External authentication provider

Prev Next

You can use OneSpan User Websites as an external authentication method for identity management platforms that support OpenID Connect (OIDC), such as Microsoft Entra ID. This allows users to select DIGIPASS authenticators as an external provider to meet multi-factor authentication requirements.

External authentication method process (Microsoft Entra ID)

  1. A user attempt to sign in to an application or resource that is protected by Microsoft Entra ID with a first factor, usually a static password.

  2. Microsoft Entra ID determines if another authentication factor is required and redirects the user to the external authentication provider, in this case, OneSpan User Websites.

  3. The user performs the actions required for authentication, for example, typing the one-time password generated by the DIGIPASS authenticator.

  4. OneSpan User Websites validates the user credentials and OTP (via OneSpan Authentication Server) and redirects the user back to Microsoft Entra ID with a valid identity token.

  5. Microsoft Entra ID validates the identity token against its requirements and completes the user sign-in request.