> ## Documentation Index
> Fetch the complete documentation index at: https://docs.blis.app/llms.txt
> Use this file to discover all available pages before exploring further.

# Microsoft OIDC

> Set up an OpenID Connect application in Azure Portal for bLIS

This guide contains instructions for setting up a new OpenID Connect application in Azure Portal (Microsoft 365).

<Info>
  For questions or support, please reach out to [support@blis.app](mailto:support@blis.app).
</Info>

## Inputs

The following values will be provided by Gamma Peak:

* Redirect URI(s)

## Outputs

After following the instructions below, you will provide the following values to Gamma Peak:

* Client ID
* Client secret
* Client secret expiration date (if configured)
* OpenID Connect metadata document URI

***

# Instructions

## 1. Log in to Azure Portal

Log in to the [Azure Active Directory Admin dashboard](https://portal.azure.com/#view/Microsoft_AAD_IAM/ActiveDirectoryMenuBlade/~/Overview). Select **App registrations** from the menu on the left.

<img src="https://mintcdn.com/gammapeak/yAdwd2b07jqDFA99/images/sso/ms-oidc-1.png?fit=max&auto=format&n=yAdwd2b07jqDFA99&q=85&s=e4247c255bcb0f0c7b8e6209e07ae705" alt="MS OIDC Step 1" width="3160" height="2004" data-path="images/sso/ms-oidc-1.png" />

Click on **App registrations**

## 2. Create a new app registration

<img src="https://mintcdn.com/gammapeak/yAdwd2b07jqDFA99/images/sso/ms-oidc-2.png?fit=max&auto=format&n=yAdwd2b07jqDFA99&q=85&s=d0a5580dbb4a3cd6409c99167865fba9" alt="MS OIDC Step 2" width="3160" height="2004" data-path="images/sso/ms-oidc-2.png" />

Click **New registration**.

<img src="https://mintcdn.com/gammapeak/yAdwd2b07jqDFA99/images/sso/ms-oidc-3.png?fit=max&auto=format&n=yAdwd2b07jqDFA99&q=85&s=988ec84d71727d7e6c9ae7446a0ff90e" alt="MS OIDC Step 3" width="3160" height="2004" data-path="images/sso/ms-oidc-3.png" />

Enter a name for the application (e.g., `bLIS`) and click **Register**. Leave the Redirect URI blank for now.

## 3. Copy and save client ID

On the application's **Overview** page, locate the **Application (client) ID** field. Copy and save this value.

<img src="https://mintcdn.com/gammapeak/yAdwd2b07jqDFA99/images/sso/ms-oidc-4.png?fit=max&auto=format&n=yAdwd2b07jqDFA99&q=85&s=2cfa1904dbfa906bdf4b6d2c2a874235" alt="MS OIDC Step 4" width="3160" height="2004" data-path="images/sso/ms-oidc-4.png" />

<Note>
  **Output:** Client ID
</Note>

## 4. Copy and save OIDC metadata document URI

<img src="https://mintcdn.com/gammapeak/yAdwd2b07jqDFA99/images/sso/ms-oidc-5.png?fit=max&auto=format&n=yAdwd2b07jqDFA99&q=85&s=b8968214091edfe1c52fe8451668fdfb" alt="MS OIDC Step 5" width="3160" height="2004" data-path="images/sso/ms-oidc-5.png" />

From the application's **Overview** page, click **Endpoints** in the top toolbar.

<img src="https://mintcdn.com/gammapeak/yAdwd2b07jqDFA99/images/sso/ms-oidc-6.png?fit=max&auto=format&n=yAdwd2b07jqDFA99&q=85&s=2eaa2390d0461b373fb0ccf813507e7d" alt="MS OIDC Step 6" width="3160" height="2004" data-path="images/sso/ms-oidc-6.png" />

In the panel that appears, locate the **OpenID Connect metadata document** URI. Copy and save this value.

<Note>
  **Output:** OpenID Connect metadata document URI
</Note>

## 5. Create a client secret

<img src="https://mintcdn.com/gammapeak/yAdwd2b07jqDFA99/images/sso/ms-oidc-7.png?fit=max&auto=format&n=yAdwd2b07jqDFA99&q=85&s=f076c222c7329871126cb1d64500b1aa" alt="MS OIDC Step 7" width="3160" height="2004" data-path="images/sso/ms-oidc-7.png" />

From the application page, click **Add a certificate or secret** (or navigate to **Certificates & secrets** in the left menu).

<img src="https://mintcdn.com/gammapeak/yAdwd2b07jqDFA99/images/sso/ms-oidc-8.png?fit=max&auto=format&n=yAdwd2b07jqDFA99&q=85&s=2c3a8a56d36a68454e4c9ed567e3c099" alt="MS OIDC Step 8" width="3160" height="2004" data-path="images/sso/ms-oidc-8.png" />

Click **New client secret**. Enter a description and select an expiration period, then click **Add**.

