Identity Provider (Microsoft Entra ID)
Let users sign in to Horizon with Microsoft Entra ID over OpenID Connect, with optional SCIM provisioning.
This guide walks through connecting Horizon to Microsoft Entra ID (formerly Azure AD) as an OpenID Connect identity provider, so your users can sign in to Horizon with their corporate account. It also covers SCIM provisioning, so users and group memberships can be synchronized automatically from Entra ID into Horizon.
Horizon supports any standards-compliant OpenID Connect provider. Entra ID is used here as a concrete example — the same steps apply to other OIDC providers, adjusting the metadata URL and claim names accordingly. For SAML or other providers, refer to the Evertrust Horizon documentation.
Prerequisites
- Entra ID tenant administrator access (to register an application and grant admin consent).
- Horizon administrator access (Security > Access Management).
Step 1 — Register an application in Entra ID
- Sign in to the Azure Portal and go to Microsoft Entra ID > App registrations > New registration.
- Give the application a name (e.g.
Horizon CLM). - Leave the Redirect URI empty for now — you'll add it in Step 3, once Horizon has generated the exact callback URL for this provider.
- Click Register.
- On the application's Overview page, note the Application (client) ID and Directory (tenant) ID — you'll need both.
- Go to Certificates & secrets > Client secrets > New client secret. Set an expiry per your organization's policy, then copy the generated secret value immediately — it is not shown again.
- Go to API permissions and confirm the delegated Microsoft Graph permissions
openid,profile, andemailare present. Grant admin consent for the tenant if required by your organization's policy.
Step 2 — Create credentials in Horizon
-
In Horizon, go to Security > Credentials.
-
Click Add a Credential.
-
Fill the different attributes:
Field Value Credentials Type Select Login. Name A unique label for this credential (e.g. entraid-oidc).Target Select Identity Providers. Login The Application (client) ID from Step 1. Password The client secret value from Step 1.
Step 3 — Create the identity provider in Horizon
-
In Horizon, go to Security > Access Management > Identity Providers.
-
Click Add.
-
Select identity provider type OpenID Connect and fill in the fields:
Field Value Name A unique, meaningful name (e.g. entraid).Provider metadata URL https://login.microsoftonline.com/<tenant-id>/v2.0/.well-known/openid-configuration, replacing<tenant-id>with the Directory (tenant) ID from Step 1.Client credentials The credential created in Step 2. Scope openid profile emailIdentifier Claim {{oid}}— Entra ID's stable, unique object ID for the user. Preferred over email or UPN since it never changes.Email Claim {{email}}Name Claim {{name}}Enable Yes Enabled on UI Yes
Entra ID does not always return an email claim by default — it depends on the account type and how optional claims are configured. If users are created without an email address, switch the Email Claim to {{preferred_username}}, or add email as an optional ID token claim in Entra ID under Token configuration.
- On the Languages tab, add a display name (e.g. "Microsoft Entra ID" or "Corporate SSO") so users recognize the option on the login screen.
- Click Save. Horizon generates the exact callback (redirect) URL for this provider — open the saved identity provider to retrieve it.
- Back in the Azure Portal, go to your app registration > Authentication > Add a platform > Web, paste the redirect URI generated by Horizon, and click Save.
Step 4 — Test sign-in
- Log out of Horizon.
- On the login screen, select the identity provider you created.
- Complete the Microsoft sign-in flow.
- Confirm you're redirected back to Horizon, authenticated as your Entra ID identity.
Step 5 — Provision users and teams automatically with SCIM (optional)
Instead of relying on just-in-time user creation at first login, Entra ID can push users and group memberships into Horizon automatically via SCIM 2.0, mapping Entra ID groups to Horizon roles or teams.
SCIM has no OIDC/OAuth flow of its own — Entra ID authenticates to Horizon's SCIM endpoint using plain HTTP Basic (or bearer) auth, encoded as base64 Login:Password. This is a separate credential from the OIDC client credentials used for SSO in Step 2: create a dedicated local account and role for it, scoped to only what SCIM provisioning needs, rather than reusing an administrator account.
-
In Horizon, go to Security > Access Management > Roles and click Add. Give it a unique Name (e.g.
entraid-scim) and grant only the permissions required to manage users, teams, and role membership. Save. -
Go to Security > Access Management > Local Accounts and click Add. Set an Identifier (e.g.
entraid-scim), assign it the role created above, and set its password — this identifier/password pair becomes theLogin:Passwordused in the SCIM Basic Auth header. -
In Horizon, go to Security > SCIM Profiles and click Add.
-
Give it a unique Name and save.
-
Edit the profile's SCIM-specific parameters:
Field Description Mail type The SCIM mail type to synchronize into Horizon. Defaults to work.Mappings One or more mappings from a SCIM group name (as sent by Entra ID) to either a Horizon role or a team — not both. Add as many mappings as you have groups to synchronize. -
Note this profile's SCIM base URL:
https://<horizonUrl>/security/scim/<scimProfileName>/. -
In the Azure Portal, open your app's corresponding Enterprise application > Provisioning, set Provisioning Mode to Automatic, set Tenant URL to the SCIM base URL above, and set Secret Token to the base64-encoded
Login:Passwordof the local account created in Step 2. -
Click Test Connection, then start provisioning.
Horizon implements a subset of the SCIM 2.0 RFCs, not the full specification: only the eq and and filter operators are supported (on the userName and displayName attributes), each SCIM user carries a single email address, and SCIM groups can only be synchronized — Horizon does not support creating or deleting SCIM groups.
Troubleshooting
| Symptom | Likely cause | Fix |
|---|---|---|
| "Invalid redirect path" error during login | The redirect URI registered in Entra ID doesn't exactly match the one Horizon generated | Copy the redirect URI from the saved identity provider in Horizon and paste it verbatim into Entra ID's Authentication settings — check for a trailing slash mismatch. |
| User is created without an email address | Entra ID didn't return an email claim for this account | Switch Email Claim to {{preferred_username}}, or add email as an optional ID token claim in Entra ID's Token configuration. |
| SCIM provisioning fails immediately with an authentication error | Wrong SCIM base URL, or the bearer/basic-auth credential doesn't match what Horizon expects | Confirm the tenant URL includes the trailing slash and the exact SCIM profile name, and re-check the secret token configured on the Entra ID side. |
| A user or group isn't synchronized | No mapping exists for that SCIM group in the SCIM Profile, or the role/team is already referenced elsewhere | Add a mapping for the missing group, and confirm the target role or team isn't already assigned through a conflicting mapping. |