What QX offers
- A person signs in to QX with the SSO login in Entra ID, through the OIDC protocol. QX never sees the password.
- Entra ID creates, updates and deactivates the users of QX through user provisioning, with the SCIM 2.0 protocol. QX receives users only. The groups stay in Entra ID.
- QX recognizes the person by the
oidclaim, the identifier of the person in the tenant. - By default, the role comes from QX: a new person signs in as an operator, and the owner changes the role in Users. If the company prefers, the owner group in Entra ID sets the role at each login.
- QX does not link users by e-mail and does not create a user at the first login with Entra ID, because the Entra ID token does not confirm the e-mail.
- The owner turns on required SSO for the whole organization. With the rule on, nobody in the organization signs in with a password, including the owner.
- When the organization requires two-step verification, the SSO connection chooses where the person proves the second factor: in Entra ID or in the QX authenticator app.
- A session that starts with the SSO login expires at the time that the owner chooses, from 1 to 8 hours after the login. It does not extend.
- The owner removes the SSO connection to change the tenant or the app registration, and then configures a new one.
The order of the work
Do the steps in this order:- The IT team creates the app registration in Entra ID.
- The IT team adds the optional claims and the groups claim.
- The owner configures the SSO connection in QX.
- The IT team stores the QX login URL in the app.
- The owner issues the provisioning key.
- The IT team activates user provisioning in Entra ID.
- The owner does the login test.
- The owner enables SSO login.
- The owner turns on required SSO.
- The Entra ID user of the owner has the same e-mail as the QX user of the owner.
- When the owner group sets the role, the owner is in that group.
The QX addresses
The owner sees the addresses in Settings › SSO, in the box Addresses for the identity provider. Each address has a Copy button.
The login URL shows only after the owner saves the SSO connection. The other two addresses are these:
1. Create the app registration in Entra ID
The names of the menus and fields in this step: not checked against an official source.- In the Microsoft Entra admin center, open App registrations and click New registration.
- In Name, type
QX. - In Supported account types, select the option for one tenant only: Accounts in this organizational directory only.
- In Redirect URI, select the Web platform and paste the QX redirect URI.
- Click Register.
- On the Overview page, copy the Application (client) ID and the Directory (tenant) ID.
- In Certificates & secrets, create a client secret and copy its value.
2. Add the optional claims and the groups claim
The Entra ID v2 ID token carries neitherauth_time nor amr by default. Both are optional claims. The names of the menus in this step: not checked against an official source.
- In the app registration, open Token configuration.
- Click Add optional claim, select the ID token and select
auth_timeandemail. - For two-step verification Through Microsoft Entra ID, also select
amr. - Only when the owner group sets the role: click Add groups claim and keep the group ID as the value.
auth_time claim is required. QX asks Entra ID for a new login in the login test, the identity confirmation and the setup of the authenticator app, with prompt=login and max_age=0. Without auth_time, the login test fails, the setup of the authenticator app fails, and the identity confirmation asks for the code of the QX authenticator app. Entra ID support for max_age: not checked against an official source.
The email claim is also required. QX refuses a token without email. Entra ID sends email only when the person has an e-mail address in Entra ID.
The groups claim carries the object ID of each group. So the owner group is the Object ID of the group. With the option Groups assigned to the application, the token carries only the groups assigned to the app, with no nested groups. Above 200 groups, the token replaces the groups with a reference to another address. When the owner group sets the role, QX refuses that login with the groups message. Use Groups assigned to the application to stay under this limit.
3. Configure the SSO connection in QX
The owner does these steps in QX:- Open Settings › SSO and click Configure SSO connection.
- Select Microsoft Entra ID and click Continue.
- In Identity provider address, type
https://login.microsoftonline.com/<tenant ID>/v2.0, with the Directory (tenant) ID of step 1. QX refusescommon,organizations,consumersand the tenant of the personal Microsoft accounts (9188040d-6c67-4c5b-b112-36a304b66dad) in place of the tenant ID. QX stores the tenant ID in lower case. The address stays fixed after the owner saves the connection. - In Client ID and Client secret, paste the values of step 1.
- In Client authentication, keep Basic (client_secret_basic). Entra ID also accepts Post (client_secret_post).
