Skip to main content

azure-ad

Applies to:
Microsoft Entra IDAzure Active DirectoryOIDCEnterprise SSO

Overview​

This guide walks you through configuring Microsoft Entra ID (formerly Azure Active Directory) as an identity provider for DuoKey Cockpit. Once configured, your users can authenticate to Cockpit using their Microsoft corporate credentials.

Prerequisites

  • Admin access to Microsoft Entra ID (Azure AD)
  • Admin access to DuoKey Cockpit
  • Your Cockpit domain URL (e.g., yourcompany.duokey.cloud)

Part 1: Azure Portal Configuration​

Step 1: Register a New Application​

Navigate to the Microsoft Entra admin center and create a new app registration.

Open App Registrations

Go to Entra ID > App registrations > New registration

Enter Application Name

Enter a descriptive name (e.g., APP_Cockpit-Demo-OIDC)

Select Account Type

Choose Single tenant only as Supported account types

Set Redirect URI

Select Single-page application (SPA) and enter https://{yourCockpitDomain}/account/login

Register

Click Register

Register an application

Note
Replace {yourCockpitDomain} with your actual Cockpit domain, for example: https://cockpit-demo.duokey.cloud/account/login

Step 2: Create a Client Secret​

Navigate to Certificates & Secrets

In the left menu under Manage, click Certificates & secrets

New Client Secret

Click + New client secret

Configure

Enter a description (e.g., cockpit-demo) and select an expiration period

Click Add

Click Add to create the secret

Add a client secret

Warning
Copy the client secret Value immediately after creation — it will be unavailable as soon as you navigate away from this page. If lost, you'll need to create a new secret.

Copy the secret value

Step 3: Configure Token Claims​

Navigate to Manage > Token configuration to add groups and optional claims.

3a. Add Groups Claim​

Add Groups Claim

Click + Add groups claim

Select Security Groups

Check Security groups

Click Add

Click Add

Add groups claim

3b. Add Optional Claims​

Add Optional Claim

Click + Add optional claim > Select Access token type

Select Claims

Check the following claims: auth_time, ctry, email, family_name, ipaddr, fwd, upn

Enable Graph Permission

Click Add, then check Turn on the Microsoft Graph profile permission and click Add again

After adding all claims, the Token configuration page should show:

Token configuration with optional claims

Step 4: Configure API Permissions​

Navigate to Manage > API permissions to add the required Microsoft Graph permissions.

Add Delegated Permission

Click + Add a permission > Microsoft Graph > Delegated permissions > check email > Add permissions

Add Application Permission

Click + Add a permission > Microsoft Graph > Application permissions > check Group.Read.All > Add permissions

Add API permissions

Grant Consent

Click Grant admin consent for {your tenant name}

Confirm

Click Yes in the confirmation dialog

Grant admin consent confirmation

All permissions should now show a green Granted status:

All permissions granted

Important
Ensure all 4 permissions (email, Group.Read.All, profile, User.Read) show "Granted for your tenant" with a green checkmark before proceeding.

Part 2: DuoKey Cockpit Configuration​

Step 1: Access Identity Providers​

Login to Cockpit

Login to DuoKey Cockpit with an administrator account

Navigate to Identity Providers

Go to Administration > Identity Providers

Create New IDP

Click + Create Identity Provider

Step 2: Select Azure AD​

Select Azure AD from the available identity provider options and click Install Now.

Step 3: Configure Azure AD Connection​

Fill in the configuration form with the values from your Azure AD setup:

FieldValue
Integration NameA friendly name (e.g., "Azure IDP DuoKey") — displayed on the login screen
Well Known Configurationhttps://login.microsoftonline.com/{tenant-id}/v2.0/.well-known/openid-configuration
Client IDThe Application (client) ID from Azure AD app registration
Client SecretThe client secret value you copied in Step 2
Scopeopenid, profile, email (pre-filled)
Validate IssuerChecked
Response Typecode, token, id_token (all checked)
Tip
After entering the Well Known Configuration URL, the Authorization endpoint, Token endpoint, and User Info Endpoint will be automatically populated and show Active status.

Add Claims Mapping​

In the Claims Mapping section at the bottom of the form, add the following mapping:

Claim Key:

http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name

Claim Value:

http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress

Click Add to save the mapping.

Step 4: Test and Submit​

Test Connection

Click Test Connection — the status must change to Online

Submit

Click Submit to save the identity provider configuration

Step 5: Enable the Identity Provider​

The IDP is created but needs to be enabled to appear on the tenant login screen.

Open Actions Menu

In the Identity Providers list, click the Actions dropdown on your Azure AD entry

Select Enable

Click Enable (or Disable if already enabled)

Confirm

Click Yes in the confirmation dialog

Once enabled, the Is Enable column will show Yes:

The Azure AD login option will now appear on the Cockpit login screen for your tenant. Users can click it to authenticate with their Microsoft corporate credentials.

Configuration Summary​

ComponentValue
Azure AD PlatformSingle-page application (SPA)
Redirect URIhttps://{yourCockpitDomain}/account/login
Well-known Configurationhttps://login.microsoftonline.com/{tenant-id}/v2.0/.well-known/openid-configuration
Delegated Permissionsemail, profile, User.Read
Application PermissionsGroup.Read.All
Optional Claims (Access)auth_time, ctry, email, family_name, ipaddr, fwd, upn
Groups ClaimSecurity groups (ID, Access, SAML)
Cockpit Scopesopenid, profile, email
Response Typecode, token, id_token
Claims Mappingname → emailaddress
ProtocolOpenID Connect (OIDC)

Troubleshooting​

Important

After making changes to your Azure AD app registration, allow a few minutes for the changes to propagate before testing.