Product

Microsoft Entra External ID

Track documentation and Message Center changes for Microsoft Entra External ID.

Microsoft Learn documentation ↗

Latest Microsoft Entra External ID changes

Add OIDC for customer sign-in

Standards

Learn how to set up OpenID Connect as an external identity provider in Microsoft Entra External ID, enabling users to sign in using their existing accounts.

Gsa Poc Internet Access

Architecture

1. [Set up tenant restrictions v2](/azure/active-directory/external-identities/tenant-restrictions-v2). If your organization currently uses tenant restrictions v1, review the [guide for migrating to tenant restrictions v2](https://aka.ms/trv2migration).

Sms Voice Retirement

Fundamentals

Passkey support for B2B users and internal guest users is planned to be available by the end of calendar year 2026. These users are included in the scope of the retirement of Microsoft-provided SMS and voice authentication.

Licensing Guest Users

General

Global Secure Access external user access licensing is supported through Microsoft Entra External ID subscription linking. The administrator must link the subscription in the resource tenant so guest users can access private resources and usage is billed corr…

Troubleshoot

Troubleshooting

Organizations that are deploying passkeys and have Conditional Access policies that require phishing-resistant authentication when accessing **All resources (formerly 'All cloud apps')** can run into a looping issue when users attempt to add a passkey to Micr…

Deployment External Operations

Architecture

Learn about edge protection, domains, subscriptions, consumer app security, and fraud tactics in security operations for Microsoft Entra External ID.

Choose Authentication Approach

Fundamentals

Compare browser-delegated and native authentication in Microsoft Entra External ID and choose the right approach for your customer-facing app.

Direct Federation

Standards

Set up direct federation with SAML 2.0 or WS-Fed identity providers so users can sign in with work accounts. Understand attributes and claims for federation.

Sign in with alias

Authentication

Learn how to sign in and sign up with alias/username with External ID for customer identity and access management (CIAM). Get detailed steps to enable username as a sign-in identifier and create users with both email address and username.

Tenant Configurations

General

Learn about tenant configurations in Microsoft Entra External ID, including the differences between workforce and external tenants.

Add Member To Group

Fundamentals

Now that you've added app groups claim in your application, add users to the security groups. If you don't have security group, [create one](~/fundamentals/how-to-manage-groups.md#create-a-basic-group-and-add-members).

External ID Pricing

General

Learn about the pricing and billing structure for Microsoft Entra External ID, along with steps for linking an external tenant to an Azure subscription.

Faq Customers

Authentication

Microsoft Entra External ID pricing is based on monthly active users (MAU), which is the count of unique users with authentication activity within a calendar month. External ID consists of a core offer and premium add-ons. The Microsoft Entra External ID core…

Direct Federation

Standards

1. On the **New SAML/WS-Fed IdP** page, enter the following:

Authentication Methods Customers

Fundamentals

With Microsoft Entra External ID, you can create secure, customized sign-in experiences for your consumer- and business customer-facing apps. In an external tenant, there are several ways for users to sign up for your app. They can create an account using the…

Custom Extensions

Fundamentals

Microsoft Entra External ID user flows are designed for flexibility. Within a sign-up and sign-in user flow, there are built-in authentication events. You can also add custom authentication extensions at specific points within the authentication flow. A custo…

Frequently asked questions

General

Find answers to frequently asked questions about Microsoft Entra External ID. Learn about pricing, features, and the future of Azure AD B2C and External Identities.

Multifactor Authentication Customers

Fundamentals

Enforcing MFA enhances your organization's security by adding an extra layer of verification, making it more difficult for unauthorized users to gain access.

Planning Your Solution

Fundamentals

Discover the steps for setting up a customer identity and access management (CIAM) solution in an external tenant, including creating a tenant, registering apps, and setting up user flows for sign-in.

Samples Ciam All

Authentication

Microsoft maintains code samples that demonstrate how to integrate various application types with Microsoft Entra External ID. We provide instructions for downloading and using samples or building your own app based on common authentication and authorization…

Security Customers

Fundamentals

Each layer addresses a different class of attacks, reducing the likelihood of compromise and limiting the blast radius.

B2b Government National Clouds

General

Learn what features are available in Microsoft Entra B2B collaboration in US Government and national clouds

B2c Deployment Plans

Architecture

Azure Active Directory B2C deployment guide for planning, implementation, and monitoring

Choose Authentication Approach

Fundamentals

Compare browser-delegated and native authentication in Microsoft Entra External ID and choose the right approach for your customer-facing app.

