Use Microsoft Entra ID (Azure AD) as an identity provider
You can use Microsoft Entra ID (Azure AD) as an identity provider.
You can use your Microsoft Entra ID (Azure AD) instance to verify the identities of your administrators and users when they sign in to Sophos Central products. You need to add Microsoft Entra ID (Azure AD) as an identity provider to do this.
If you want to use Microsoft Entra ID (Azure AD) as an identity provider, find your Tenant ID for your Microsoft Entra ID (Azure AD) instance. We need this to verify your users and administrators.
Requirements
You must verify a domain first. See Verify a federated domain.
You must be a Super Admin.
Warning
If you want to use federated sign-in as your sign-in option, you must ensure that all your administrators and users are assigned to a domain and have an identity provider.
You must do the following before you can add Microsoft Entra ID (Azure AD) as an identity provider:
- Ensure you have a Microsoft Entra ID (Azure AD) account with Microsoft. Microsoft Entra ID (Azure AD) is Microsoft’s cloud-based identity and access management service.
- Get consent and authorization from your Microsoft Entra ID (Azure AD) admin to use your organization's Microsoft Entra ID (Azure AD) with Sophos Central.
- Ensure you have a Sophos Central account that matches your Microsoft Entra ID (Azure AD) account (the emails must match).
Microsoft Entra ID (Azure AD) consent
A Microsoft Entra ID (Azure AD) administrator must grant consent (permission) to use the credentials stored in your organization's Microsoft Entra ID (Azure AD) tenant to sign in to Sophos Central.
This consent applies to all Sophos Central products.
When a Microsoft Entra ID (Azure AD) administrator gives consent, it means your Microsoft Entra ID (Azure AD) tenant trusts Sophos Central, and you can add Microsoft Entra ID (Azure AD) as your identity provider.
For help with granting consent in Microsoft Entra ID (Azure AD), see Understanding Microsoft Entra ID (Azure AD) application consent experiences.
Find your Tenant ID
You need to know the Tenant ID before you can add Microsoft Entra ID (Azure AD) as an identity provider.
To find your Tenant ID, do as follows:
- From the Microsoft Azure portal menu, select Microsoft Entra ID. The Overview page appears.
-
In the Basic information section, find your Tenant ID. This is the ID for your tenant domain.
You'll need to enter it when you set up Microsoft Entra ID (Azure AD) as an identity provider.
To add Microsoft Entra ID (Azure AD) as an identity provider, see the following topics:
- If your users' email address and UPN are the same, see Add an identity provider.
- If your users' email address and UPN are different, see Configure Microsoft Entra ID (Azure AD) to allow users to sign in using UPN.