Integration brief · Microsoft Entra ID ← Back to the page   Print or save as PDF
Integration brief Microsoft Entra IDIdentity and Access

The Identity Provider You Already Own

Microsoft Entra ID is already there. Any organization on Microsoft 365 E3 or E5 owns it without a separate identity purchase, which is much of why it is the most widely deployed identity platform there is. Connecting Nexus adds one more enterprise application to a tenant that already carries dozens, opened with the account people use for Outlook and Teams. Redactor, AI Intelligence Hub and AI Live Insight are enabled on that same portal, so one connection covers all four.

What you can do together

01

One work account, four products

Staff open Nexus and the Redactor, AI Intelligence Hub and AI Live Insight enabled on it with the credential they already hold. Nothing new is issued.

02

Accounts before day one

SCIM fills the user list from the directory, so content can be shared with a new starter before that person has ever signed in.

03

Entitlement from the group, not a ticket

A rule on an Entra ID group's display name decides which Client Access License a user holds, so a department move upstream reaches the portal with nobody touching it.

04

Your existing authentication policy, applied here

The portal's own second factor is an email passcode. Enforcing SSO puts Entra ID's multi-factor and conditional access in front of it instead.

How it connects

Most of the work happens in the Entra admin center, where the portal becomes an enterprise application, assigned to the users and groups that should reach it. On the portal side an administrator adds an SSO app under Admin, Portal Settings, Apps, labeled SAML / OIDC in the catalog, and gives it Entra ID's metadata address or a client id and secret. Attribute mapping pairs the claims Entra ID returns with profile fields, custom ones included. Conditional access rules written for other applications cover this one on the same terms.

Provisioning is the second connection, with the portal as the SCIM 2.0 service provider. An administrator enables provisioning, generates a portal-scoped API token with an expiry, and enters it with the base URI on the application's provisioning tab. Users and groups are pushed ahead of first sign-in. Each one lands on a Client Access License, the portal's bundle of features and permissions, from a default that rules override by matching the incoming group's display name, first match winning.

Plenty of Microsoft estates are hybrid, with on-premises Active Directory still the directory of record and Entra Connect syncing it upward. That changes nothing here. The portal only ever talks to Entra ID, the on-premises directory sits upstream, and a change made in either place arrives by the same route. Nothing is written back. Note the token expiry. On-premises and disconnected deployments follow a separate provisioning path, because Entra ID cannot reach a portal with no public address.

VIDIZMO and Microsoft Entra ID · Integration briefPage 1 of 2
How it works Microsoft Entra IDIdentity and Access

A scenario

  1. Week one, ITThe identity administrator registers the enterprise application in Entra ID, adds the matching SSO app in Nexus, enables SCIM and generates a token. Two rules: Plant Safety to the safety Client Access License, Domain Users to the viewer default.
  2. Same afternoonEntra ID pushes the assigned groups, and the user list fills with names and plant codes nobody typed, each already entitled.
  3. Monday, 06:20A press line supervisor opens the safety library on a floor tablet, answers the authenticator prompt required everywhere else, and the induction video plays.
  4. TuesdayA safety engineer reviews an AI Live Insight alert for a missing hard hat at the stamping line, then asks AI Intelligence Hub how often that line raised it this quarter. Both sit on the portal she signed into once.
  5. FridayA contract maintenance crew finishes and their accounts are disabled in the on-premises directory. Entra Connect carries the change up, and the portal accounts deactivate behind it.

What stays where

Entra ID remains the identity provider

Passwords, multi-factor policy, conditional access and account lifecycle are governed there, as for every other application in the tenant.

Your directory of record does not move

Where on-premises Active Directory is still the master and Entra Connect syncs upward, that stands. The portal reads what Entra ID presents.

The flow is inbound only

Claims arrive at sign-in and SCIM pushes users and groups. The portal writes nothing to Entra ID and never holds the password.

The portal runs where you put it

Shared SaaS, a dedicated cloud, your own Azure subscription in commercial or government regions, or your own servers.

Products and solutions

Next step

See it on your own Microsoft Entra ID instance.

We will show the connection made, the data moving and the output, then size it for your deployment.

Contact VIDIZMO

sales@vidizmo.ai

+1 571-969-2180

vidizmo.ai

Product names and logos are the property of their respective owners.Page 2 of 2