cancel
Showing results for 
Search instead for 
Did you mean: 
Reply
pmarnason
Helper I
Helper I

Is it possible to have external users SSO authenticate using their own AAD credentials?

We want to have clients authenticate using their own AAD credentials, so they don't have to remember yet another password just to use our product.

 

I came across this article which seems to indicate it is indeed possible, while searching on this forum hints at the opposite.

 

So is it possible?

 

EDIT: To make this first post seem less vague, here is some more information:

 

  • This is regarding AAD B2C, since that is recommended over using simply AAD
  • I am using Recommended user flows, since the Standard ones are deprecated in August
  • The B2C tenant as well as the portal environment are completely fresh (created in January)

Finally, I don't HAVE to use B2C nor Recommended user flows. I am only doing so because the documentations keep recommending to do that.

The single only business need we have, is that any user with a Microsoft school or work account should be able to register without entering any credentials, and with as few clicks as possible. So far any user we haven't invited to our B2C tenant beforehand will get an AADSTS50020 error upon using the user flow.

24 REPLIES 24
ragavanrajan
Super User
Super User

Hi @pmarnason , 

 

 Yes it is possible through Azure B2B if you want to allow them to use their own credentials.  I am adding the official docs for you to check how to enable Azure Active directory login. Keep in mind that once you have enabled this option the external users will set in the main "Azure Active Directory tenant" 

 

https://docs.microsoft.com/en-us/powerapps/maker/portals/configure/use-simplified-authentication-con...

Adding our community champion @OliverRodrigues  recent good video for your reference: 

https://www.youtube.com/watch?v=SngdBdEVGBc&ab_channel=PowerCommunity 

 

and another one from EngineeredCode to understand more: 

 

https://www.youtube.com/watch?v=_Gf142b9Aq4&t=54s&ab_channel=EngineeredCode 

 

 

PS: The recommended approach is to enable Azure B2C but you can try the above method also. 

 

Hope it helps. 

------------

If you like this post, give a Thumbs up. Where it solved your request, Mark it as a Solution to enable other users find it.

Thank you for the links, but I went with the B2C instead.

 

I set up Azure B2C and managed to add an SSO button to the login flow on my portal.

 

Unfortunately, the registration of a user is a very lengthy process:

  1. Invite guest user to B2C tenant
  2. User opens invite link on their email
  3. User is redirected to myapplications.microsoft.com after accepting registration (I am certain this redirect url could/should be changed)
  4. User logs in to portal through SSO button
  5. User has to enter email to get a verification code sent, and after entering the code the user is allowed to register

After this, the SSO button functions as expected.

 

Preferably, we would not have to invite guest users at all, but rather allow anyone to register without any action on our part. It would be even better if it simply happened as the user presses the SSO button, as if they were an invited and registered guest user and portal contact already to begin with.

 

If this is not possible, is there at least a way to avoid the verification code on portal sign up?

 

 

Thank you again for your help.

ragavanrajan
Super User
Super User

Hi @pmarnason ,

 

 You can automate the "Guest user invitation part" if you have sufficient privileges to Azure. 

Please see the blog from Arpit  https://arpitmscrmhunt.blogspot.com/2020/05/add-guest-users-in-azure-active.html. 

 

Regarding the verification code it is security thing: 

 

"A user can choose to remember the browser that successfully passed the verification, so that the security code won't be required the next time the user signs in from the same browser." 

 

You can turn off the security code verification if needed by going in to site settings: 

Authentication/Registration/TwoFactorEnabled  - If you dont see one you can create it. 

 

Set the value to "false". In portal studio > Do the sync configuration and browse website to make the changes reflected. 

 


Hope it helps. 

------------

If you like this post, give a Thumbs up. Where it solved your request, Mark it as a Solution to enable other users find it.

 

Thank you, I guess I could let users invite themselves through a link or something then.

