SSO Entra ID Configuration
Use Microsoft Entra ID as an OpenID Connect identity provider for MetaDefender Software Supply Chain. Users sign in with their corporate account, and MetaDefender grants them the Administrator or Read-only role based on the application role Entra ID sends.
For general SSO behavior, SAML configuration, and additional troubleshooting, see Single Sign-On.
Before you start
HTTPS is required. Entra ID rejects redirect URIs that use plain HTTP, except
http://localhost, and the MetaDefender session cookie is only sent over HTTPS. Enable HTTPS first. See Configuring HTTPS.Open MetaDefender at the address your users will use. MetaDefender takes the redirect URI from the browser address you are on when you save the SSO settings. Save from
https://mdssc.example.com, and the redirect URI becomeshttps://mdssc.example.com/callback. Do not save fromlocalhostor an IP address unless that is the address users sign in from.You need the Administrator role to change SSO settings. Administrators who signed in through SSO can view the page but cannot save it.
Decide the two application roles. Create one role for administrators and one for read-only users. Role values are matched exactly and are case-sensitive.
Register MetaDefender in Entra ID
In the Entra admin center, create an App registration for MetaDefender.
Under Authentication, add a Web platform with the redirect URI
https://<your-mdssc-address>/callback.Under Authentication, enable ID tokens in the implicit grant and hybrid flows section. MetaDefender requests
code id_token.Under Certificates & secrets, create a client secret. Copy the value now. Entra shows it only once.
Under App roles, create two roles. The role value is what MetaDefender matches, for example
MDSSC-AdminsandMDSSC-ReadOnly.In Enterprise applications, open the application and assign users or groups to the two roles.
Note the Application (client) ID and the Directory (tenant) ID. You need both when you configure MetaDefender.
Configure SSO in MetaDefender
Sign in as an Administrator and go to Settings > SSO Configuration.
Turn on Enable Single Sign-On.
Set SSO Type to OpenID Connect.
Set Identity Provider to Microsoft Entra ID.
Enter the OpenID Connect settings:
Field
Value
Authority URL
https://login.microsoftonline.com/<tenant-id>/v2.0, replacing<tenant-id>with the Directory (tenant) IDClient ID
The Application (client) ID of the app registration
Client Secret
The client secret value
Under Role Mapping, enter the two application role values:
Field
Value
Administrator group
The application role whose members get the Administrator role
Read-only group
The application role whose members get the Read-only role
Click Save.
The Save button stays disabled until you change a value.
Enter the role value only, for example MDSSC-Admins. The two values must differ, and matching is case-sensitive. mdssc-admins does not match MDSSC-Admins.
If you leave a field empty, MetaDefender uses SsoAdministrator for administrators and SsoReadOnlyAdministrator for read-only users. You can use those values for the Entra ID application roles and leave both fields empty.
Client secret storage
MetaDefender stores the client secret encrypted and never shows it again. The field shows Stored when a value exists.
To save any later change on the SSO Configuration page, enter the Client Secret again. A save with an empty secret is rejected.
Assign users and groups
In the Entra admin center, open the MetaDefender enterprise application and assign each user or group to either the administrator or read-only application role.
MetaDefender resolves the role at every sign-in. When you assign a user to the other role in Entra ID, the change applies the next time the user signs in.
If Entra ID does not send an application role that matches one of the two Role Mapping entries, sign-in fails and MetaDefender does not create the account. Assign the user to one of the two application roles and sign in again.
Users created through SSO appear on the Users page like local users. See User management.
Troubleshooting
Symptom | Cause | Fix |
|---|---|---|
Sign In with SSO is not on the login page | SSO is disabled | Turn on Enable Single Sign-On and save |
Entra shows error AADSTS50011, redirect URI mismatch | The redirect URI registered in Entra differs from | Register the exact URI, or open MetaDefender at the registered address and save the SSO settings again |
After signing in at Entra ID, MetaDefender shows Tenant Configuration service error | The sign-in took longer than 15 minutes, for example during multi-factor registration, or the browser blocked the sign-in cookies | Start the sign-in again. Complete multi-factor registration before signing in to MetaDefender |
The user signs in but every action says the role does not allow it | The user's application role matched the Read-only group | Assign the user to the administrator application role in Entra ID and sign in again |
The user signs in at Entra ID, but MetaDefender rejects the sign-in and no account appears on the Users page | The user has neither application role, or the role value differs in case from the Role Mapping entry | Compare the role value in Entra ID with the Role Mapping fields, character by character. Assign the user to the role and sign in again |
Save fails with Use a different group for each role | Both Role Mapping fields hold the same value | Enter two different application role values |
Save fails with Enter a valid http or https URL | The Authority URL is malformed | Enter the full URL including the scheme |