Add OIDC for customer sign-in
Learn how to set up OpenID Connect as an external identity provider in Microsoft Entra External ID, enabling users to sign in using their existing accounts.
Track documentation and Message Center changes for Microsoft Entra External ID.
Microsoft Learn documentation ↗Learn how to set up OpenID Connect as an external identity provider in Microsoft Entra External ID, enabling users to sign in using their existing accounts.
1. [Set up tenant restrictions v2](/azure/active-directory/external-identities/tenant-restrictions-v2). If your organization currently uses tenant restrictions v1, review the [guide for migrating to tenant restrictions v2](https://aka.ms/trv2migration).
Passkey support for B2B users and internal guest users is planned to be available by the end of calendar year 2026. These users are included in the scope of the retirement of Microsoft-provided SMS and voice authentication.
SharePoint One-Time Passcode (SPO OTP) authentication retires in October 2026, transitioning external sharing and authentication to Microsoft Entra B2B. New external sharing uses Entra B2B from May 2026. External users need guest accounts for access; admins should prepare by upd…
Use the Migration Policy Analyzer to scan Azure AD B2C custom policies and generate a detailed migration assessment for Microsoft Entra External ID. Start your migration today.
Global Secure Access external user access licensing is supported through Microsoft Entra External ID subscription linking. The administrator must link the subscription in the resource tenant so guest users can access private resources and usage is billed corr…
Learn to migrate from Amazon Cognito to Microsoft Entra External ID with step-by-step guidance, feature mapping, and validation strategies.
Organizations that are deploying passkeys and have Conditional Access policies that require phishing-resistant authentication when accessing **All resources (formerly 'All cloud apps')** can run into a looping issue when users attempt to add a passkey to Micr…
Learn about edge protection, domains, subscriptions, consumer app security, and fraud tactics in security operations for Microsoft Entra External ID.
Compare browser-delegated and native authentication in Microsoft Entra External ID and choose the right approach for your customer-facing app.
Set up direct federation with SAML 2.0 or WS-Fed identity providers so users can sign in with work accounts. Understand attributes and claims for federation.
Learn how to sign in and sign up with alias/username with External ID for customer identity and access management (CIAM). Get detailed steps to enable username as a sign-in identifier and create users with both email address and username.
Learn about tenant configurations in Microsoft Entra External ID, including the differences between workforce and external tenants.
Now that you've added app groups claim in your application, add users to the security groups. If you don't have security group, [create one](~/fundamentals/how-to-manage-groups.md#create-a-basic-group-and-add-members).
Zscaler B2B User Portal is available in the following [national cloud deployments](/graph/deployments).
Learn about the pricing and billing structure for Microsoft Entra External ID, along with steps for linking an external tenant to an Azure subscription.
Microsoft Entra External ID pricing is based on monthly active users (MAU), which is the count of unique users with authentication activity within a calendar month. External ID consists of a core offer and premium add-ons. The Microsoft Entra External ID core…
Learn how to attach custom x-* headers to native authentication network requests in an Android (Kotlin) app to integrate fraud-detection SDKs with Microsoft Entra External ID.
With Microsoft Entra External ID, you can create secure, customized sign-in experiences for your consumer- and business customer-facing apps. In an external tenant, there are several ways for users to sign up for your app. They can create an account using the…
Microsoft Entra External ID user flows are designed for flexibility. Within a sign-up and sign-in user flow, there are built-in authentication events. You can also add custom authentication extensions at specific points within the authentication flow. A custo…
Find answers to frequently asked questions about Microsoft Entra External ID. Learn about pricing, features, and the future of Azure AD B2C and External Identities.
Enforcing MFA enhances your organization's security by adding an extra layer of verification, making it more difficult for unauthorized users to gain access.
Discover the steps for setting up a customer identity and access management (CIAM) solution in an external tenant, including creating a tenant, registering apps, and setting up user flows for sign-in.
Microsoft maintains code samples that demonstrate how to integrate various application types with Microsoft Entra External ID. We provide instructions for downloading and using samples or building your own app based on common authentication and authorization…
Each layer addresses a different class of attacks, reducing the likelihood of compromise and limiting the blast radius.
