• Task
  • Version ยท 6.0
  • Manage

Configure single sign-on with Microsoft Entra

Last updated: September 29, 2026

Authenticate a workspace against your own Microsoft Entra tenant, using either OpenID Connect or SAML 2.0, and test it before you turn it on.

Before you begin

  • You must be a member of the Administrators group. The account that set up the server is a member.

  • You need permission to register an application in your Microsoft Entra tenant.

  • Decide which protocol to use. OpenID Connect is the recommended default for most Entra tenants. Use SAML 2.0 where your enterprise app library is templated for SAML, or where security policy requires it.

  • One protocol is active per workspace at a time.

  • Plan how each person gets their groups in Liquibase Secure, which does not use the groups your IT team manages in Microsoft Entra. Invite people into groups before they first sign in, or assign groups afterward to anyone who arrives in the Pending group.

Procedure

1

Open Single Sign-On

Go to Administer and select Single Sign-On.

The page authenticates this workspace against your organization's Microsoft Entra tenant.

The Single Sign-On page before a provider is configured
2

Choose the protocol

Under Protocol, select OIDC (OpenID Connect) or SAML 2.0. One protocol is active per workspace.

The Protocol choice between OIDC and SAML 2.0
3

Identify the provider

Both protocols share two fields:

  • Display name is what your users see. The sign-in button reads Continue with followed by this name, so use something they recognize, such as Example Corp Microsoft.

  • Email domain routes users signing in with an address at that domain to your tenant. Enter a bare domain such as example.com.

The Display name and Email domain fields
4

Supply the protocol details

OpenID Connect

Fill in the values from your Entra app registration:

  • Directory (tenant) ID

  • Application (client) ID

  • Client secret

Be sure to:

  • Use the GUIDs from Entra for the tenant and application IDs. Both are validated as GUIDs.

SAML 2.0

Under Import IDP configuration, supply your identity provider's federation metadata in whichever form you have it:

  • Upload metadata XML: drop your IDP federation metadata XML onto the import area, or select Browse files. The entity ID, sign-on URL, and signing certificate are read automatically.

  • Metadata URL: give the metadata URL, which is fetched and parsed when you save.

  • Manual: fill in the fields directly: IDP entity ID (issuer), Single sign-on URL, Signing certificate (X.509), and Service provider identifier (audience).

The signing certificate is encrypted at rest. Assertions are accepted only if the signature validates against it.

The OIDC provider configuration form
The SAML 2.0 provider configuration form
5

Save the configuration

Select Save configuration.

After you save, the page shows what to register in Entra: the redirect URI for OpenID Connect, or the service provider metadata for SAML 2.0.

The saved provider configuration with the issuer and redirect URI
6

Register Liquibase in Entra

OpenID Connect

Select Copy next to the redirect URI shown on the page, and add it to your Entra app registration.

SAML 2.0

Download the service provider metadata XML from the page and register those values in your Entra SAML enterprise app.

The redirect URI to register in Entra, with Copy and Setup guide buttons
7

Test the configuration

Select Verify configuration to confirm the tenant discovery endpoint is reachable and the client credentials are valid. Then select Run test sign-in to run a real sign-in against your tenant in a new window.

The test waits for you to finish signing in. It reports pass, warn, or fail, and each failure states what was expected against what was received. The test never creates a real session.

Select Diagnostics to download the results.

Be sure to:

  • Re-run the test after any change. A test taken before an edit is marked stale, and the page says the configuration changed after the test.

The Verify configuration and Test sign-in controls
8

Enable single sign-on

Turn on the Enable Single Sign-On toggle.

Your sign-in button then appears on the sign-in page. Email and password sign-in stays available. Users you invited join the groups named in their invitation when they first sign in with single sign-on. Anyone else lands in the Pending group with no permissions until an administrator assigns them a group.

Liquibase Secure does not use the groups your IT team manages in Microsoft Entra, such as a Database Administrators group. Access comes only from groups in Liquibase Secure, either named in an invitation or assigned by an administrator.

The Enable Single Sign-On toggle

Rotate an expiring credential

Credentials expire, and the page rotates whichever one the active protocol depends on.

  • SAML 2.0: paste the replacement signing certificate. Sign-in keeps working with the current certificate until you save.

  • OpenID Connect: under Rotate client secret, paste the replacement into New client secret and select Rotate secret. Sign-in keeps working with the current secret until you save.

The Rotate client secret section

Disable or remove a provider

To disable a provider, turn off the Enable Single Sign-On toggle. To remove it, select Remove under Remove configuration, then select Yes, remove configuration. Removing and registering again is also how you switch protocol or move to a different tenant.

Turning the provider off, or removing its configuration, signs out every user who authenticated through it. The sign-out takes effect on their next request rather than when their session would have expired.

Password users and users of a different provider are unaffected.

Note: This makes disabling a provider useful for offboarding or breach response, and disruptive during routine maintenance. Disabling a provider to change a setting logs that provider's users out.

The Remove configuration confirmation