Integration
Microsoft Entra ID single sign-on for DocumentMS
DocumentMS authenticates against Microsoft Entra ID over OIDC. Directory groups map to DocumentMS roles, which means a leaver removed from a group loses document access without anyone touching DocumentMS, and access reviews happen where the rest of your identity governance already lives.
What this connection does
DocumentMS authenticates against Microsoft Entra ID over OIDC, with directory groups mapped to DocumentMS roles. Users sign in with the account they already have, and role assignment is evaluated on each sign-in from the group claims in the token.
The convenience is secondary. The control is that a leaver disabled in the directory cannot authenticate to DocumentMS — which removes the gap between an HR offboarding process and a document system nobody remembered to update. Access reviews then happen where the rest of your identity governance already happens.
What you need on your side
- A Microsoft Entra ID tenant and an administrator able to create an application registration
- Security groups that correspond to the DocumentMS roles you want — create them before mapping, rather than mapping to groups that exist for another purpose
- Group claims enabled in the token configuration
Setting it up
Step 1: Register the application
Create an app registration with the DocumentMS redirect URI and note the client and tenant identifiers.
Step 2: Configure claims
Enable group claims so role assignment can be driven from directory membership.
Step 3: Map groups to roles
Map each security group to a DocumentMS role. Start restrictive and widen; the reverse is harder to unwind.
Step 4: Verify with one user
Sign in as a test user, confirm the expected role, then disable the account and confirm access is refused.
Limits worth knowing before you rely on it
- Role changes take effect at the next sign-in rather than immediately, because roles are evaluated from the token — for immediate revocation, disable the account rather than changing groups
- Users in a very large number of groups may have group claims omitted from the token by Entra ID; use application roles or group filtering if you hit that limit
- SCIM 2.0 provisioning is supported alongside OIDC, so joiners, movers and leavers flow from Entra ID without a manual step — authentication and account lifecycle are handled separately, and large tenants need both
最終レビュー: 2026-09-01