Learn how to attach custom x-* headers to native authentication network requests in an iOS (Swift) app to integrate fraud-detection SDKs with Microsoft Entra External ID.
Learn how to attach custom x-* headers to native authentication requests in a React or Angular SPA to integrate fraud-detection SDKs with Microsoft Entra External ID.
Learn what features are available in Microsoft Entra B2B collaboration in US Government and national clouds
Azure Active Directory B2C deployment guide for planning, implementation, and monitoring
Learn methods to build resilience in customer identity and access management (CIAM) using Azure AD B2C.
Learn how to call a protected API in your Node.js web application using access tokens from Microsoft Entra External ID.
Compare browser-delegated and native authentication in Microsoft Entra External ID and choose the right approach for your customer-facing app.
Learn how to configure Microsoft Entra External ID with Azure Web Application Firewall.
Learn to convert local guests into Microsoft Entra B2B guest accounts by identifying apps and local guest accounts, migration, and more.
Learn how to prepare your Node.js client web app to call a protected API using access tokens from Microsoft Entra External ID.
Create an enterprise application using the client ID for a multitenant application.
Learn how your organization can define custom roles to manage cross-tenant access settings, allowing for precise control without relying on built-in management roles.
Learn about customizing the language experience in your user flows in Microsoft Entra External ID.
Compare solutions for using Microsoft Entra External ID to work with people outside your organization, including B2B collaboration and Azure AD B2C.
Learn how to configure an external MFA method provider for Microsoft Entra multifactor authentication.
A Microsoft Entra documentation page was updated: Customer intent: As an organization administrator, I want to customize the invitation process for external users using the Microsoft Graph REST API, so that I can tailor the onboarding experience and control t…
Set up direct federation with SAML 2.0 or WS-Fed identity providers so users can sign in with work accounts. Understand attributes and claims for federation.
Disable sign-up in your user flow with Microsoft Graph API. Prevent new registrations and allow only sign-in for your external users.
Enable HSC mode on your Azure AD B2C tenant to adopt Microsoft Entra External ID endpoints while keeping existing users and credentials in place.
Learn how to configure a Microsoft Entra ID tenant as an OpenID Connect identity provider in Microsoft Entra External ID, enabling users to sign in using their existing organizational accounts.
Learn how to give cloud B2B users access to on-premises apps with Microsoft Entra B2B collaboration.
Learn how to implement SSO between a native mobile app and a web resource in an embedded web view using Microsoft Entra External ID native authentication.
Learn how to migrate passwords from another identity provider to Microsoft Entra External ID using Just-In-Time (JIT) Migration.
As a B2B collaboration user, learn how to leave an organization if you no longer need guest user access to apps. If you're an admin, see how to allow external users to leave.
Learn to securely deploy and operate Microsoft Entra External ID architectures with Microsoft Entra.
Migrate users, credentials, and applications from Azure AD B2C to Microsoft Entra External ID using the standard migration approach.
Learn how to set up native authentication in Microsoft Entra External ID. Customize the user interface for mobile and desktop apps, and provide a seamless sign-in experience.
Learn about tenant-level restrictions and controls for users, groups, and applications, along with policy management in a cloud-based portal.
Choose between the standard migration approach and High Scale Compatibility (HSC) mode when moving from Azure AD B2C to Microsoft Entra External ID.
Learn how to run a sample JavaScript SPA to sign in users
Learn how to run a sample Node.js/Express web app to sign in users
Learn how to run a sample Python Django web app to sign in users
Learn how to run a sample Python Flask web app to sign in users
Learn how to run a sample Angular SPA to sign in users
Learn how to run a sample ASP.NET web app to sign in users
Resilience through developer best practices in Customer Identity and Access Management using Azure AD B2C
Resilience through monitoring and analytics using Azure AD B2C
Learn methods to build resilience in end-user experience with Azure AD B2C
Learn about methods to build resilient interfaces with external processes.
Reference documentation for a custom authentication extension that invokes the emailOtpSend event for External ID customer configurations.
Reference documentation for a custom authentication extension that invokes the OnAttributeCollectionStart event for External ID customer configurations.