Current Limitations

General

Current limitations for Microsoft Entra B2B collaboration

Custom roles for cross-tenant access settings

General

Learn how your organization can define custom roles to manage cross-tenant access settings, allowing for precise control without relying on built-in management roles.

Direct Federation

Standards

Set up direct federation with SAML 2.0 or WS-Fed identity providers so users can sign in with work accounts. Understand attributes and claims for federation.

Entra Id Federation Customers

Standards

Learn how to configure a Microsoft Entra ID tenant as an OpenID Connect identity provider in Microsoft Entra External ID, enabling users to sign in using their existing organizational accounts.

Hybrid Cloud To On Premises

General

Learn how to give cloud B2B users access to on-premises apps with Microsoft Entra B2B collaboration.

Leave The Organization

General

As a B2B collaboration user, learn how to leave an organization if you no longer need guest user access to apps. If you're an admin, see how to allow external users to leave.

Native authentication

Fundamentals

Learn how to set up native authentication in Microsoft Entra External ID. Customize the user interface for mobile and desktop apps, and provide a seamless sign-in experience.

Self Service Portal

General

Learn how to customize the onboarding workflow for Microsoft Entra B2B users to fit your organization’s needs.

Self Service Sign Up Overview

Fundamentals

Learn how to enable self-service sign-up for Microsoft Entra External ID. Allow external users to sign up for your applications themselves, customize the sign-up experience, and manage user flows.

Sign in with alias

Authentication

Learn how to sign in and sign up with alias/username with External ID for customer identity and access management (CIAM). Get detailed steps to enable username as a sign-in identifier and create users with both email address and username.

Tenant Configurations

General

Learn about tenant configurations in Microsoft Entra External ID, including the differences between workforce and external tenants.

Use MSAL.js with Azure AD B2C

Microsoft identity platform

The Microsoft Authentication Library for JavaScript (MSAL.js) enables applications to work with Azure AD B2C and acquire tokens to call secured web APIs. These web APIs can be Microsoft Graph, other Microsoft APIs, web APIs from others, or your own web API.

User profile attributes

Fundamentals

User profile attributes that you can collect from the user during sign-up, and how to extend user profile attributes by using custom user attributes.

About B2B Invitations

Authentication

Learn about the B2B collaboration invitation email you can send to business partners and external guest users who need to authenticate and access your apps.

Add OIDC for customer sign-in

Standards

Learn how to set up OpenID Connect as an external identity provider in Microsoft Entra External ID, enabling users to sign in using their existing accounts.

Set up claims mapping for OIDC

Standards

Learn how to configure the standard OpenID Connect claims with the claims your identity provider provides in your external tenant.

Direct Federation

Standards

1. On the **New SAML/WS-Fed IdP** page, enter the following:

User Flow Sign Up Sign In Customers

Authentication

By default, after a customer signs in to an app that uses your user flow, they see a **Stay signed in?** prompt asking whether to stay signed in across browser sessions. If the user selects **Yes**, a persistent authentication cookie is issued and they remain…

Direct Federation

Standards

To enable domainless federation for a new SAML IdP, follow these steps:

Backup Difference Report Recovery Model

Monitoring

Microsoft Entra Backup and Recovery is available for workforce tenants only. Microsoft Entra External ID tenants and Azure AD B2C tenants aren't supported.

B2b Quickstart Add Guest Users Portal

General

In this quickstart, you'll learn how to add a new guest user to your Microsoft Entra directory in the Microsoft Entra admin center. You'll also send an invitation and see what the guest user's invitation redemption process looks like.

Entra Id Federation Customers

Branding

An external user can self-register in the External ID tenant by using the sign-up and sign-in user flow. When the user selects the federated Microsoft Entra ID identity provider on the sign-in page and authenticates with their organizational account, a user a…

Manage Admin Accounts

General

Use the following steps to create a new user account and to grant admin permissions to the account by adding a Microsoft Entra role. (Only required steps are described here. For a complete description of all properties, see the Microsoft Entra ID article [How…

Multi Tenant Organization Known Issues

Provisioning

- If you're already using Microsoft Entra cross-tenant synchronization, for various [multi-hub multi-spoke topologies](cross-tenant-synchronization-topology.md), you don't need to use the Microsoft 365 admin center share users functionality. Instead, you migh…

User Permissions

General

To better understand the typical use cases for users in an external tenant, we can categorize them as follows:

Customize the browser language

Authentication

Learn about how to customize the browser language for your app's authentication experience to provide a personalized sign-in.