- In Role of the people, select Set in QX or Set by the owner group. With the second option, type in Owner group the Object ID of the group.
- In Two-step verification, select Through Microsoft Entra ID or Through the QX authenticator app. The section Two-step verification of this guide explains the options.
- In SSO session duration, select from 1 to 8 hours. The default is 8 hours.
- Click Save SSO connection. If the login of the owner is older than 15 minutes, QX asks for the password.
4. Store the login URL in Entra ID
The My Apps portal opens the app at theloginUrl of the service principal. Store the QX login URL in this value. The portal field that stores the loginUrl: not checked against an official source.
Without this value, the person opens QX through the login URL, kept in the bookmarks of the browser.
5. Issue the provisioning key
The owner does these steps in QX:- In Settings › SSO, click Manage provisioning keys.
- Click Issue provisioning key, then Issue key. If the login of the owner is older than 15 minutes, QX asks for the password.
- Copy the key. QX shows the key only once. The key starts with
qxp_. - Give the key to the IT team through a safe channel. Do not send the key by e-mail or by message.
- After the IT team pastes the key, check I pasted the key into the identity provider and click Back to the keys.
6. Activate user provisioning in Entra ID
The names of the menus in this step: not checked against an official source.- Open the QX enterprise application, then Provisioning. Select the automatic provisioning.
- In Tenant URL, paste the user provisioning base URL, with no slash at the end.
- In Secret Token, paste the provisioning key.
- Click Test Connection. Entra ID looks for a user that does not exist, and QX answers with an empty list.
- Save the configuration.
- In the attribute mappings of the users, change the source of
externalId: frommailNickname, the default, toobjectId. - Turn off the groups mapping. Entra ID lets you turn off this mapping only after the provisioning job exists. QX does not receive groups.
- Assign to the enterprise application the people who use QX.
- Turn on provisioning.
externalId carries the objectId of the person. QX links the person to the login when the oid of the token equals the externalId. The objectId of the person has the same value as the oid (not checked against an official source). With the default mailNickname, the SSO login does not find the person.
7. Do the login test
- In Settings › SSO, the owner clicks Test login.
- QX opens Entra ID and asks for a new login. The owner signs in with their own user.
- QX shows “The login test passed. The SSO connection is verified.”
- The token carries
auth_time. Without it, the test fails with “The identity provider did not send the time of the login (auth_time).” - When the owner group sets the role, the owner is in the owner group.
- When the organization requires two-step verification through Entra ID, the owner signs in to Entra ID with the second factor.
8. Enable SSO login
- In Settings › SSO, the owner clicks Enable SSO login. If the login of the owner is older than 15 minutes, QX asks for the password.
- A person who is not an owner opens QX from the My Apps portal, or through the login URL, and checks the login.
9. Turn on required SSO
- In Settings › SSO, the owner clicks Turn on required SSO.
- The owner reads the warning and clicks Turn on required SSO again. If the login of the owner is older than 15 minutes, the warning asks for the password.
Two-step verification
The option of the SSO connection applies when the organization requires two-step verification. A change of the option ends the sessions that started with SSO.- Through Microsoft Entra ID: QX accepts the SSO login only when the optional
amrclaim confirms the second factor. Theamrmust holdmfa, or a possession method (otp,hwk,swk,sms,telorsc) together with the password, a PIN or biometrics. Entra ID putsmfain theamronly after a multi-factor authentication. Without the optionalamrclaim, QX refuses each login. - Through the QX authenticator app: after the login in Entra ID, the person types the code of the QX authenticator app. At the first login, the person sets up the app. The person has 15 minutes to finish. After that time, the person signs in again through Entra ID.
auth_time. To change the app, the person asks another owner or QX support for a reset of the second factor.
When the SSO login is older than 15 minutes, a sensitive act asks for the identity confirmation. QX asks for a new login in Entra ID. When the token carries no auth_time, QX asks for the code of the authenticator app. The confirmation by code needs an app that the person already set up.
Session duration
The owner chooses the SSO session duration in Edit SSO connection, from 1 to 8 hours. After that time, the person signs in again through Entra ID. A shorter time also shortens the open sessions, counted from the login. A longer time applies to the next logins only. The identity confirmation does not change the time.How QX treats each person
- User provisioning creates the user of a new person. The Users screen shows “Waiting for SSO login”. The first SSO login activates the user. A new user is an operator.