 

Is there a way to completely avoid the registering process, so to a new registrant it would simply appear as they are logging in without having to be invited in the first place? I want the steps/clicks involved to be as few as possible.

ragavanrajan
Super User
Super User

Hi @pmarnason

 

    I am little bit confused, Are you trying local registration  or Azure B2C logon. If it is local registration then can you please raise it as a separate topic. May be I am wrong in understanding your full issue, I will handover to our peer community champions to help here.   FYI: @OliverRodrigues  & @OOlashyn 

I do not blame you one bit, as I have been confusing myself a lot too trying to solve this one.

 

In regards to local registration vs Azure B2C logon, I wished to follow best practices and so I believe I have successfully implemented B2C now.

 

The issue lies in how I phrased my original question, I should have asked: Is it possible to have external users register themselves by simply authenticating through Azure B2C using their own credentials.

And as such completely skipping the whole invite process.

 

As an example of the user flow we want to accomplish, I refer to how signing up to reddit.com works. 

Screenshot 2021-01-26 110619.png

When I click "continue with Google" on the sign up prompt, I am sent to Google OAuth and after selecting my account, my user is immediately created on Reddit. We want the same user experience for our end users, except with the external provider allowing them to use their own Azure credentials.

 

Exactly how this is accomplished with local registration or B2C, or something else entirely, really does not matter. 

Hi @pmarnason ,

You can configure your Azure B2C and portal to support registration process without invites etc. In the configuration process of Azure B2C (https://docs.microsoft.com/en-us/powerapps/maker/portals/configure/configure-azure-ad-b2c-provider-m...) at step 6 you should configure Registration Claims mapping  and Login Claims mapping with proper fields(email, firstname and lastname) and toggle Contact mapping with email to make sure that if contact already exists in the system it will map it properly by the email. Keep in mind that in your user flow in Azure B2C you need to configure additional claims (like firstname and lastname from external provider) because be default system only provide email claim. If for some reason you cannot configure Portal part in new UI you can do it with site settings. For that you can check my article about Open ID Connect configuration (https://www.dancingwithcrm.com/claims-mapping-for-openidconnect-for-portal/) - it is applicable for Azure B2C with proper Site Settings name.

----------------------------------------------------
If you find this post helpful consider marking it as a solution to help others find it.

I configured Registration Claims mapping and Login Claims mapping, toggled Contact mapping with email and also followed the instructions from your article.

 

Unfortunately, I am still at a complete loss.

 

First and foremost, users (both from our org and external) still get error AADSTS50020 when trying to register without having been invited beforehand in B2C:

Test user from our organization is unable to register without an invitationTest user from our organization is unable to register without an invitation

 

If I do invite the user in B2C, it still appears as if I set up claims mapping wrong somehow, as you can see in this screenshot:

Screenshot 2021-01-26 212527.png

You might also note the form is asking for a verification code, despite Authentication/Registration/TwoFactorEnabled being set to false.

 

I will try to gather all necessary configurations here:

Spoiler
Screenshot 2021-01-26 213147.png
Screenshot 2021-01-26 213426.png
Screenshot 2021-01-26 213815.png
Screenshot 2021-01-26 213900.png
Screenshot 2021-01-26 213914.png
Screenshot 2021-01-26 214011.png
Screenshot 2021-01-26 214137.png

 

Thank you in advance.

Hi @pmarnason,

Sorry for the long reply. Well everything looks correct. I will try to try to set up similar configuration and see if it will work. Meanwhile maybe you will think about workaround like allowing user to register on portal and automatically create them in your azure via power automate flow (like in this article - https://powerapps.microsoft.com/en-us/blog/on-boarding-user-external-user-to-tenant-through-powerapp...).

----------------------------------------------------
If you find this post helpful consider marking it as a solution to help others find it.

