authentication/oidc-sso/ping-identity.md): Learn how to configure Ping Identity as an identity provider for NocoDB.
