MDM Lite – Setting Up Single Sign-On with Microsoft Entra ID
This document is intended for public publication. It is written for the IT/identity administration of customers adopting MDM Lite, and for Microsoft's Entra App Gallery reviewers as part of the Gallery submission for "MDM Lite – Data Prudentia". It contains only the information needed for single sign-on setup — no internal operational procedures, no customer-specific identifiers, and no credentials.
As of: 2026-09-23. A German version is available at
entra-sso-setup.de.md.
Contents
- Introduction
- Licensing requirements
- Required roles
- Requested permissions
- Application identification
- How MDM Lite maps users
- Step-by-step setup
- Testing steps for pilot users
- Error handling
- Support
1. Introduction
MDM Lite is a SaaS application from Data Prudentia GmbH for centrally maintaining
versioned reference and configuration data (https://mdm.data-prudentia.com). Employees of
customer organizations sign in with their own corporate account — MDM Lite never creates
guest accounts and never issues additional passwords. The customer's Entra directory fully
authenticates the person, including multi-factor authentication and Conditional Access policies;
MDM Lite then only determines the person's role within the application.
Protocol
| Characteristic | Value |
|---|---|
| Protocol | OpenID Connect / OAuth 2.0 |
| Endpoint | Microsoft Identity Platform v2.0 |
| Flow | Authorization Code Flow with PKCE, via MSAL Browser in the frontend |
| Tenancy | Multi-tenant — authorization against https://login.microsoftonline.com/organizations |
| Token confidentiality | Access tokens are kept only in the browser's MSAL cache; they are never logged server-side |
Because authorization runs against the cross-tenant /organizations endpoint, any work or
school account from any Microsoft Entra directory can technically authenticate. Whether that
person actually gets access to MDM Lite afterwards is decided exclusively by authorization
within MDM Lite (tenant membership, see Section 6) — not by Entra
authentication alone.
Supported identity providers / account types
| Account type | Supported |
|---|---|
| Microsoft Entra ID work or school account | Yes — the only supported account type |
| Personal Microsoft account (Outlook.com, Xbox Live, …) | No |
| Other identity providers (Google, SAML IdPs, Okta, …) | No — MDM Lite offers SSO exclusively through Microsoft Entra ID |
| Entra ID B2B guest account in a foreign directory | Technically possible, but not the intended path — see Section 6 |
2. Licensing requirements
| Component | Requirement |
|---|---|
| MDM Lite | SaaS subscription from Data Prudentia GmbH. Specific plans, user counts, and terms are agreed with your Data Prudentia contact (see Section 10). |
| Microsoft Entra ID — basic SSO | Microsoft Entra ID Free is sufficient. Sign-in itself, admin consent, and directly assigning individual users to the enterprise application require no paid Entra ID license. |
| Microsoft Entra ID — Conditional Access / MFA | Requires Microsoft Entra ID P1 (or higher). Conditional Access policies for access to MDM Lite are optional but recommended. |
| Microsoft Entra ID — group assignment | Assigning security groups (instead of individual users) to the "MDM Lite – Data Prudentia" enterprise application also requires Entra ID P1. |
MDM Lite itself requests no Microsoft Graph permissions (see Section 4) and is therefore usable independently of your Microsoft 365 licensing.
3. Required roles
On the customer IT side (in your own Entra directory)
Granting the application one-time consent (Admin Consent) requires one of the following Entra directory roles:
- Global Administrator
- Application Administrator
- Cloud Application Administrator
This role is only needed for the one-time consent. Ongoing operation (assigning users/groups, Conditional Access, revocation) still requires one of these roles, or a delegated permission on the relevant enterprise application.
On the MDM Lite side
- MDM Lite tenant admin: the first person invited into your MDM Lite workspace by Data Prudentia. This role subsequently manages all further users independently (invite, assign role, block) — without further involvement from your IT or from Data Prudentia.
- Editor / Viewer: regular application roles for day-to-day work with the datasets, assigned by the tenant admin. They are not relevant to the SSO setup itself.
4. Requested permissions
When signing in, MDM Lite requests only the following delegated permissions — all act on behalf of the signed-in person, never as an application permission (app-only):
| Permission (scope) | Resource | Business justification |
|---|---|---|
openid | Microsoft Identity Platform | Core requirement for OpenID Connect: confirms the signed-in person's identity to MDM Lite. |
profile | Microsoft Identity Platform | Reads basic profile information of the signed-in account (name, account ID) so MDM Lite can display the person correctly in the UI and assign them a role. |
offline_access | Microsoft Identity Platform | Enables silent renewal of the access token during an active session, without requiring the person to sign in again. |
api://f78dec68-a861-4a98-b8aa-9663fbba9953/access_as_user | MDM Lite's own API | Allows the signed-in person to use the MDM Lite REST API on their own behalf (read/edit datasets according to their role). Without this scope the web UI cannot load any data. |
Explicitly not requested: any Microsoft Graph permission — no reading of mailboxes,
files, calendars, or Teams content, no directory or group access, no application permissions
(app-only access). The app registration's requiredResourceAccess contains no resource other than
its own API. MDM Lite can technically only do what the signed-in person is themselves allowed to
do within MDM Lite.