Helpful resources

Announcements

November 2023 Community Newsletter

Welcome to our November Newsletter, where we highlight the latest news, product releases, upcoming events, and the amazing work of our outstanding Community members. If you're new to the Community, please make sure to follow the latest News & Announcements and check out the Community on LinkedIn as well! It's the best way to stay up-to-date with all the news from across the Power Platform and beyond.        This month's highlights:- - Our most active community members- Microsoft Power Up Program- Microsoft Community Days website - The latest blogs and more                 COMMUNITY HIGHLIGHTS Check out the most active community members of the last month. These hardworking members are posting regularly, answering questions, kudos, and providing top solutions in their communities. We are so thankful for each of you--keep up the great work! If you hope to see your name here next month, just get active! FLMikePstork1Nived_NambiarWarrenBelzSprongYeManishSolankiLaurensMwskinnermlcAgniusExpiscornovuscreativeopinion KatieAUinzil2kHaressh2728hafizsultan242douicmccaughanwoLucas001domliu   Power Up Program Click the image below to discover more about the amazing Microsoft Power Up Program, as Reem Omar, Abbas Godhrawala, Chahine Atallah, Ruby Ruiz Brown, Juan Francisco Sánchez Enciso, Joscelyne Andrade Arévalo, Eric G. and Paulina Pałczyńska share how non-tech professionals can successfully advance into a new career path using Microsoft #PowerPlatform.   To find out more about this amazing initiative, click here to apply for the program and reboot your journey into low-code app development today!     Community Days - Event Website Have you checked out the Community Days website yet? Dedicated to the volunteer community organizers around the world, Community Days is the perfect place to find an event near you or add an event for wider exposure. Many thanks to Thomas Daly, Sharon Weaver, Sedat Tum, Jonathan Weaver, Manpreet Singh, David Leveille, Jason Rivera, Mike Maadarani, Rob Windsor and the team for all their hard work. Anyone can host a Community Day on any topic relevant to our industry, just click the image below to find out more.       EVENT NEWS Power Platform French Summit - Paris/Virtual - 6-7th Dec It's not long now until the Power Platform French Summit, which takes place both virtually and in-person at the Microsoft France conference center in Paris on 6-7th December 2023. If you can't make it in-person, all sessions will also be broadcast on virtual networks for better distribution and accessibility.   There's a fantastic array of speakers, including Jérémy LAPLAINE, Amira Beldjilali, Rémi Chambard, Erika Beaumier, Makenson Frena, Assia Boutera, Elliott Pierret, Clothilde Facon, Gilles Pommier, Marie Aubert, Antoine Herbosa, Chloé Moreau, Raphaël Senis, Rym Ben Hamida, Loïc Cimon, Joséphine Salafia, David Zoonekyndt, Aïcha Charpentier, Henry Jammes, Milene Rochard, Mehdi EL YASSIR, and many more. Click the image below for more information.       LATEST COMMUNITY BLOG ARTICLES Power Apps Community Blog Power Automate Community Blog Copilot Community Blog Power Pages Community Blog

Back to Basics Tuesday Tip #10: Community Support

This is the TENTH post in our ongoing series dedicated to helping the amazing members of our community--both new members and seasoned veterans--learn and grow in how to best engage in the community! Each Tuesday, we feature new content that will help you best understand the community--from ranking and badges to profile avatars, from Super Users to blogging in the community. Our hope is that this information will help each of our community members grow in their experience with Power Platform, with the community, and with each other!   This Week: All About Community Support   Whether you're a seasoned community veteran or just getting started, you may need a bit of help from time to time! If you need to share feedback with the Community Engagement team about the community or are looking for ways we can assist you with user groups, events, or something else, Community Support is the place to start.   Community Support is part of every one of our communities, accessible to all our community members.     Power Apps: https://powerusers.microsoft.com/t5/Community-Support/ct-p/pa_community_support Power Automate: https://powerusers.microsoft.com/t5/Community-Support/ct-p/mpa_community_support Power Pages: https://powerusers.microsoft.com/t5/Community-Support/ct-p/mpp_community_support Copilot Studio: https://powerusers.microsoft.com/t5/Community-Support/ct-p/pva_community-support   Within each community's Community Support page, you'll find three distinct areas, each with a different focus to help you when you need support from us most.     Community Accounts & Registration is the go-to source for any and all information related to your account here in the community. It's full of great knowledge base articles that will help you manage your community account and know what steps to take if you wish to close your account.  ●  Power Apps  ●  Power Automate  ●  Power Pages, ●  Copilot Studio      Using the Community is your source for assistance with everything from Community User Groups to FAQ's and more. If you want to know what kudos are, how badges work, how to level up your User Group or something else, you will probably find the answers here. ●  Power Apps   ● Power Automate    ●  Power Pages  ●  Copilot Studio      Community Feedback is where you can share opportunities, concerns, or get information from the Community Engagement team. It's your best place to post a question about an issue you're having in the community, a general question you need answered. Whatever it is, visit Community Feedback to get the answers you need right away. Our team is honored to partner with you and can't wait to help you!   ●  Power Apps  ● Power Automate   ● Power Pages   ● Copilot Studio  

