Skip to main content

Step-by-step guide: Integrating Falcon with Microsoft Entra ID for SSO via OpenID Connect (OIDC)

Learn how to configure Microsoft Entra ID as the identity provider (IdP) for Falcon and enable single sign-on (SSO).

Jonas Steeger avatar
Written by Jonas Steeger
Updated this week

Prerequisites

  • An active Microsoft Entra ID tenant

  • Administrative permissions in Microsoft Entra (for example, Cloud Application Administrator)

  • Access to the Falcon Hub security settings

  • The SSO feature is enabled for the Falcon Hub


Step 1: Register a new application in Microsoft Entra ID

  1. Sign in to the Microsoft Entra admin center.

  2. Go to App registrations.

  3. Select New registration.

  4. Enter a name for the application, for example: Falcon.

  5. Under Supported account types, choose the option that matches your organization (for example, Accounts in this organizational directory only).

  6. Select Register.

  7. Note the following values:

    • Application (client) ID

    • Directory (tenant) ID

  8. Go to Certificates & secrets.

  9. Select New client secret.

  10. Enter a description and choose an Expires value.

  11. Select Add.

  12. Copy and store the client secret Value (this is only shown once).


Step 2: Configure SSO in Falcon

  1. Sign in to Falcon with the appropriate permissions.

  2. Go to Security & Privacy.

  3. Open Authentication.

  4. Select Manage identity providers.

  5. Create a new identity provider.

  6. Enter the following information:

    • Issuer:
      ​https://login.microsoftonline.com/<tenant-id>/v2.0
      ​(Replace <tenant-id> with your Directory (tenant) ID from Microsoft Entra ID.)

    • Client ID:
      The Application (client) ID from Microsoft Entra ID

    • Client secret:
      The client secret Value you generated earlier

  7. Select Save.

  8. Copy the Callback URL by clicking it.


Step 3: Finish configuration in Microsoft Entra ID

  1. In the Falcon app registration in Microsoft Entra ID, go to Authentication.

  2. Select Add a platform.

  3. Choose Web.

  4. Paste the Callback URL from Falcon into Redirect URI.

  5. Select Configure.


Step 4: Test the configuration

  1. In Falcon, select Sign in with this identity provider, or copy the provider URL and open it in a browser.

  2. You will be redirected to Microsoft.

  3. Select your user account or sign in.

  4. Accept the consent prompt for the Falcon application (if prompted).

  5. You will receive an email from Falcon with further instructions.

  6. Open the confirmation link from the email.

  7. If required, confirm your identity with your password.

Your user is now successfully linked to your SSO provider.


Optional: Assign users

  1. In Microsoft Entra ID, go to Enterprise applications and select the Falcon application.

  2. Under Properties, set Assignment required? to Yes.

  3. Select Save.

  4. Go to Users and groups and select Add user/group.

  5. Select the users or groups who should have access to Falcon and confirm the assignment.

Did this answer your question?