<divrole="region"aria-label="Skip to main content"><aclass="skipToContent_fXgn"href="#__docusaurus_skipToContent_fallback">Skip to main content</a></div><navaria-label="Main"class="navbar navbar--fixed-top"><divclass="navbar__inner"><divclass="navbar__items"><buttonaria-label="Toggle navigation bar"aria-expanded="false"class="navbar__toggle clean-btn"type="button"><svgwidth="30"height="30"viewBox="0 0 30 30"aria-hidden="true"><pathstroke="currentColor"stroke-linecap="round"stroke-miterlimit="10"stroke-width="2"d="M4 7h22M4 15h22M4 23h22"></path></svg></button><aclass="navbar__brand"href="/oauth2-proxy/"><divclass="navbar__logo"><imgsrc="/oauth2-proxy/img/logos/OAuth2_Proxy_icon.svg"alt="OAuth2 Proxy"class="themedImage_ToTc themedImage--light_HNdA"><imgsrc="/oauth2-proxy/img/logos/OAuth2_Proxy_icon.svg"alt="OAuth2 Proxy"class="themedImage_ToTc themedImage--dark_i4oU"></div><bclass="navbar__title text--truncate">OAuth2 Proxy</b></a><aaria-current="page"class="navbar__item navbar__link navbar__link--active"href="/oauth2-proxy/docs/">Docs</a></div><divclass="navbar__items navbar__items--right"><divclass="navbar__item dropdown dropdown--hoverable dropdown--right"><aclass="navbar__link"aria-haspopup="true"aria-expanded="false"role="button"href="/oauth2-proxy/docs/next/">Next</a><ulclass="dropdown__menu"><li><aaria-current="page"class="dropdown__link dropdown__link--active"href="/oauth2-proxy/docs/next/configuration/providers/azure">Next</a></li><li><aclass="dropdown__link"href="/oauth2-proxy/docs/">7.5.x</a></li><li><aclass="dropdown__link"href="/oauth2-proxy/docs/7.4.x/">7.4.x</a></li><li><aclass="dropdown__link"href="/oauth2-proxy/docs/7.3.x/">7.3.x</a></li><li><aclass="dropdown__link"href="/oauth2-proxy/docs/7.2.x/">7.2.x</a></li><li><aclass="dropdown__link"href="/oauth2-proxy/docs/7.1.x/">7.1.x</a></li><li><aclass="dropdown__link"href="/oauth2-proxy/docs/7.0.x/">7.0.x</a></li><li><aclass="dropdown__link"href="/oauth2-proxy/docs/6.1.x/">6.1.x</a></li></ul></div><ahref="https://github.com/oauth2-proxy/oauth2-proxy"target="_blank"rel="noopener noreferrer"class="navbar__item navbar__link">GitHub<svgwidth="13.5"height="13.5"aria-hidden="true"viewBox="0 0 24 24"class="iconExternalLink_nPIU"><pathfill="currentColor"d="M21 13v10h-21v-19h12v2h-10v15h17v-8h2zm3-12h-10.988l4.035 4-6.977 7.07 2.828 2.828 6.977-7.07 4.125 4.172v-11z"></path></svg></a><divclass="toggle_vylO colorModeToggle_DEke"><buttonclass="clean-btn toggleButton_gllP toggleButtonDisabled_aARS"type="button"disabled=""title="Switch between dark and light mode (currently light mode)"aria-label="Switch between dark and light mode (currently light mode)"aria-live="polite"><svgviewBox="0 0 24 24"width="24"height="24"class="lightToggleIcon_pyhR"><pathfill="currentColor"d="M12,9c1.65,0,3,1.35,3,3s-1.35,3-3,3s-3-1.35-3-3S10.35,9,12,9 M12,7c-2.76,0-5,2.24-5,5s2.24,5,5,5s5-2.24,5-5 S14.76,7,12,7L12,7z M2,13l2,0c0.55,0,1-0.45,1-1s-0.45-1-1-1l-2,0c-0.55,0-1,0.45-1,1S1.45,13,2,13z M20,13l2,0c0.55,0,1-0.45,1-1 s-0.45-1-1-1l-2,0c-0.55,0-1,0.45-1,1S19.45,13,20,13z M11,2v2c0,0.55,0.45,1,1,1s1-0.45,1-1V2c0-0.55-0.45-1-1-1S11,1.45,11,2z M11,20v2c0,0.55,0.45,1,1,1s1-0.45,1-1v-2c0-0.55-0.45-1-1-1C11.45,19,11,19.45,11,20z M5.99,4.58c-0.39-0.39-1.03-0.39-1.41,0 c-0.39,0.39-0.39,1.03,0,1.41l1.06,1.06c0.39,0.39,1.03,0.39,1.41,0s0.39-1.03,0-1.41L5.99,4.58z