Skip to main content

Configure single sign-on with Microsoft Entra ID

Set up a Microsoft Entra ID app registration so your team can sign in to Nudge Security with their Microsoft credentials.

Written by Velizar Demirev

This guide walks you through creating an app registration in Microsoft Entra ID (formerly Azure Active Directory) so your team can sign in to Nudge Security with their Microsoft credentials using OpenID Connect (OIDC).

When you're done, you'll send three values to Nudge Security. We'll finish the configuration on our side and let you know when SSO is ready to test.

This is separate from the Microsoft Entra ID integration. If you connected Entra ID to Nudge for app discovery and analysis, that uses a different app. You'll create a new, dedicated app registration for sign-in. For the discovery integration, see Configure access to Microsoft Entra ID.

Before you begin

You'll need:

  • An account in your Entra tenant with one of these roles: Application Administrator, Cloud Application Administrator, or Global Administrator

  • About 10–15 minutes

  • A secure way to share a secret with Nudge Security, such as a password manager share link (see Step 5)

You'll collect these values along the way:

Value

Where to find it

Sensitive?

Directory (tenant) ID

App registration → Overview

No

Application (client) ID

App registration → Overview

No

Client secret value

App registration → Certificates & secrets (shown only once)

Yes—treat it like a password

Step 1: Create the app registration

  1. Go to App registrations. If you don't see it in the left navigation, search for App registrations in the top search bar.

  2. Select + New registration.

  3. Complete the form:

    • Name: Nudge Security. Your users may see this name on the Microsoft sign-in consent screen.

    • Supported account types: Accounts in this organizational directory only (Single tenant)

    • Redirect URI: Select Web from the platform list, then paste this URI exactly:

https://oidc-auth.nudgesecurity.io/oauth2/idpresponse

Finally, Select Register.

The redirect URI must match exactly—including https://, the lowercase path, and no trailing slash. A mismatch is the most common cause of failed sign-ins.

Reusing an existing app registration? Open it, select Authentication, and confirm a Web platform exists with the redirect URI above. If it doesn't, select + Add a platform → Web, paste the URI, and select Configure. Leave Implicit grant and hybrid flows unchecked and Allow public client flows set to No.

Step 2: Add API permissions

Nudge Security requests only the standard OIDC scopes—openid, profile, and email—to identify who's signing in and read their name and email address. Nudge doesn't access any other data.

  1. In your app registration, select API permissions.

  2. Select + Add a permission → Microsoft Graph → Delegated permissions.

  3. Under OpenId permissions, select email, openid, and profile.

  4. Select Add permissions.

  5. Optional: Entra adds User.Read to new registrations by default. Nudge doesn't use it, so you can remove it by selecting ⋯ on its row → Remove permission. Leaving it is harmless.

  6. Recommended: Select Grant admin consent for [your organization] and confirm. This keeps your users from seeing a consent prompt the first time they sign in.

The Configured permissions table should now list email, openid, and profile under Microsoft Graph.

Step 3: Create a client secret

  1. In your app registration, select Certificates & secrets.

  2. On the Client secrets tab, select + New client secret.

  3. Enter a description, such as Nudge Security SSO.

  4. Choose an expiration that fits your credential rotation policy. Note the expiry date—SSO stops working when the secret expires (see Rotate your client secret below).

  5. Select Add.

  6. Copy the value in the Value column right away. Microsoft shows it in full only once. Don't copy the Secret ID—that's not the secret.

⚠️ If you leave the page before copying the value, delete the secret and create a new one.

Step 4: Copy your tenant ID and client ID

  1. In your app registration, select Overview.

  2. In the Essentials section, copy the Application (client) ID and the Directory (tenant) ID.

Both are GUIDs that look like 12345678-abcd-1234-abcd-1234567890ab.

Step 5: Send the values to Nudge Security

Email help@nudgesecurity.com with your tenant ID and client ID, and let us know how you'll share the client secret.

Never send the client secret in plain email or chat. Share it through a secure channel, like a 1Password or other password manager share link.

We'll configure SSO on our side, confirm when it's ready, and send you a sign-in link to test. Once you're satisfied, we'll turn on SSO for your organization.

Sign in with Microsoft

When your SSO setup is complete, you can sign in to Nudge Security with your Microsoft account:

  1. Select the option to sign in with Microsoft.

  2. Sign in with your Microsoft work account when prompted.

Optional: Restrict who can sign in

By default, anyone in your tenant can authenticate through the app registration. They still need a Nudge Security account to get in. To limit sign-in to specific users or groups:

  1. In the Entra admin center, go to Enterprise applications and open Nudge Security. Entra creates it automatically with your app registration.

  2. Select Properties, set Assignment required? to Yes, and select Save.

  3. Select Users and groups → + Add user/group, then assign the users or groups who should have access.

Rotate your client secret

Before your secret expires, create a new one (Step 3) and send the new value to Nudge Security the same way. Keep the old secret active until we confirm the switch, then delete it.

Troubleshooting

Error

Likely cause

Fix

AADSTS50011: redirect URI doesn't match

Typo in the redirect URI, or wrong platform type

Confirm a Web platform with the exact URI in Step 1

AADSTS700016: application not found in directory

Wrong client ID or tenant ID sent to Nudge

Recopy both values from Overview (Step 4)

AADSTS7000215: invalid client secret

Secret ID sent instead of the value, or the secret expired

Create a new secret (Step 3) and send the Value

AADSTS65001 or "Need admin approval"

Admin consent not granted

Complete Step 2, item 6

AADSTS50105: user isn't assigned to a role

Assignment is required, but the user isn't assigned

Assign the user or a group they belong to

Sign-in succeeds in Microsoft, but you can't get into Nudge

No Nudge Security account for that user

Ask a Nudge admin to add you (see Manage users and roles)

Did this answer your question?