Microsoft SSOIdentity and Access
A Personal Microsoft Account Is Enough To Get In
This is the personal Microsoft account, the sign-in a member of the public already holds for Outlook.com, Hotmail or Xbox. It is not Microsoft Entra ID, which is the work directory an organization runs and issues accounts from, and which is a separate record in this catalog. An employer that wants staff signing in with the work account it gave them is describing that one. This record is Nexus positioned as the Enterprise Video Platform admitting people whose Microsoft account is their own: a body too small to run a directory, and an audience who each turn up with an account nobody issued them.
What you can do together
Sign in people who have no work account
A small staff reaches Nexus with the personal Microsoft account they use every day, and no directory has to exist first.
Let an outside audience arrive as it is
Members, dealers or volunteers sign in with the account they hold, with nothing created in advance.
Set where people land
The SSO app carries a default Client Access License, so a first sign-in arrives with the permissions chosen for that door.
Offer several accounts on one page
Turning Microsoft on beside Google or LinkedIn is a portal setting, so visitors use whichever account they hold.
How it connects
Configuration is per portal, under Admin, Portal Settings, Apps, and there are two ways to use it. As an SSO app, given a client id and secret, Microsoft authenticates the person and returns claims that attribute mapping writes into profile fields. Somebody signing in for the first time gets an account created on the spot, on the app's default Client Access License, the portal's bundle of features and permissions. This is the route for an organization whose people have only personal accounts to sign in with.
As social sign-in it is a separately licensed feature, enabled per portal for public viewers rather than staff. Microsoft appears on the sign-in page beside whichever other consumer providers the administrator turned on, among Google, Facebook, LinkedIn, X and Yahoo. A visitor picks it, authenticates at Microsoft and reaches the shared content.
Either way the portal is a service provider, never an identity provider, and nothing is written back to Microsoft. One difference from a work directory matters more than the rest. A personal account is not yours to suspend, so when somebody should no longer have access the administrator disables that user in the portal, and the refusal happens there.
Microsoft SSOIdentity and Access
A scenario
- SetupThe association's IT contractor adds an SSO app to the secretariat portal with a client id and secret, maps name and email, and sets the default Client Access License. On the members' portal he enables social sign-in instead.
- Monday, 09:00The membership officer opens the secretariat portal, signs in at Microsoft with the personal account she uses for association mail, and the upload page opens with her name in place.
- Conference weekA member abroad opens the members' portal, picks Sign in with Microsoft and uses the account he has had since his first job. He watches the keynote, and nobody created anything for him.
- The same afternoonAnother member signs in with Google from the same page. Both are known viewers under the settings chosen for that portal, because neither account carries a directory group.
- Year endThe membership officer moves on, and her Microsoft account goes with her. The administrator disables her user in the portal, so her next attempt is refused there.
What stays where
The account belongs to the person, not the organization
Microsoft holds the password and any second factor, and Nexus never sees either.
This is not the work directory
Microsoft Entra ID is a different system with its own record here. A personal Microsoft account carries no directory membership of any kind, so nothing arrives with it beyond the identity itself.
Entitlement is the portal's work
With no groups behind the visitor, what each one may open is set in the portal. That is the trade for admitting people you do not employ, and it is why offboarding happens there too.
Where you deploy is where it runs
Shared SaaS, a dedicated cloud or your own servers.
Products and solutions
Next step
See it on your own Microsoft SSO instance.
We will show the connection made, the data moving and the output, then size it for your deployment.
Contact VIDIZMO
sales@vidizmo.ai
+1 571-969-2180
vidizmo.ai