Sign In with Microsoft Entra ID
Overview
Connect your Microsoft Entra ID tenant to Scout Console so that your users sign in with their existing Microsoft work accounts.
You register an application in your own Entra ID tenant and send base14 its credentials. base14 then enables Microsoft sign-in for your organization. Sign-in is limited to users of your tenant.
- Sign-in only. Single sign-on authenticates users who already have a Scout Console account. It does not create accounts.
- Accounts come first. Invite users in Scout Console, or provision them automatically with Entra ID Provisioning.
- Roles are not synced. Roles are managed in Scout Console. See User Management.
Prerequisites
- The Application Administrator or Cloud Application Administrator role in your Entra ID tenant.
- Your organization's redirect URI from base14. Contact base14 Support to request it.
- Matching email addresses. Each user's email address in Entra ID must match the email address on their Scout Console account.
Single sign-on works on every Entra ID tier, including the free tier.
Step 1: Register the Application
- Sign in to the Microsoft Entra admin center.
- Go to Identity → Applications → App registrations.
- Select New registration.
- Enter a name, for example
base14 Scout SSO. - Under Supported account types, select Accounts in this organizational directory only (Single tenant).
- Under Redirect URI, select the Web platform and paste the redirect URI that base14 provided.
- Select Register.
The redirect URI must be registered under the Web platform, not Single-page application or Public client. The URI must match the value base14 provided exactly.
Step 2: Create a Client Secret
- In your new application, select Certificates & secrets.
- On the Client secrets tab, select New client secret.
- Enter a description and choose an expiry.
- Select Add.
- Copy the secret's Value immediately. Entra ID shows it only once.
Copy the Value column, not the Secret ID. The Secret ID is not the secret.
Step 3: Confirm API Permissions
- Select API permissions.
- Confirm that Microsoft Graph → User.Read (Delegated) is listed. New registrations include it by default.
- If it is missing, select Add a permission → Microsoft Graph →
Delegated permissions, add
User.Read, and select Add permissions.
Step 4: Send the Details to base14
Collect these values:
| Value | Where to find it |
|---|---|
| Application (client) ID | Overview → Application (client) ID |
| Directory (tenant) ID | Overview → Directory (tenant) ID |
| Client secret | The value you copied in Step 2 |
Send them to base14 Support through a secure channel. Never send the client secret in plain email. base14 enables single sign-on for your organization and confirms when it is ready.
Step 5: Test Sign-In
- Open Scout Console in a private browser window.
- On the sign-in page, select Microsoft.
- Sign in with an Entra ID account whose email matches an existing Scout Console user.
- Confirm that you land in Scout Console as that user.
Rotating the Client Secret
Entra ID client secrets expire. When a secret expires, Microsoft sign-in stops working for your organization.
Before the expiry date:
- Create a new client secret as described in Step 2.
- Send the new value to base14 Support.
- After base14 confirms the update, delete the old secret in Entra ID.
Set a reminder for the expiry date when you create each secret.
Troubleshooting
"AADSTS50011: The redirect URI ... does not match"
The redirect URI in your application does not exactly match the one Scout Console sends. Return to Authentication in your application and confirm the Web redirect URI matches the value base14 provided, character for character.
"AADSTS7000215: Invalid client secret provided"
The client secret base14 has on file is wrong or has expired. Common causes:
- The Secret ID was sent instead of the Value.
- The secret was truncated when copied.
- The secret has passed its expiry date.
Create a new secret and send it to base14 Support.
"AADSTS50020: User account ... does not exist in tenant"
The user is signing in with an account from a different Entra ID tenant. Sign-in is restricted to your tenant. The user must sign in with their account in your directory.
Sign-in succeeds at Microsoft but Scout Console shows an error
No Scout Console account matches the user's email address. Single sign-on does not create accounts. Invite the user in Scout Console, or provision them with Entra ID Provisioning. Then confirm that the email address on their Scout Console account matches their email in Entra ID.
Getting Help
If sign-in still fails after working through the steps above, contact the base14 team with:
- The full error text, including any
AADSTScode. - The email address of an affected user.
- The Application (client) ID of your app registration. Do not include the client secret.
Related Guides
- Entra ID Provisioning - Create and disable Scout Console users automatically from Entra ID
- User Management and Access Control - Assign roles and manage users in Scout Console