Azure AD (Entra)

This page gives the steps to configure Azure AD as the Identity service provider for NocoDB.

NocoDB, Retrieve Redirect URL

  1. Go to Account Settings.
  2. Select Authentication (SSO).
  3. Click the New Provider button. A popup modal opens.
  4. In the popup modal, specify a Display name for the provider. The login page shows the provider with this name.
  5. Copy the Redirect URL. You configure it later in the Identity Provider.

OIDC SSO Configuration OIDC SSO Configuration OIDC SSO Configuration

Azure AD, Configure NocoDB as an Application

  1. Sign in to your Azure account. Below Azure Services, go to Azure Active Directory.
  2. In the navigation bar, open Manage Tenants. Select your directory, and click Switch.
  3. On the homepage of your directory, in the navigation bar, click + Add > App Registration.
  4. On the Register an application page:
    • Type the name of your application.
    • Set the Supported account types to Accounts in this organizational directory only.
    • Select Web as the Application type.
    • Below Redirect URIs, add the Redirect URL.
    • Click Register.
  5. On the homepage of your application:
    • Copy the Application (client) ID.
    • In the Client credentials section, click Add a certificate or secret.
    • On the Certificates & secrets page, go to the Client secrets section.
    • Click New client secret.
    • On the Add a client secret page:
      • Add a description for the secret.
      • Set the expiration that you need.
      • Click Add.
    • Copy the Value of the new secret.
  6. On the homepage of your application:
    • Go to the Endpoints tab.
    • Open the OpenID Connect metadata document URL. From the JSON response, copy authorization_endpoint, token_endpoint, userinfo_endpoint and jwks_uri.
  7. Configure the scopes:
    • Go to the API permissions tab.
    • Click Add a permission.
    • On the Request API permissions page:
      • From Microsoft APIs, select Microsoft Graph.
      • Select Delegated permissions.
      • From the Select permissions dropdown, select openid profile email offline_access.
      • From the Users dropdown, select User.Read.
      • Click Add permissions.
    • On the API permissions page, click Grant admin consent for this directory.

NocoDB, Configure Azure AD as an Identity Provider

In NocoDB, open Account Settings > Authentication > OIDC. The "Register OIDC Identity Provider" modal opens. Enter this information:

NocoDB fieldValue
Client IDThe Application (client) ID from step (7) above
Client SecretThe Value of the new secret from step (7) above
Authorization URLThe authorization_endpoint from step (8) above
Token URLThe token_endpoint from step (8) above
Userinfo URLThe userinfo_endpoint from step (8) above
JWK Set URLThe jwks_uri from step (8) above
Scopeopenid profile email offline_access

The sign-in page now shows the Sign in with <SSO> option to users.

SAML SSO Configuration

Post sign-out, refresh page (for the first time) if you do not see Sign in with SSO option

For more common questions and troubleshooting, see our SSO FAQ.

For information about Azure AD API Scopes, refer here.

Availability

  • OIDC SSO is available on NocoDB Cloud (Business plan and above) and on licensed self-hosted deployments (Business plan and above). For access, reach out to sales.
  • For users on the Business plan, the SSO configuration menu is in the workspace sidebar, at Settings > Single Sign-On (SSO). For more information, refer here.
  • Domain Verification Required for Cloud Plans: Before you configure OIDC SSO, you must verify your domain in NocoDB. This is necessary for both Business and Enterprise plans in the cloud. Only users with email addresses from verified domains can sign in through SSO. For more information, refer to Domain Verification.

Last updated on

Latest product updates?See Changelog
Stay in the loop? Follow us onLinkedInLinkedInYouTubeYouTubeXX