Microsoft Ignite 2023: The Recap

What an amazing event we had this year, as Microsoft showcased the latest advancements in how AI has the potential to reshape how customers, partners and developers strategize the future of work. Check out below some of our handpicked videos and Ignite announcements to see how Microsoft is driving real change for users and businesses across the globe.   Video Highlights Click the image below to check out a selection of Ignite 2023 videos, including the "Microsoft Cloud in the era of AI" keynote from Scott Guthrie, Charles Lamanna, Arun Ulag, Sarah Bird, Rani Borkar, Eric Boyd, Erin Chapple, Ali Ghodsi, and Seth Juarez. There's also a great breakdown of the amazing Microsoft Copilot Studio with Omar Aftab, Gary Pretty, and Kendra Springer, plus exciting sessions from Rajesh Jha, Jared Spataro, Ryan Jones, Zohar Raz, and many more.     Blog Announcements Microsoft Copilot presents an opportunity to reimagine the way we work—turning natural language into the most powerful productivity tool on the planet. With AI, organizations can unearth value in data across productivity tools like business applications and Microsoft 365. Click the link below to find out more.     Check out the latest features in Microsoft Power Apps that will help developers create AI-infused apps faster, give administrators more control over managing thousands of Microsoft Power Platform makers at scale, and deliver better experiences to users around the world. Click the image below to find out more.     Click below to discover new ways to orchestrate business processes across your organization with Copilot in Power Automate. With its user-friendly interface that offers hundreds of prebuilt drag-and-drop actions, more customers have been able to benefit from the power of automation.     Discover how Microsoft Power Platform and Microsoft Dataverse are activating the strength of your enterprise data using AI, the announcement of “plugins for Microsoft Copilot for Microsoft 365”, plus two new Power Apps creator experiences using Excel and natural language.       Click below to find out more about the general availability of Microsoft Fabric and the public preview of Copilot in Microsoft Fabric. With the launch of these next-generation analytics tools, you can empower your data teams to easily scale the demand on your growing business.     And for the rest of all the good stuff, click the link below to visit the Microsoft Ignite 2023 "Book of News", with over ONE HUNDRED announcements across infrastructure, data, security, new tools, AI, and everything else in-between!        

Back to Basics Tuesday Tip #9: All About the Galleries

This is the ninth post in our series dedicated to helping the amazing members of our community--both new members and seasoned veterans--learn and grow in how to best engage in the community! Each Tuesday, we feature new content that will help you best understand the community--from ranking and badges to profile avatars, from Super Users to blogging in the community. Our hope is that this information will help each of our community members grow in their experience with Power Platform, with the community, and with each other!     Today's Tip: All About the Galleries Have you checked out the library of content in our galleries? Whether you're looking for the latest info on an upcoming event, a helpful webinar, or tips and tricks from some of our most experienced community members, our galleries are full of the latest and greatest video content for the Power Platform communities.   There are several different galleries in each community, but we recommend checking these out first:   Community Connections & How-To Videos Hosted by members of the Power Platform Community Engagement  Team and featuring community members from around the world, these helpful videos are a great way to "kick the tires" of Power Platform and find out more about your fellow community members! Check them out in Power Apps, Power Automate, Power Pages, and Copilot Studio!         Webinars & Video Gallery Each community has its own unique webinars and videos highlighting some of the great work being done across the Power Platform. Watch tutorials and demos by Microsoft staff, partners, and community gurus! Check them out: Power Apps Webinars & Video Gallery Power Automate Webinars & Video Gallery Power Pages Webinars & Video Gallery Copilot Studio Webinars & Video Gallery   Events Whether it's the excitement of the Microsoft Power Platform Conference, a local event near you, or one of the many other in-person and virtual connection opportunities around the world, this is the place to find out more about all the Power Platform-centered events. Power Apps Events Power Automate Events Power Pages Events Copilot Studio Events   Unique Galleries to Each Community Because each area of Power Platform has its own unique features and benefits, there are areas of the galleries dedicated specifically to videos about that product. Whether it's Power Apps samples from the community or the Power Automate Cookbook highlighting unique flows, the Bot Sharing Gallery in Copilot Studio or Front-End Code Samples in Power Pages, there's a gallery for you!   Check out each community's gallery today! Power Apps Gallery Power Automate Gallery Power Pages Gallery Copilot Studio Gallery

