Single Sign On with Entra into My1Login

Single Sign On with Entra into My1Login

There are a few different ways you can initiate Single Sign On (SSO) with Entra depending on how the customer environment is set up. My1Login can give advice on which option will suit you best.

User initiated SSO

The user browses to their whitelabel (or has it set as their home page) and then clicks the OIDC login button on the page. This will redirect them to Microsoft as their IDP for authentication. The authentication will happen automatically if they have a PRT (Primary Resource Token) already in their browser or it will present them with the standard Microsoft login form to login as normal.

Query string and browser plugin Seamless SSO

The administrator sets the user’s home page to have a custom My1Login Entra query string appended to it and has the My1Login browser plugin installed on their users' PCs. The query string lets the My1Login browser plugin know what white label to open, and which OIDC button to push to initiate the IDP login to Microsoft.

Direct Login URL Seamless SSO

The administrator might want to set the My1Login vault as their users' homepage or open it in a second tab, or the user might want to have the vault as a bookmark that they can click on and login automatically. They can do this by using the Direct Login URL. This URL simulates what pressing the OIDC login button does and takes the user directly to their vault if they have a valid PRT.

The Direct Login URL is unique to every customer. It consists of two parts:

  1. The accountProviderId which tells them which OIDC IDP tenant and button to use. The ID number is unique to each OIDC integration.
    1. https://acme-live.my1login.com/Business/Oidc/StartAuth?accountProviderId=1127
  2. The redirectURL which directs them to their white label:
    1. &redirectUrl=https://acme.my1login.com

Altogether it will look like this:

https://acme-live.my1login.com/Business/Oidc/StartAuth?accountProviderId=1127&redirectUrl=https://acme-live.my1login.com


    • Related Articles

    • Install and Configure My1Login's Entra Directory Service (EDS)

      Entra Directory Service (EDS) Allows admins to control which users are synchronised from the Entra Directory to My1Login and provides seamless Single Sign-On (SSO) to the My1Login web application using Entra identities. Additionally, this functions ...
    • What is the Entra Directory Service (EDS) and how does it work?

      The My1Login Entra Directory Service (EDS) : - enables a Zero-Login experience for your My1Login users so adoption is guaranteed - provides the highest level of customer security by managing client-side encryption keys inside the secure perimeter of ...
    • Troubleshooting: A user is unable to login to My1Login

      If a user is unable to login to My1Login, below are a simple set of checks to troubleshoot. Valid User: Check the user is registered with an account associated with your company. This could be either an email account or an Active Directory account. ...
    • My1Login EDS: Azure App Registration

      Registration of the My1Login EDS App within Azure The My1Login Entra Directory Service (EDS) : enables a Zero-Login experience for your My1Login users so adoption is guaranteed provides the highest level of customer security by managing client-side ...
    • How the Active Directory Connector (ADC) works

      How the Active Directory Connector (ADC) works The My1Login Active Directory Connector (ADC) extends your AD domain into the My1Login cloud Identity registry enabling seamless single sign on to the My1Login system. The ADC supports bi-directional ...