Reference documentation for a custom authentication extension that invokes the OnAttributeCollectionSubmit event for External ID customer configurations.
Learn how to customize the onboarding workflow for Microsoft Entra B2B users to fit your organization’s needs.
Learn how to enable self-service sign-up for Microsoft Entra External ID. Allow external users to sign up for your applications themselves, customize the sign-up experience, and manage user flows.
Learn how to configure iOS (Swift) sample app to sign up, sign in, sign out and reset password scenarios using Microsoft Entra External ID.
Learn how to configure macOS (Swift) sample app to sign up and sign in using Microsoft Entra External ID.
Learn how to sign in and sign up with alias/username with External ID for customer identity and access management (CIAM). Get detailed steps to enable username as a sign-in identifier and create users with both email address and username.
Learn about tenant configurations in Microsoft Entra External ID, including the differences between workforce and external tenants.
Learn how to manage your external tenant by calling the Azure REST API.
Transition to Microsoft Entra External ID for CIAM: Learn how to migrate your legacy customer identity solutions to enhance security, compliance, and scalability.
Diagnose and resolve common errors when using the High Scale Compatibility (HSC) API for migrating from Azure AD B2C to Microsoft Entra External ID.
The Microsoft Authentication Library for JavaScript (MSAL.js) enables applications to work with Azure AD B2C and acquire tokens to call secured web APIs. These web APIs can be Microsoft Graph, other Microsoft APIs, web APIs from others, or your own web API.
User profile attributes that you can collect from the user during sign-up, and how to extend user profile attributes by using custom user attributes.
Learn about the B2B collaboration invitation email you can send to business partners and external guest users who need to authenticate and access your apps.
Learn how to set up OpenID Connect as an external identity provider in Microsoft Entra External ID, enabling users to sign in using their existing accounts.
Learn how to configure the standard OpenID Connect claims with the claims your identity provider provides in your external tenant.
Learn how to attach custom x-* headers to native authentication requests in a React or Angular SPA to integrate fraud-detection SDKs with Microsoft Entra External ID.
Learn how to attach custom x-* headers to native authentication network requests in an iOS (Swift) app to integrate fraud-detection SDKs with Microsoft Entra External ID.
Learn how to attach custom x-* headers to native authentication network requests in an Android (Kotlin) app to integrate fraud-detection SDKs with Microsoft Entra External ID.
By default, after a customer signs in to an app that uses your user flow, they see a **Stay signed in?** prompt asking whether to stay signed in across browser sessions. If the user selects **Yes**, a persistent authentication cookie is issued and they remain…
Microsoft Entra Backup and Recovery is available for workforce tenants only. Microsoft Entra External ID tenants and Azure AD B2C tenants aren't supported.
In this quickstart, you'll learn how to add a new guest user to your Microsoft Entra directory in the Microsoft Entra admin center. You'll also send an invitation and see what the guest user's invitation redemption process looks like.
An external user can self-register in the External ID tenant by using the sign-up and sign-in user flow. When the user selects the federated Microsoft Entra ID identity provider on the sign-in page and authenticates with their organizational account, a user a…
Use the following steps to create a new user account and to grant admin permissions to the account by adding a Microsoft Entra role. (Only required steps are described here. For a complete description of all properties, see the Microsoft Entra ID article [How…
- If you're already using Microsoft Entra cross-tenant synchronization, for various [multi-hub multi-spoke topologies](cross-tenant-synchronization-topology.md), you don't need to use the Microsoft 365 admin center share users functionality. Instead, you migh…
To better understand the typical use cases for users in an external tenant, we can categorize them as follows:
Microsoft Entra will enforce stricter federatedTokenValidationPolicy by default starting mid-August 2026, blocking federated sign-ins when internalDomainFederation doesn't match the user's UPN domain. This affects tenants with federated domains configured before December 2025 an…
Shows how an admin can add sponsors to guest users in Microsoft Entra B2B collaboration.
author: garrodonnell
Learn about how to customize the browser language for your app's authentication experience to provide a personalized sign-in.
Learn how to give cloud B2B users access to on-premises apps with Microsoft Entra B2B collaboration.
Learn about customizing the language experience in your user flows in Microsoft Entra External ID.