Skip to main content

Configure OIDC SSO between DigiCert and Microsoft Entra ID

Use this procedure to configure single sign-on (SSO) between your DigiCert​​®​​ account and Microsoft Entra ID using OpenID Connect (OIDC).

To set up this sign in method, you need to switch between two tabs, DigiCert and Microsoft Entra, to exchange URLs and other information.

Note

For more information, refer to Entra Help Center.

Before you begin

You need elevated privileges in DigiCert account and Microsoft Entra to configure SSO:

  • Account admin user group required in DigiCert account.

    How do I check my user group?

  • Application Administrator or equivalent role required in Entra.

Access DigiCert's OIDC configuration page:

  1. In the DigiCert​​®​​ account menu, select the Accounts icon > sign in methods.

  2. Select Single sign-on with OIDC.

  3. Keep this tab open.

In another tab, create an OIDC app for your DigiCert account:

  1. Sign in to your Microsoft Entra admin center.

  2. Go to Devices > App registrations.

  3. Select New registration.

  4. Enter DigiCert account in the Name field.

  5. In the Supported account types, keep the default Accounts in this organizational directory only.

  6. In the Redirect URI section, select Web as the platform.

  7. Leave the Redirect URI field blank for now.

  8. Select Register.

  9. Keep this tab open.

Provide the following Entra information to DigiCert:

  1. Copy the Application (client) ID field and enter it in the following fields in DigiCert account:

    1. Client ID

    2. ID token audience

  2. In the Client credentials field, select Add a certificate or secret.

    1. On the Client secrets tab, select + New client secret.

    2. In the Description field, enter a name.

    3. In the Expires field, select a timeframe.

    4. Select Add.

  3. Copy the Value of the client secret you created and enter it into the Client secret field in DigiCert account.

  4. In the application menu, select Overview > Endpoints.

    1. Copy the OpenID Connect metadata document URL and enter it into the Provider URL in DigiCert account.

      Example: https://login.microsoftonline.com/a0b1c3-.../v2.0/.well-known/openid-configuration

  5. In the left pane, select Overview.

  6. Keep this tab open.

Provide DigiCert information to Entra:

  1. In the Redirect URIs field, select Add a Redirect URI.

    1. In the Platform configurations section, select + Add a platform.

    2. Select Web.

    3. In the Configure Web page:

    4. Enter the Redirect URI from DigiCert account into the Redirect URIs field.

    5. Enter the Logout URL from DigiCert account into the Front-channel logout URL field.

    6. Select Configure.

  2. On the Platform configurations page, in the Web Redirect URIs section, select Add URI.

    1. Enter the Login URL from DigiCert account.

    2. Select Save.

  3. In Entra's application menu, select Overview.

  4. In the Application ID URI field, select Add an Application ID URI.

    1. In the Application ID URI field, select Add.

    2. Select Save.

  1. In the Enable/Disable SSO with SAML section, switch to enable SSO.

  2. Select Save configuration.

Ensure that all users in your DigiCert account are assigned to the SAML application in Microsoft Entra admin center:

  1. Go to Manage > Enterprise applications.

  2. Select the DigiCert account application you created.

  3. From the application's overview, select Assign users and groups.

  4. Select +Add user/group.

Attempt to sign in to DigiCert account, using your Entra credentials:

  1. Sign in to DigiCert​​®​​ account.

  2. Provide your Entra username.

  3. Select Sign in with your company's SSO.

    Tip

    When 2FA is enabled, DigiCert skips the OTP prompt if you have already provided an OTP to your IdP.

    • Your SAML app is configured correctly if:

      • You use 2FA to access your IdP, and you're automatically signed in to your DigiCert account.

      • You don't use 2FA to access your IdP, you're redirected to your DigiCert account and asked to finish two-factor authentication (2FA).

    • If you aren't able to sign in with SSO, compare your app settings to these instructions or contact DigiCert Support for assistance.