Integrate Microsoft Entra ID External Authentication Methods

Microsoft Entra ID is a customer identity and access management (CIAM) solution for managing external identities. See the following documentation for more help:

       https://learn.microsoft.com/en-us/entra/external-id/

       https://learn.microsoft.com/en-us/entra/identity/authentication/how-to-authentication-external-method-manage

       https://learn.microsoft.com/en-us/entra/identity/authentication/concept-authentication-external-method-provider.

You can configure Microsoft Entra ID External Authentication Methods to use Identity as a Service for multi-factor authentication. To do this, you must add Microsoft Entra ID External Authentication Methods as an application in Identity as a Service. This integration guide describes how to integrate Microsoft Entra ID External Authentication Methods with Identity as a Service. To integrate Microsoft Entra ID Active Directory with Identity as a Service, see Integrate Microsoft Entra ID active directory with Identity as a Service.

Note: You can configure one or more Microsoft Entra External ID Authentication Methods OIDC applications for your Microsoft Entra External ID custom tenant that can be used across all application within that tenant. For example, you can create multiple Microsoft Entra External ID Authentication Methods OIDC applications in Identity as a Service and set each application to require a different authenticator.

To integrate Microsoft Entra External ID OIDC with Identity as a Service, complete the following steps:

Step 1: Complete the following prerequisites:

1.      Synchronize your Microsoft Entra ID users with Identity as a Service. See Synchronize Microsoft Entra ID External users with Identity as a Service and Sync an on-premises AD with Microsoft Entra ID External.

2.      If you have not done so already, Create and configure a gateway

3.      Obtain the Microsoft Entra ID Tenant ID.

Step 2: Add Microsoft Entra ID External Authentication Methods to Identity as a Service

Step 3: Add a resource rule to protect access to Microsoft Entra ID External Authentication

Note: Set Skip Password as the first-factor authentication type and then set the second-factor authenticators that you want to use with Microsoft Entra ID External Authentication Methods.

Step 4: Configure the Microsoft Entra ID External ID Tenant

Step 5: Add conditional policies to Microsoft Entra ID

Step 6: Test the Conditional Access Control in Microsoft Entra ID External