Skip to demo content
Step 1 of 7: User clicks Sign in with Microsoft
← All demos

Enterprise OIDC with Entra ID

1. User clicks Sign in with Microsoft

User navigates to the app dashboard or clicks 'Sign in with Microsoft'. The app finds no session, generates PKCE parameters, state, and nonce, then redirects to the authorization endpoint of Contoso's tenant -- not a global Microsoft endpoint. The tenant is part of the URL.

What the user sees

https://secrets.example.com/dashboard
Demo simulation — do not enter real credentials
Redirecting to login...

What's happening (HTTP)

  1. REQUEST Browser → App
    GET https://secrets.example.com/dashboard
    Cookie: (none)
    No session cookie present
  2. INTERNAL App → App
    Generate OAuth2 parameters
    Generate code_verifier, compute code_challenge = BASE64URL(SHA256(code_verifier)), generate random state and nonce. Store all three server-side keyed by session.
  3. RESPONSE App → Browser
    302 Found
    Location: https://login.microsoftonline.com/contoso.onmicrosoft.com/oauth2/v2.0/authorize?
    client_id=8f3a2b1c-9d4e-4f5a-b6c7-1a2b3c4d5e6f
    &redirect_uri=https://secrets.example.com/auth/callback
    &response_type=code
    &response_mode=query
    &scope=openid profile email
    &state=xYz9Kp2mN7qR4sT1
    &nonce=aB3cD5eF7gH9iJ1k
    &code_challenge=E9Melhoa2OwvFrEMTJguCHaoeK1t8URWbuGJSstw-cM
    &code_challenge_method=S256
    Redirect to the tenant-scoped authorize endpoint with PKCE challenge, state, and nonce. offline_access is deliberately absent: signing in needs no refresh token.

Legend

Browser request
Server response
Server-to-server
Internal
← All demos
An educational demo, not a reference implementation v0.3.0