Single Sign-On with Microsoft Entra ID
Let your organization sign in with its own Microsoft Entra ID tenant. Bring your own tenant and app registration; LucentSkill has no platform tenant, so your identities and credentials stay in your directory.
What it is
Single sign-on (SSO) lets your people sign in to LucentSkill with the same work account they already use for Microsoft 365, Teams, and other Entra ID apps. Each organization brings its own Entra ID tenant, so authentication stays inside your directory and your identity provider remains the system of record for your users.
The connection uses the industry standards for secure sign-in: OAuth 2.0 authorization code flow with PKCE (RFC 7636) and OpenID Connect (OIDC). LucentSkill verifies every sign-in against your tenant's published keys, and never trusts identity claims it did not cryptographically validate.
Use
- When SSO is on, your people see a 'Sign in with Microsoft' button on the sign-in screen and can also be redirected automatically after typing their work email.
- You can make SSO optional (people may still use a password) or required (password sign-in for your organization is turned off and everyone must sign in with Microsoft).
- New people are created in LucentSkill automatically the first time they sign in, as members. You assign admin or owner roles afterward in the member roster, exactly as you do for any other member.
Set up Entra SSO
You configure everything on the LucentSkill side from Admin → Organization Settings → Single sign-on. First, create the app registration in your own Entra ID tenant, then copy three values back into LucentSkill.
- 1. In the Azure portal, open Microsoft Entra ID → App registrations → New registration. Give it a name such as 'LucentSkill SSO'.
- 2. Set Redirect URI to https://www.lucentskill.com/api/auth/entra/callback and the platform to Web. If your workspace uses a custom domain, use https://your-domain.com/api/auth/entra/callback instead. It must match exactly. Click Register.
- 3. Copy the Application (client) ID and the Directory (tenant) ID from the app's Overview page.
- 4. Under Certificates & secrets → New client secret, create a secret and copy its value once. LucentSkill encrypts it before storing it, so it can never be read back.
- 5. Under Authentication, confirm the Redirect URI from step 2 is listed.
- 6. Back in LucentSkill, paste the client ID, tenant ID, and client secret, then set the sign-in domain (your email domain, for example contoso.com). Turn Sign in with Microsoft on, and choose whether to require it.
Security
- Your client secret is encrypted at rest with AES-256-GCM and is write-only: LucentSkill never displays it again and never writes it to logs.
- Every sign-in validates the identity token signature against your tenant's published keys, plus the issuer, audience, expiry, a nonce, and a PKCE code verifier, so a forged or replayed token cannot start a session.
- LucentSkill has no platform tenant: your directory and sign-in policy remain entirely under your tenant's control, including conditional access and multi-factor authentication.
- Identity is matched by email within your organization only; an SSO account can never be linked to another organization's workspace.
- No admin or owner role is ever granted from a Microsoft group or claim. Roles are assigned by your organization's owner through the member roster, so access control stays inside LucentSkill.