Hideez Server as an External Authentication Method for Microsoft Entra ID via OIDC
The Hideez + Microsoft Entra ID
Last updated
The Hideez + Microsoft Entra ID
Last updated
This guide provides step-by-step instructions to configure Hideez Identity Cloud as an External Authentication Method (EAM) for Microsoft Entra ID using OIDC (OpenID Connect). This setup facilitates seamless external authentication and ensures secure user login through an additional MFA (Multifactor Authentication) step.
Hideez Server as an External Authentication Method (EAM) does not enable direct login to Microsoft Entra ID. It serves solely as an additional MFA verification method.
To enable this feature, an Entra ID P1 license is required.
Additional Resources
For further setup guidance, refer to the following articles:
Log in to the Microsoft Entra Admin Center.
Navigate to Identity → Applications → App Registrations.
Click + New registration.
Define a name for the app.
Set Supported account type to:
Accounts in any organizational directory (Any Entra ID directory - Multitenant).
Under the Redirect URI section:
Select Web platform.
Enter: https://<hideez server name>/connect/authorize
Example: https://dev.hideez.com/connect/authorize
Click Register.
After registering, keep the Application ID from the Essentials section. You'll need it later to configure your EAM in Hideez Enterprise Server.
Go to Hideez Enterprise Server.
Go to Integrations → OIDC.
Click Create App Integration and set the following parameters:
App Type: Entra ID External Authentication Method (EAM).
Fill in the following:
Tenant ID
Application ID
Click Create.
Keep the tab Add openid connect client with values Client ID, Discovery Endpoint, and Entra Application ID ready for the next step.
Go back to Microsoft Entra Admin Center.
Navigate to Protection → Authentication Methods → Policies.
Click + Add external method (Preview).
Set the following parameters:
Name: The name users will see during Entra ID login when choosing their authentication method.
Client ID: Paste from the app integration in Hideez Enterprise Server.
Discovery Endpoint: Paste from the app integration in the Hideez Enterprise Server.
App ID: Paste from the app integration in Hideez Enterprise Server.
Click Request permission to grant admin consent for the app to read user information.
Click Enable.
Review the Included and Excluded Targets (all users are included by default).
Click Save.
During migration, administrators are advised to create parallel Conditional Access Policies to test new configurations with a subset of users. This ensures minimal disruption and allows admins to verify the functionality of the custom controls.
Login to Microsoft Entra admin center.
Navigate to Protection → Conditional Access → Policies.
Click + New Policy (or edit an existing policy).
Configure the policy:
Specify Users: Define the users who will be affected by this policy.
Target Applications: Specify the applications covered by this policy.
Access Requirements:
Choose Require multifactor authentication so that the EAM (Hideez Enterprise Server) is used as the MFA step.
Click on Save.
More information from Microsoft can be found here Using Custom Control and EAM in parallel