Authentication via Microsoft Entra ID is used to enhance security and simplify logging in to CDESK. You can link CDESK with MS Entra ID in under 15 minutes. To use this feature, you must have your own CDESK / CM Server domain.
You can configure authentication either only for users from your MS Entra tenant (single-tenant), or for external users from other tenants (multi-tenant). Login for external users (multi-tenant) is supported from CDESK version 3.2.6.
For authentication to work, the organisation must have an Office 365 tenant created with accounts set up for users. The accounts do not need an Office 365 licence. For verification, it is enough for the user to have a valid email address registered in the tenant that they actually use (because of the activation link). This address does not have to be part of Office 365; it can also be an external email service. In that case, however, the domain of this service must be configured in the Office 365 environment, which you should arrange with your IT.
The procedure for setting up the link is described below.
The first step in creating the link is adding the MS Entra ID Authentication API connector in CDESK. Go to CDESK → Global settings → Connectors, API. A list of connectors and APIs that are currently configured on your CDESK Server will open. To add the MS Entra ID connector, click the +Add connector button located in the top right corner.

After clicking, a new window opens with a selection of the connector type. Select the Microsoft Entra ID Authentication option and click the Continue button.

Next, the form for configuring the MS Entra ID connector opens. Fields marked with the symbol • are mandatory. Description of the individual fields:
Connector type • – The connector you selected in the previous step, pre-filled automatically.
Title • – The name under which the connector will be displayed in the list of connectors.
Enabled – Turning the connector’s activity on or off. If you do not want to use the connector, switch this toggle off.
More detailed logging – Used in the event of authentication problems. Enable it only after consulting a support representative of the CDESK manufacturer.
Application (client) ID • – You obtain this value in the MS Entra ID settings. The procedure is described below in the section Linking the CDESK environment with the MS Entra ID tenant.
Secret value • – You obtain this value in the MS Entra ID settings. The procedure is described below in the section Linking the CDESK environment with the MS Entra ID tenant.
Directory (tentant) ID • – You obtain this value in the MS Entra ID settings. The procedure is described below in the section Linking the CDESK environment with the MS Entra ID tenant. Required only for the single-tenant setup.
Multi-Tenant – Enable it if you want to authenticate users from other Office 365 tenant environments.
Redirect URI – an address generated automatically by CDESK. It is used during the registration of the MS Entra ID connector. It specifies the address that will be accessed via MS Entra ID after successful authorisation. You will enter this address into the registered application in MS Entra ID.
Automatic login from the login screen (True SSO) – If enabled, the user will be logged in immediately after entering the CDESK / CM Portal address, without having to click the Office 365 / Entra ID button.
Allow new customer accounts to be created in CDESK – If enabled, users from allowed domains who do not yet have an account in CDESK will be able to create a user account after successful authentication via MS Entra ID. Configuring this feature is described in the article Creating customer accounts using MS Entra ID.

To obtain the Application (client) ID and Secret value data, you need to register CDESK in MS Entra ID. Go to the office.com page, where you log in with an Office 365 account that has permission to administer MS Entra ID. Among the application menu on the left side of the window, look for the Admin application.

After clicking, the administrator’s home screen opens. In the menu on the left side, select the Show all option. In the expanded menu, click the Identity option. Once the application has loaded, the initial overview is displayed, and in the left-hand menu select the App registrations option.

A new window opens. Then select the +New registration option to register a new application.

After clicking, a window for registering a new application opens with the following items:
Name – a text field for entering the name under which the registration will be displayed in the list of registered links.
Supported account types – a setting for whether authorisation will also be performed for other tenants. If you are using an account registered under your company, select the Acconunts in this organizational directory only (your company only – Single tenant) option. If you have an Office 365 account created within another company, select the Accounts in any organizational directory (Any Microsoft Entra ID tenant – Multitenant). option.
Redirect URI – select the Web option and copy the Redirect URI from the MS Entra ID API connector settings in CDESK into the text field (following image).

Then, to register the application, click the Register button located in the bottom left corner below the list.

After registering the application, you will be redirected to the Overview section, where the registration details become available. Into the form for configuring the API connector for MS Entra ID in CDESK, copy the Application (client) ID and Directory (tenant) ID data (only in the case of single-tenant).

To complete the connector configuration, you still need to enter the Secret value. Go to the Certificates & secrets section, located in the menu on the left side. Click the +New client secret button and select the code’s expiry period. We recommend two years. In the Description field you can insert a description. To generate the code, click the Add button.

After creating it by clicking, the generated code is displayed in the Client secrets list. Click Copy to cliboard, go to CDESK and paste it into the Secret value field in the MS Entra ID connector form.

Once all the necessary data is in the form, save the settings using the Create button at the bottom right.

Go to Users and groups → Users. In the list, open the user account you want to link and, in the General settings tab, scroll down lower.
After completing the configuration of the MS Entra ID connector, the Logging in via MS Entra ID – use the contact email toggle is enabled by default in all accounts, meaning the configured contact email will be used for authentication.

However, if you needed to use a different email, switch the toggle off and enter the email in the Entra ID account e-mail for sync field. In both cases the email used must be the one the user also has in MS Entra ID. Save the settings using the Save button in the bottom right corner.

After configuring the MS Entra ID connector, a button for logging in using Microsoft Entra ID is displayed on the CDESK login screen.
After clicking it, you will be redirected to the Office 365 login page, where you verify yourself with your login credentials. If you are already logged in in the browser, authentication takes place automatically and you will be immediately redirected to CDESK without needing to re-enter your login credentials.

If you have registered a new application in this way, upon first login users will be shown a prompt to grant the application permissions. The administrator of each tenant from which users will log in can, on first login, tick „Consent on behalf of your organization“, thereby granting Admin Consent for the entire organisation. This ensures that the application will work for the given tenant without further consent prompts for the other users in the organisation. Without the administrator’s consent, each user will have to grant these permissions themselves.

Admin Consent can also be granted via the MS Entra ID portal, namely in the Enterprise applications, section, where you select the given application, go to the Permissions section and click Grant admin consent for your company.