Unlocking the Power of Community: A Journey with Featued User Group leaders Geetha Sivasailam and Ben McMann

In the bustling world of technology, two dynamic leaders, Geetha Sivasailam and Ben McMann, have been at the forefront, steering the ship of the Dallas Fort Worth Power Platform User Group since its inception in February 2019. As Practice Lead (Power Platform | Fusion Dev) at Lantern, Geetha brings a wealth of consulting experience, while Ben, a key member of the Studio Leadership team at Lantern, specializes in crafting strategies that leverage Microsoft digital technologies to transform business models.   Empowering Through Community Leadership Geetha and Ben's journey as user group leaders began with a simple yet powerful goal: to create a space where individuals across the DFW area could connect, grow their skills, and add value to their businesses through the Power Platform. The platform, known for its versatility, allows users to achieve more with less code and foster creativity.   The Power of Community Impact Reflecting on their experiences, Geetha and Ben emphasize the profound impact that community engagement has had on both their professional and personal lives. The Power Platform community, they note, is a wellspring of resources and opportunities, fostering continuous learning, skill enhancement, and networking with industry experts and peers.   Favorite Moments and Words of Wisdom The duo's favorite aspect of leading the user group lies in witnessing the transformative projects and innovations community members create with the Power Platform. Their advice to aspiring user group leaders? "Encourage diverse perspectives, maintain an open space for idea-sharing, stay curious, and, most importantly, have fun building a vibrant community."   Building Bridges, Breaking Barriers Geetha and Ben encourage others to step into the realm of user group leadership, citing the rewarding experience of creating and nurturing a community of like-minded individuals. They highlight the chance to influence, impact, and positively guide others, fostering connections that extend beyond mere technology discussions.   Joining a User Group: A Gateway to Growth The leaders stress the importance of joining a user group, emphasizing exposure to diverse perspectives, solutions, and career growth opportunities within the Power Platform community. "Being part of such a group provides a supportive environment for seeking advice, sharing experiences, and navigating challenges."   A Year of Milestones Looking back at the past year, Geetha and Ben express pride in the group's growth and global participation. They recount the enriching experience of meeting members in person at the Microsoft Power Platform conference, showcasing the diverse range of perspectives and guest speakers that enriched the community's overall experience.   Continuous Learning on the Leadership Journey As user group leaders, Geetha and Ben recognize the continuous learning curve, blending interpersonal skills, adaptability, and dedication to foster a vibrant community. They highlight the importance of patience, persistence, and flexibility in achieving group goals, noting the significance of listening to the needs and suggestions of group members.They invite all tech enthusiasts to join the Dallas Fort Worth Power Platform User Group, a thriving hub where the power of community propels individuals to new heights in the dynamic realm of technology.

Visit the Community Lounge at Microsoft Ignite!

Are you attending Microsoft Ignite in Seattle this week? If so, we'd love to see you at the Community Lounge! Hosted by members of our Community team, it's a great place to connect, meet some Microsoft executives, and get a sticker or two. And if you're an MVP there are some special opportunities to meet up!     The Community Lounge is more than just a space—it's a hub of activity, collaboration, and camaraderie. So, dive in, explore, and make the most of your Microsoft Ignite experience by immersing yourself in the vibrant and dynamic community that awaits you.Find out the schedule and all the details here: Community Lounge at Ignite! See you at #MSIgnite!    

Users online (3,949)