M18.36,16.95 c-0.39-0.39-1.03-0.39-1.41,0c-0.39,0.39-0.39,1.03,0,1.41l1.06,1.06c0.39,0.39,1.03,0.39,1.41,0c0.39-0.39,0.39-1.03,0-1.41 L18.36,16.95z M19.42,5.99c0.39-0.39,0.39-1.03,0-1.41c-0.39-0.39-1.03-0.39-1.41,0l-1.06,1.06c-0.39,0.39-0.39,1.03,0,1.41 s1.03,0.39,1.41,0L19.42,5.99z M7.05,18.36c0.39-0.39,0.39-1.03,0-1.41c-0.39-0.39-1.03-0.39-1.41,0l-1.06,1.06 c-0.39,0.39-0.39,1.03,0,1.41s1.03,0.39,1.41,0L7.05,18.36z"></path></svg><svgviewBox="0 0 24 24"width="24"height="24"class="darkToggleIcon_wfgR"><pathfill="currentColor"d="M9.37,5.51C9.19,6.15,9.1,6.82,9.1,7.5c0,4.08,3.32,7.4,7.4,7.4c0.68,0,1.35-0.09,1.99-0.27C17.45,17.19,14.93,19,12,19c-3.86,0-7-3
<strong>App registrations</strong> and then click on <strong>New registration</strong>.</li><li>Pick a name, check the supported account type(single-tenant, multi-tenant, etc). In the <strong>Redirect URI</strong> section create a new
<strong>Web</strong> platform entry for each app that you want to protect by the oauth2 proxy(e.g.
<ahref="https://internal.yourcompanycom/oauth2/callback"target="_blank"rel="noopener noreferrer">https://internal.yourcompanycom/oauth2/callback</a>). Click <strong>Register</strong>.</li><li>Next we need to add group read permissions for the app registration, on the <strong>API Permissions</strong> page of the app, click on
<strong>Add a permission</strong>, select <strong>Microsoft Graph</strong>, then select <strong>Application permissions</strong>, then click on <strong>Group</strong> and select
<strong>Group.Read.All</strong>. Hit <strong>Add permissions</strong> and then on <strong>Grant admin consent</strong> (you might need an admin to do this).<br>**IMPORTANT**: Even if this permission is listed with **"Admin consent required=No"** the consent might actually be required, due to AAD policies you won't be able to see. If you get a **"Need admin approval"** during login, most likely this is what you're missing!</li><li>Next, if you are planning to use v2.0 Azure Auth endpoint, go to the <strong>Manifest</strong> page and set <code>"accessTokenAcceptedVersion": 2</code>
in the App registration manifest file.</li><li>On the <strong>Certificates & secrets</strong> page of the app, add a new client secret and note down the value after hitting <strong>Add</strong>.</li><li>Configure the proxy with:</li></ol><ul><li>for V1 Azure Auth endpoint (Azure Active Directory Endpoints - <ahref="https://login.microsoftonline.com/common/oauth2/authorize"target="_blank"rel="noopener noreferrer">https://login.microsoftonline.com/common/oauth2/authorize</a>)</li></ul><divclass="codeBlockContainer_Ckt0 theme-code-block"style="--prism-color:#bfc7d5;--prism-background-color:#292d3e"><divclass="codeBlockContent_biex"><pretabindex="0"class="prism-code language-text codeBlock_bY9V thin-scrollbar"><codeclass="codeBlockLines_e6Vv"><spanclass="token-line"style="color:#bfc7d5"><spanclass="token plain"> --provider=azure</span><br></span><spanclass="token-line"style="color:#bfc7d5"><spanclass="token plain"> --client-id=<application ID from step 3></span><br></span><spanclass="token-line"style="color:#bfc7d5"><spanclass="token plain"> --client-secret=<value from step 5></span><br></span><spanclass="token-line"style="color:#bfc7d5"><spanclass="token