# Azure AD (Entra)

> Part of the NocoDB documentation (Product docs > Account & Billing > Authentication ☁ > OpenID Connect). Index of all pages: https://nocodb.com/llms.txt. Any docs page is available as Markdown by adding `.md` to its URL.

URL: https://nocodb.com/docs/product/account-settings/authentication/oidc-sso/azure-ad
Last updated: 2026-10-03

Configure Azure AD as an OIDC identity provider for NocoDB SSO.

This page gives the steps to configure Azure AD as the Identity service provider for NocoDB.

### NocoDB, Retrieve `Redirect URL`

1. Go to `Account Settings`.
2. Select `Authentication (SSO)`.
3. Click the `New Provider` button. A popup modal opens.
4. In the popup modal, specify a `Display name` for the provider. The login page shows the provider with this name.
5. Copy the `Redirect URL`. You configure it later in the Identity Provider.

<img alt="OIDC SSO Configuration" src={__img0} placeholder="blur" />
<img alt="OIDC SSO Configuration" src={__img1} placeholder="blur" />
<img alt="OIDC SSO Configuration" src={__img2} placeholder="blur" />

### Azure AD, Configure NocoDB as an Application

1. Sign in to your [Azure account](https://portal.azure.com/#allservices). Below `Azure Services`, go to `Azure Active Directory`.
2. In the navigation bar, open `Manage Tenants`. Select your directory, and click `Switch`.
3. On the homepage of your directory, in the navigation bar, click `+ Add` > `App Registration`.
4. On the `Register an application` page:
   * Type the name of your application.
   * Set the `Supported account types` to `Accounts in this organizational directory only`.
   * Select `Web` as the Application type.
   * Below `Redirect URIs`, add the `Redirect URL`.
   * Click `Register`.
5. On the homepage of your application:
   * Copy the `Application (client) ID`.
   * In the `Client credentials` section, click `Add a certificate or secret`.
   * On the `Certificates & secrets` page, go to the `Client secrets` section.
   * Click `New client secret`.
   * On the `Add a client secret` page:
     * Add a description for the secret.
     * Set the expiration that you need.
     * Click `Add`.
   * Copy the `Value` of the new secret.
6. On the homepage of your application:
   * Go to the `Endpoints` tab.
   * Open the `OpenID Connect metadata document` URL. From the JSON response, copy `authorization_endpoint`, `token_endpoint`, `userinfo_endpoint` and `jwks_uri`.
7. Configure the scopes:
   * Go to the `API permissions` tab.
   * Click `Add a permission`.
   * On the `Request API permissions` page:
     * From `Microsoft APIs`, select `Microsoft Graph`.
     * Select `Delegated permissions`.
     * From the `Select permissions` dropdown, select `openid` `profile` `email` `offline_access`.
     * From the `Users` dropdown, select `User.Read`.
     * Click `Add permissions`.
   * On the `API permissions` page, click `Grant admin consent for this directory`.

### NocoDB, Configure Azure AD as an Identity Provider

In NocoDB, open `Account Settings` > `Authentication` > `OIDC`. The "Register OIDC Identity Provider" modal opens. Enter this information:

| NocoDB field        | Value                                             |
| ------------------- | ------------------------------------------------- |
| `Client ID`         | The `Application (client) ID` from step (7) above |
| `Client Secret`     | The `Value` of the new secret from step (7) above |
| `Authorization URL` | The `authorization_endpoint` from step (8) above  |
| `Token URL`         | The `token_endpoint` from step (8) above          |
| `Userinfo URL`      | The `userinfo_endpoint` from step (8) above       |
| `JWK Set URL`       | The `jwks_uri` from step (8) above                |
| `Scope`             | `openid` `profile` `email` `offline_access`       |

The sign-in page now shows the `Sign in with <SSO>` option to users.

<img alt="SAML SSO Configuration" src={__img3} placeholder="blur" />

<Callout type="info">
  Post sign-out, refresh page (for the first time) if you do not see `Sign in with SSO` option
</Callout>

<Callout type="info">
  For more common questions and troubleshooting, see our 

  [SSO FAQ](/docs/product/account-settings/authentication/FAQs)

  .
</Callout>

For information about Azure AD API Scopes, refer [here](https://learn.microsoft.com/en-us/azure/active-directory/develop/v2-permissions-and-consent#offline_access).

## Availability

* OIDC SSO is available on **NocoDB Cloud** (Business plan and above) and on licensed self-hosted deployments (Business plan and above). For access, reach [**out to sales**](https://cal.com/nocodb/sales).
* For users on the **Business plan**, the SSO configuration menu is in the workspace sidebar, at **Settings** > **Single Sign-On (SSO)**. For more information, refer [here](/docs/product/account-settings/authentication#business-plan).
* **Domain Verification Required for Cloud Plans**: Before you configure OIDC SSO, you must verify your domain in NocoDB. This is necessary for both Business and Enterprise plans in the cloud. Only users with email addresses from verified domains can sign in through SSO. For more information, refer to [Domain Verification](/docs/product/account-settings/authentication#domain-verification).

---

## Related pages

- [Okta](https://nocodb.com/docs/product/account-settings/authentication/oidc-sso/okta.md): Configure Okta as an OIDC identity provider for NocoDB SSO.
- [Auth0](https://nocodb.com/docs/product/account-settings/authentication/oidc-sso/auth0.md): Configure Auth0 as an OIDC identity provider for NocoDB SSO.
- [Ping Identity](https://nocodb.com/docs/product/account-settings/authentication/oidc-sso/ping-identity.md): Configure Ping Identity as an OIDC identity provider for NocoDB.
