> For the complete documentation index, see [llms.txt](https://docs.lithnet.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.lithnet.io/ams/v3.0/configuration/setting-up-authentication/setting-up-authentication-with-azure-ad.md).

# Setting up authentication with Microsoft Entra ID

The following guide will assist you in configuring your application to use Microsoft Entra for authentication.

## Part 1: Configure a new application in Entra ID

Follow the steps in [Creating an Entra app for Access Manager](/ams/v3.0/help-and-support/advanced-help-topics/creating-an-entra-app.md) to create the app registration for Access Manager. Take note of the tenant ID, client ID and secret created here as they will be used in the next step.

Ensure that the appropriate API permissions have been granted for the `User authentication using OpenID Connect` scenario.

## Part 2: Configure Lithnet Access Manager

1. Open the Lithnet Access Manager Service Configuration Tool
2. Select the `App configuration\User Authentication` page
3. Select `Open ID Connect` as the authentication provider
4. Use the `application id` obtained from the Entra ID setup process as the `client ID` value
5. Specify the `client secret` obtained from the Entra ID setup process.
6. Set the authority as appropriate for your tenant (e.g. for `lithnet.io` it would be `https://login.microsoftonline.com/lithnet.io`)

![!](https://1500666603-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FzPrDxVWpXXpSNTpkDVnR%2Fuploads%2Fgit-blob-60f2ede9ef0839205051b1301b0668aeedc8fe52%2Fui-page-authentication-oidc-azure.png?alt=media)

## Part 3: Enable multifactor authentication

For further security, you can set up a conditional access policy to require multifactor authentication for the app

## Alternative claim mapping

AMS maps `upn`, `sid` and `onprem_sid` claims automatically if they are found in the response from the IDP.

If you need to use an attribute other than those, you can configure a custom claim mapping using [PowerShell](/ams/v3.0/help-and-support/powershellmodule/add-amsidpclaimmapping.md)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.lithnet.io/ams/v3.0/configuration/setting-up-authentication/setting-up-authentication-with-azure-ad.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
