How to add a Microsoft Entra SSO to your CMS

Connecting Microsoft Entra ID to Keycloak — Two-Party Setup Guide

Client — manages the Microsoft Entra ID (Azure) environment CultureSuite — manages the Keycloak environment


Step 1: Request the Redirect URI from CultureSuite


Step 2: Register the Application in Microsoft Entra ID

The Client sets up the OAuth credentials using the URI received from CultureSuite (see screenshots of substeps at the bottom of this article).

  1. Go to the Azure Portal and navigate to Microsoft Entra ID.
  1. Go to App Registrations → New Registration.
  1. Fill in the following:
      • Name: e.g. Keycloak-Integration
      • Supported account types: Accounts in this organizational directory only
      • Redirect URI: paste the URI received from CultureSuite in step 1
  1. Click Register.
  1. Navigate to Certificates & Secrets → New client secret, create a secret and copy the value immediately.
  1. Under API Permissions, add the following Microsoft Graph permissions and click Grant admin consent:
      • openid
      • email
      • profile
      • User.Read
  1. Copy the Application (Client) ID from the app's Overview page.
  1. From the Azure Portal overview, also copy the Tenant ID.
📤 Client sends to CultureSuite: the Client ID, the Client Secret, and the Tenant ID.

Step 3: CultureSuite configures the Entra ID Identity Provider in Keycloak


Step 4: Verify the Integration

  1. Open the CMS login page for the configured realm.
  1. Confirm that Login with Microsoft Entra ID appears as an option.
  1. The first time you log in, you are shown a message. This means your log in was succesfull, but you don’t have a CMS role yet (admin or user).
    1. If you are the first (admin), please contact CultureSuite so we can set your admin role.
    2. After that, you can configure roles for all your colleagues via the CMS users module after their first login.
The new SSO button
The new SSO button
The message displayed the first time anyone logs in via SSO (see step 3 above)
The message displayed the first time anyone logs in via SSO (see step 3 above)
👉

The SSO button can replace the familiar username + password fields. So make sure all your CMS users have a Microsoft account to access the new SSO.

If you still want to be able to also log in the “classic” way via a password and email, we can keep that option available too.


Information Exchange Summary

#
From
To
What
1
CultureSuite
Client
Keycloak Redirect URI
2
Client
CultureSuite
Tenant ID, Client ID & Client Secret

Screenshots

Step 2

Notion image
 

Step 3

Notion image

Step 4

Notion image

Step 5

Notion image
Notion image

Step 6

Notion image
Notion image
Notion image
Notion image
Notion image
Notion image
Did this answer your question?
😞
😐
🤩