Velaxe
AccessGuard — IAM with JWT, MFA, RBAC & SSO (SAML/OIDC) | Velaxe

AccessGuard

Azure AD (Entra ID) — Integration

SSO via Microsoft Entra ID using OIDC or SAML, with Conditional Access support and optional SCIM provisioning.

Overview

SSO via Microsoft Entra ID using OIDC or SAML, with Conditional Access support and optional SCIM provisioning.

Capabilities

  • OIDC and SAML single sign-on

  • Group/role claim mapping to AccessGuard roles

  • Conditional Access compatibility (device/compliance/geo)

  • Optional SCIM 2.0 user & group provisioning

  • Multi-tenant or single-tenant app registrations

  • JWKS discovery and automatic key rotation

Setup Steps (6)

  1. 1

    Step 1

    In Entra admin center, create an App registration; enable ID tokens (OIDC) or configure Enterprise app (SAML).

  2. 2

    Step 2

    Note the Issuer (Tenant ID), Client ID, and create a Client Secret (for OIDC).

  3. 3

    Step 3

    In AccessGuard → Settings → SSO, add **Azure AD** and paste the credentials or SAML metadata.

  4. 4

    Step 4

    Map groups/roles from Azure AD claims to AccessGuard roles.

  5. 5

    Step 5

    Optionally enable SCIM and provide the SCIM endpoint and token from AccessGuard.

  6. 6

    Step 6

    Test login and verify Conditional Access prompts as required.

Limitations

  • SCIM requires appropriate Entra licensing and admin consent.

  • Group claims may require directory settings for overage scenarios (large groups).

  • SAML entity IDs and reply URLs must exactly match the configured values.

FAQs

Do you support national cloud tenants?

Yes. Provide the correct authority/issuer URL for your cloud (e.g., Azure Government).

Can we restrict by domain?

Yes. Limit tenants or enforce domain allowlists via AccessGuard policies.

How are roles assigned?

Via group/claim mapping rules evaluated at login and on SCIM updates.

Pricing

Free

Free

Great for trying the integration.

Pro

USD 9.99 / monthly

Enterprise

USD 49.99 / monthly