<Warning>
  Access to bLIS will be lost once the secret expires. Prior to expiration, please contact an administrator to update the secret value. The expiration period is up to you.
</Warning>

<img src="https://mintcdn.com/gammapeak/yAdwd2b07jqDFA99/images/sso/ms-oidc-9.png?fit=max&auto=format&n=yAdwd2b07jqDFA99&q=85&s=51bc1125be79b2f6cd60a8a02903693d" alt="MS OIDC Step 9" width="3160" height="2004" data-path="images/sso/ms-oidc-9.png" />

Enter a description and expiration for the secret.

<img src="https://mintcdn.com/gammapeak/yAdwd2b07jqDFA99/images/sso/ms-oidc-10.png?fit=max&auto=format&n=yAdwd2b07jqDFA99&q=85&s=c91182074f8f8405fdfd248d5fa3e490" alt="MS OIDC Step 10" width="3160" height="2004" data-path="images/sso/ms-oidc-10.png" />

Copy the **Value** field of the newly created secret immediately.

<Warning>
  This value will only be visible for a few minutes. Copy and save before proceeding.
</Warning>

<Note>
  **Output:** Client secret and expiration date
</Note>

## 6. Enter redirect URIs

<img src="https://mintcdn.com/gammapeak/yAdwd2b07jqDFA99/images/sso/ms-oidc-11.png?fit=max&auto=format&n=yAdwd2b07jqDFA99&q=85&s=15bc5e058d267456f00146abfc8c101c" alt="MS OIDC Step 11" width="3160" height="2004" data-path="images/sso/ms-oidc-11.png" />

Click on **Authentication** in the left menu.

<img src="https://mintcdn.com/gammapeak/yAdwd2b07jqDFA99/images/sso/ms-oidc-12.png?fit=max&auto=format&n=yAdwd2b07jqDFA99&q=85&s=4b92f11775a5233a43d0fe5733ea3603" alt="MS OIDC Step 12" width="3160" height="2004" data-path="images/sso/ms-oidc-12.png" />

Click **Add a platform**.

<img src="https://mintcdn.com/gammapeak/yAdwd2b07jqDFA99/images/sso/ms-oidc-13.png?fit=max&auto=format&n=yAdwd2b07jqDFA99&q=85&s=12a568cb5f0748f09dccd3c5b3368453" alt="MS OIDC Step 13" width="3160" height="2004" data-path="images/sso/ms-oidc-13.png" />

Click **Web**.

<img src="https://mintcdn.com/gammapeak/yAdwd2b07jqDFA99/images/sso/ms-oidc-14.png?fit=max&auto=format&n=yAdwd2b07jqDFA99&q=85&s=127ac951116e55b6e3af14bfa7851d55" alt="MS OIDC Step 14" width="3160" height="2004" data-path="images/sso/ms-oidc-14.png" />

Enter the first redirect URI provided to you. Under **Implicit grant and hybrid flows**, select both **Access tokens** and **ID tokens**. Click **Configure**.

<img src="https://mintcdn.com/gammapeak/yAdwd2b07jqDFA99/images/sso/ms-oidc-15.png?fit=max&auto=format&n=yAdwd2b07jqDFA99&q=85&s=c1c2e1ed7dd9134e860ee9ebd18cb1d1" alt="MS OIDC Step 15" width="3160" height="2004" data-path="images/sso/ms-oidc-15.png" />

If you received multiple redirect URIs, click **Add URI** for each additional one and enter the value.

<img src="https://mintcdn.com/gammapeak/yAdwd2b07jqDFA99/images/sso/ms-oidc-16.png?fit=max&auto=format&n=yAdwd2b07jqDFA99&q=85&s=d803a800e199364534bd539ad2c8a397" alt="MS OIDC Step 16" width="3160" height="2004" data-path="images/sso/ms-oidc-16.png" />

Enter each an additional redirect URI into the input that appears. Repeat this for each additional redirect URI you received. Click **Save** once all redirect URIs have been entered.

<Warning>
  Do not use the values visible in any screenshots — use only the redirect URIs provided to you by Gamma Peak.
</Warning>

## 7. Send output values

Configuration in Azure Portal is now complete. Send the following output values to [support@blis.app](mailto:support@blis.app):

* **Client ID**
* **Client secret**
* **Client secret expiration date**
* **OpenID Connect metadata document URI**

These values contain sensitive information. Please use one of the following services to share them securely:

* [Yopass](https://yopass.se/)
* [Doppler Share](https://share.doppler.com/)

<Info>
  For questions or support, please reach out to [support@blis.app](mailto:support@blis.app).
</Info>