plain"> --azure-tenant={tenant-id}</span><br></span><spanclass="token-line"style="color:#bfc7d5"><spanclass="token plain"> --oidc-issuer-url=https://sts.windows.net/{tenant-id}/</span><br></span></code></pre><divclass="buttonGroup__atx"><buttontype="button"aria-label="Copy code to clipboard"title="Copy"class="clean-btn"><spanclass="copyButtonIcons_eSgA"aria-hidden="true"><svgviewBox="0 0 24 24"class="copyButtonIcon_y97N"><pathfill="currentColor"d="M19,21H8V7H19M19,5H8A2,2 0 0,0 6,7V21A2,2 0 0,0 8,23H19A2,2 0 0,0 21,21V7A2,2 0 0,0 19,5M16,1H4A2,2 0 0,0 2,3V17H4V3H16V1Z"></path></svg><svgviewBox="0 0 24 24"class="copyButtonSuccessIcon_LjdS"><pathfill="currentColor"d="M21,7L9,19L3.5,13.5L4.91,12.09L9,16.17L19.59,5.59L21,7Z"></path></svg></span></button></div></div></div><ul><li>for V2 Azure Auth endpoint (Microsoft Identity Platform Endpoints - <ahref="https://login.microsoftonline.com/common/oauth2/v2.0/authorize"target="_blank"rel="noopener noreferrer">https://login.microsoftonline.com/common/oauth2/v2.0/authorize</a>)</li></ul><divclass="codeBlockContainer_Ckt0 theme-code-block"style="--prism-color:#bfc7d5;--prism-background-color:#292d3e"><divclass="codeBlockContent_biex"><pretabindex="0"class="prism-code language-text codeBlock_bY9V thin-scrollbar"><codeclass="codeBlockLines_e6Vv"><spanclass="token-line"style="color:#bfc7d5"><spanclass="token plain"> --provider=azure</span><br></span><spanclass="token-line"style="color:#bfc7d5"><spanclass="token plain"> --client-id=<application ID from step 3></span><br></span><spanclass="token-line"style="color:#bfc7d5"><spanclass="token plain"> --client-secret=<value from step 5></span><br></span><spanclass="token-line"style="color:#bfc7d5"><spanclass="token plain"> --azure-tenant={tenant-id}</span><br></span><spanclass="token-line"style="color:#bfc7d5"><spanclass="token plain"> --oidc-issuer-url=https://login.microsoftonline.com/{tenant-id}/v2.0</span><br></span></code></pre><divclass="buttonGroup__atx"><buttontype="button"aria-label="Copy code to clipboard"title="Copy"class="clean-btn"><spanclass="copyButtonIcons_eSgA"aria-hidden="true"><svgviewBox="0 0 24 24"class="copyButtonIcon_y97N"><pathfill="currentColor"d="M19,21H8V7H19M19,5H8A2,2 0 0,0 6,7V21A2,2 0 0,0 8,23H19A2,2 0 0,0 21,21V7A2,2 0 0,0 19,5M16,1H4A2,2 0 0,0 2,3V17H4V3H16V1Z"></path></svg><svgviewBox="0 0 24 24"class="copyButtonSuccessIcon_LjdS"><pathfill="currentColor"d="M21,7L9,19L3.5,13.5L4.91,12.09L9,16.17L19.59,5.59L21,7Z"></path></svg></span></button></div></div></div><p><strong><em>Notes</em></strong>:</p><ul><li>When using v2.0 Azure Auth endpoint (<code>https://login.microsoftonline.com/{tenant-id}/v2.0</code>) as <code>--oidc_issuer_url</code>, in conjunction
with <code>--resource</code> flag, be sure to append <code>/.default</code> at the end of the resource name. See
<ahref="https://docs.microsoft.com/en-us/azure/active-directory/develop/v2-permissions-and-consent#the-default-scope"target="_blank"rel="noopener noreferrer">https://docs.microsoft.com/en-us/azure/active-directory/develop/v2-permissions-and-consent#the-default-scope</a> for more details.</li><li>When using the Azure Auth provider with nginx and the cookie session store you may find the cookie is too large and doesn't
get passed through correctly. Increasing the proxy_buffer_size in nginx or implementing the