mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-05 12:26:38 +00:00
docs: add entra / azure mfa docs
This commit is contained in:
@@ -17,3 +17,40 @@ Check the box in Personal Settings > Two-factor Authentication to enable email-b
|
|||||||
building support for other forms of identification via SMS and Authenticator
|
building support for other forms of identification via SMS and Authenticator
|
||||||
App.
|
App.
|
||||||
</Note>
|
</Note>
|
||||||
|
|
||||||
|
## Entra ID / Azure AD MFA
|
||||||
|
|
||||||
|
<Note>
|
||||||
|
Before proceeding make sure you've enabled [SAML SSO for Entra ID / Azure AD](./sso/azure).
|
||||||
|
|
||||||
|
We also encourage you to have your team download and setup the
|
||||||
|
[Microsoft Authenticator App](https://www.microsoft.com/en-us/security/mobile-authenticator-app) prior to enabling MFA.
|
||||||
|
</Note>
|
||||||
|
|
||||||
|
<Steps>
|
||||||
|
<Step title="Open your Infisical application in the Microsoft Entra Admin Center">
|
||||||
|

|
||||||
|
</Step>
|
||||||
|
<Step title="Tap on Conditional Access under the Security Tab">
|
||||||
|

|
||||||
|
</Step>
|
||||||
|
<Step title="Tap on Create New Policy from Templates">
|
||||||
|

|
||||||
|
</Step>
|
||||||
|
<Step title="Select Require MFA for All Users and Tap on Review + Create">
|
||||||
|

|
||||||
|
<Note>
|
||||||
|
By default all users except the configuring admin will be setup to require MFA.
|
||||||
|
Microsoft encourages keeping at least one admin excluded from MFA to prevent accidental lockout.
|
||||||
|
</Note>
|
||||||
|
</Step>
|
||||||
|
<Step title="Set Policy State to Enabled and Tap on Create">
|
||||||
|

|
||||||
|
</Step>
|
||||||
|
<Step title="MFA is now Required When Accessing Infisical">
|
||||||
|

|
||||||
|
<Note>
|
||||||
|
If users have not setup MFA for Entra / Azure they will be prompted to do so at this time.
|
||||||
|
</Note>
|
||||||
|
</Step>
|
||||||
|
</Steps>
|
||||||
@@ -116,3 +116,7 @@ description: "Learn how to configure Microsoft Entra ID for Infisical SSO."
|
|||||||
- `AUTH_SECRET`: A secret key used for signing and verifying JWT. This can be a random 32-byte base64 string generated with `openssl rand -base64 32`.
|
- `AUTH_SECRET`: A secret key used for signing and verifying JWT. This can be a random 32-byte base64 string generated with `openssl rand -base64 32`.
|
||||||
- `SITE_URL`: The URL of your self-hosted instance of Infisical - should be an absolute URL including the protocol (e.g. https://app.infisical.com)
|
- `SITE_URL`: The URL of your self-hosted instance of Infisical - should be an absolute URL including the protocol (e.g. https://app.infisical.com)
|
||||||
</Note>
|
</Note>
|
||||||
|
|
||||||
|
<Note>
|
||||||
|
If you'd like to require Multi-factor Authentication for your team members to access Infisical check out our [Entra ID / Azure AD MFA](../mfa#entra-id-azure-ad-mfa) guide.
|
||||||
|
</Note>
|
||||||
|
|||||||
@@ -30,7 +30,7 @@ enum AuthProvider {
|
|||||||
|
|
||||||
const ssoAuthProviders = [
|
const ssoAuthProviders = [
|
||||||
{ label: "Okta SAML", value: AuthProvider.OKTA_SAML },
|
{ label: "Okta SAML", value: AuthProvider.OKTA_SAML },
|
||||||
{ label: "Azure SAML", value: AuthProvider.AZURE_SAML },
|
{ label: "Azure / Entra SAML", value: AuthProvider.AZURE_SAML },
|
||||||
{ label: "JumpCloud SAML", value: AuthProvider.JUMPCLOUD_SAML },
|
{ label: "JumpCloud SAML", value: AuthProvider.JUMPCLOUD_SAML },
|
||||||
{ label: "Keycloak SAML", value: AuthProvider.KEYCLOAK_SAML },
|
{ label: "Keycloak SAML", value: AuthProvider.KEYCLOAK_SAML },
|
||||||
{ label: "Google SAML", value: AuthProvider.GOOGLE_SAML }
|
{ label: "Google SAML", value: AuthProvider.GOOGLE_SAML }
|
||||||
@@ -161,7 +161,7 @@ export const SSOModal = ({ popUp, handlePopUpClose, handlePopUpToggle, hideDelet
|
|||||||
entityId: "Identifier (Entity ID)",
|
entityId: "Identifier (Entity ID)",
|
||||||
entryPoint: "Login URL",
|
entryPoint: "Login URL",
|
||||||
entryPointPlaceholder: "https://login.microsoftonline.com/xxx/saml2",
|
entryPointPlaceholder: "https://login.microsoftonline.com/xxx/saml2",
|
||||||
issuer: "Azure Application ID",
|
issuer: "Azure / Entra Application ID",
|
||||||
issuerPlaceholder: "abc-def-ghi-jkl-mno"
|
issuerPlaceholder: "abc-def-ghi-jkl-mno"
|
||||||
};
|
};
|
||||||
case AuthProvider.JUMPCLOUD_SAML:
|
case AuthProvider.JUMPCLOUD_SAML:
|
||||||
|
|||||||
Reference in New Issue
Block a user