Skip to main content

Microsoft OIDC / SSO

Connecting Microsoft OIDC for user authentication

Updated over 4 months ago

Before you start

Review our general User (Admin & Employee) Authentication documentation for more details.

Set up

1. Navigate to the Settings -> Authentication section of your Adaptive Admin account.

2. Select the '+ Add Option' button in the section specific to which Adaptive app you want to set the authentication for (Admin portal or Employee Training App). Select Microsoft and click 'Add Option' in the bottom right corner of the modal.

3. Microsoft OIDC doesn't require configuration / setup in Azure, so after selecting this option the log in flow will begin to show Microsoft to users after they enter their email.

Testing

  1. From the login page, select 'Continue with Microsoft'

    1. Depending on your Microsoft setup, when you log in for the first time you may see an option to “consent on behalf of your organization" -- please make sure to check this option before continuing

  2. You will be taken to the Adaptive training application

All employees for you company will now be able to use the Microsoft OIDC / SSO option to log in.

Additionally, it's best practice to log out of your session on https://admin.adaptivesecurity.com/ and log back in using the 'Continue with Microsoft' option to ensure things are functioning as expected on both Adaptive applications.

Troubleshooting

If an admin did not check “consent on behalf of your organization" when setting up their Microsoft SSO the first time, employees will not be able to log in. The best way to solve this is to just delete and reinstall the Adaptive SSO app. Instructions below:

  • As an admin, sign into https://portal.azure.com/

  • In the top search search bar, type Entra

  • In the left sidebar of the Entra menu, go to Manage > Enterprise Applications

  • Click on the app titled: Adaptive User SSO [PROD]

  • In the left sidebar, go to Manage > Properties

  • In the top bar, click Delete

  • Finally, go to this link, log in as an admin, and check the “consent on behalf of your organization" box when prompted

Also note that the email address the admin uses to log in to Microsoft also has to be an admin in the Adaptive platform.

Did this answer your question?