Skip to content
PlainID
← Back to all integrations
Microsoft Entra ID logo

Microsoft Entra ID

Use Entra ID identity context and enrich its tokens to drive fine-grained access decisions.

About PlainID + Microsoft Entra ID

The integration of PlainID with Entra ID enables organizations to implement a seamless Authentication-Authorization process. Entra ID, serving as an IdP (Identity Provider), primarily manages the Authentication process using established protocols like OIDC and SAML, resulting in an authentication token. The PlainID Entra ID Authorizer complements Entra ID's authentication process by calculating and generating a dynamic list of claims and groups based on PlainID's policies. These claims and groups enhance the token generated by Entra iD, granting users the adaptive access they are entitled to.

The flow of token enrichment aims to contextually and dynamically calculate and provide a list of Authorizations (claims) to Entra ID during the login process. The result is a continuous and adaptive Authorization process that allows users access based on their evolving roles and responsibilities within an organization. The PlainID Entra ID Authorizer bridges the gap between Authentication and Authorization, offering organizations a comprehensive solution for managing user access.

Technical Information

The PlainID Entra ID Authorizer allows enriching Entra ID's JWT as part of the login process. This is done by utilizing Entra ID’s webhook to obtain the relevant claims for the authenticating user from PlainID’s PDP. The Token Enrichment functionality is supported both by the PlainID Cloud-Based PDP, and the Hybrid customer-hosted PlainID Policy Authorization Agent.

Architectures

  1. User logins to the application.
  2. The app initiates an authentication process (SSO) with the Entra ID.
  3. As part of the authentication process, Entra ID sends a request to PlainID Authorizer via a webhook interface for authorization claims.
  4. The PDP dynamically calculates the access decision.
    If needed the Policy Information Point (PIP) pulls additional user or asset attributes from various data sources to calculate the access decision. PlainID Authorizer then returns the access decisions containing claims to be used for enriching the access token minted by Entra ID.
  5. Entra ID provides the app with an access token containing the dynamically calculated access decision.

Technology

  • Identity Providers

Capabilities

  • Manage
  • Enforce

Auth Patterns

  • Token Enrichment
  • Policy information point (PIP)

Need help integrating?

Our experts can help you architect the perfect authorization strategy for your stack.

Contact Support

Better Together

Connect Context. Centralize Policy. Enforce Everywhere.