- When the person already has a QX user, user provisioning links that user by the e-mail, in the same organization. The user keeps the history.
- QX recognizes the person by the
oid. The Entra IDsubchanges from one app to another, and a new app registration changes thesubof each person. - At each login, QX checks that the
tidclaim is the tenant of the identity provider address. - The token carries the e-mail with the
emailscope. Microsoft says that this value can change and has no verification. So QX does not link or create a user by e-mail with Entra ID. - When QX sets the role, the owner changes the role in Users, and the SSO login does not change the role.
- When the owner group sets the role, the role changes at the next SSO login after a group change. A person in the group signs in as an owner, and the other people sign in as operators. The role is read-only in Users.
- To deactivate a person, remove the person from the assignment of the app or disable the person in Entra ID. Entra ID sends
active=false, and QX deactivates the user. All sessions of the user end at the same moment. After you remove the person from the assignment, Entra ID stops managing the user and never sends the deletion. - Entra ID sends the deletion of a person only after the hard delete, 30 days after the soft delete or when an administrator deletes the person permanently. QX turns off the access of the user and stops showing the user to user provisioning. The user and its history stay in QX.
- To reactivate a person, assign the person to the app again. The user goes back to “Waiting for SSO login” and signs in again at the next SSO login.
- The name and the e-mail of the person change only in Entra ID. The owner sees the user in QX, but does not change them.
- A new e-mail in Entra ID does not block the SSO login. The user page shows the Entra ID e-mail when it differs from the e-mail in QX.
Replace the provisioning key
The SSO connection keeps up to 2 active keys. With two keys, Entra ID switches to the new key with no gap in user provisioning.- The owner issues a new key, as in step 5. In a session that started with SSO, when the login is older than 15 minutes, QX asks for the identity confirmation.
- The IT team opens Provisioning in the enterprise application, pastes the new key into Secret Token, clicks Test Connection and saves.
- The owner checks the Last use column of the new key.
- The owner clicks Revoke on the old key, then Revoke key.
Replace the client secret
- In the app registration, the IT team creates a new client secret in Certificates & secrets (not checked against an official source).
- The owner opens Edit SSO connection, pastes the new secret into Client secret and clicks Save SSO connection.
When Entra ID is down
With required SSO on, nobody signs in to QX while Entra ID is down. The open sessions continue until they expire.- If an owner still has an open session, the owner clicks Turn off required SSO in Settings › SSO. QX asks for no confirmation, so this works while Entra ID is down.
- If no owner has an open session, ask QX support. Support turns off required SSO and writes the reason in the audit log.
- A person with no password clicks Forgot your password? on the login page and sets a password.
- When Entra ID is back, the owner clicks Turn on required SSO.
Remove the SSO connection
To change the tenant or the app registration, the owner removes the SSO connection and configures a new one. The new connection has another login URL.- In Settings › SSO, the owner clicks Remove connection. If the login of the owner is older than 15 minutes, QX asks for the password or for the identity confirmation.
- The owner reads the warning and clicks Remove connection again.
- The sessions that started with SSO end, including the session of the owner.
- SSO login and required SSO stop. People sign in with a password.
- QX deletes the external identities and the provisioning keys. Entra ID stops creating and deactivating users in QX. Turn off provisioning in the old enterprise application.
- The users stay in QX. A person who only signed in with SSO creates a password with Forgot your password?, on the login page.
Refusal messages
Sources
- Microsoft, ID token claims reference.
- Microsoft, Optional claims reference.
- Microsoft, OpenID Connect on the Microsoft identity platform.
- Microsoft, Microsoft identity platform and OAuth 2.0 authorization code flow.
- Microsoft, Configure group claims.
- Microsoft Graph, servicePrincipal resource type.
- Microsoft, Tutorial: Develop and plan provisioning for a SCIM endpoint.
- Microsoft, Known issues and resolutions with SCIM 2.0 protocol compliance.
- Microsoft, How application provisioning works.
- Microsoft, Customize application attributes.
- Microsoft, OpenID Connect discovery document.