5. Application identification
Check these values in the consent dialog and in your list of enterprise applications to uniquely identify the application:
| Attribute | Value |
|---|---|
| Application name | MDM Lite – Data Prudentia |
| Application ID (client ID) | f78dec68-a861-4a98-b8aa-9663fbba9953 |
| Verified publisher | Data Prudentia GmbH (verified through the Microsoft AI Cloud Partner Program) |
| Publisher domain | data-prudentia.com |
| Application address (redirect URI) | https://mdm.data-prudentia.com |
| Privacy statement | https://data-prudentia.de/datenschutz/ |
| Terms of service | https://data-prudentia.de/impressum/ |
App registration signInAudience | AzureADMultipleOrgs (multi-tenant) |
Consents granted before the branding update (2026-09-23) may still show the application under its earlier technical name
mdm-lite-prod-frontendin your enterprise applications list. The application ID and publisher domain remain unchanged.
6. How MDM Lite maps users
MDM Lite maps a signed-in Entra account to a user account in MDM Lite via the account's
immutable object ID (the oid claim that Entra issues in the token on every sign-in) — not
via the email address.
- The email address is used only to match an invitation to an invited person the first time they open the invitation link. Once the invitation is accepted, MDM Lite permanently links the user account to the object ID of the signed-in account.
- If a person's email address or display name later changes in the Entra directory (for example due to marriage or a department change), their access to MDM Lite remains unaffected — the mapping continues to use the same object ID.
- An invitation can only be accepted by the person to whose address it was sent. If someone signs in with a different account, MDM Lite rejects the acceptance, even if the link was forwarded or intercepted (see Section 9).
7. Step-by-step setup
7.1 Admin consent — today's regular path
-
A Data Prudentia contact sends you a consent link following this pattern (with your own Entra directory ID already inserted):
https://login.microsoftonline.com/<directory-id>/adminconsent?client_id=f78dec68-a861-4a98-b8aa-9663fbba9953&redirect_uri=https://mdm.data-prudentia.com<directory-id>is the directory (tenant) ID of your Entra directory (Entra portal → Overview → Tenant ID). -
Open the link — preferably in a private browser window — and sign in with an account that holds one of the roles listed in Section 3.
-
Review the values from Section 5 in the consent dialog and confirm with "Accept".
-
Entra then redirects to
https://mdm.data-prudentia.com. Seeing only the sign-in page at first is normal.
7.2 Adding from the Microsoft Entra App Gallery — available once published
Once MDM Lite is listed in the Microsoft Entra App Gallery, you will alternatively be able to add the application directly from the Gallery to your directory (Entra portal → Enterprise applications → New application → search for "MDM Lite" → Create). The subsequent consent step matches Section 7.1. This path is only available once the Gallery submission is complete.
7.3 Controlling access (Conditional Access, MFA, assignment)
After consent, you will find the application under Entra portal → Enterprise applications → MDM Lite – Data Prudentia. All further controls remain entirely in your hands:
-
Conditional Access / MFA — your own policies for access to MDM Lite (requires Entra ID P1, see Section 2).
-
Users and groups — assign the intended people or a group to the enterprise application.
-
Properties → "Assignment required" — restricts sign-in to explicitly assigned users or groups.
Caution: If you set "Assignment required" to Yes, you must actually assign the intended people or a group — otherwise Entra rejects all sign-ins before MDM Lite is even involved (see
AADSTS50105in Section 9). -
Revocation — consent can be fully revoked at any time: delete the enterprise application, or withdraw the granted consent under Permissions. After that, no further sign-in to MDM Lite is possible.
7.4 Onboarding in MDM Lite
Granting admin consent alone does not yet unlock MDM Lite — MDM Lite must know about your directory before anyone can sign in. Afterwards, please tell Data Prudentia:
- that consent was granted,
- your directory ID (tenant ID) — Data Prudentia records it as the directory binding, so that only accounts from your directory can sign in to your workspace,
- the email address of the first administrator for MDM Lite.
Data Prudentia then sets up your workspace and invites the named person as tenant admin. This person accepts the invitation by signing in with their Entra account, and can then invite all further users themselves — without any further involvement from your IT or additional Entra changes.
8. Testing steps for pilot users
Before extending access to more people, we recommend a test run with a single pilot user:
- Have the tenant admin invite the pilot user via profile menu → "Manage users" → Invitations, choosing the desired role (Viewer, Editor, or Admin).
- The pilot user receives an invitation email with an acceptance link and opens it.
- They sign in with exactly the account to which the invitation was sent (see Section 6).
- Expected result: After signing in, the "Welcome!" confirmation appears and the person lands in their workspace, with exactly the assigned role.
- Also verify signing out (profile menu → "Sign out") and signing back in, to confirm the full sign-in cycle.
- If you have enabled Conditional Access or "Assignment required": verify the pilot user is assigned in the enterprise application, or satisfies the Conditional Access policy (e.g. registered device, MFA), before running the test.
Once the test run succeeds, the tenant admin can add further people through the same invitation flow.
9. Error handling
9.1 Errors on the Entra side (AADSTS codes)
| Code / message | Meaning | Resolution |
|---|---|---|
| AADSTS65001 — "Need admin approval" | Your directory has not yet consented to the requested permissions (user consent is disabled, or restricted to verified publishers with selected permissions). | Grant admin consent as described in Section 7.1 from an authorized account. |
| AADSTS50020 — "The selected user account does not exist in this tenant…" | The sign-in ran against a foreign directory (for example because the browser was still signed in with a different account), or the account is a guest account that has not yet been added to the target directory. | Retry sign-in in a private browser window and make sure you sign in with your own corporate account. |
| AADSTS50105 — "The signed-in user is not assigned to a role for the application" | "Assignment required" is enabled on your enterprise application, but the person is not assigned (see Section 7.3). | Assign the person or their group to the "MDM Lite – Data Prudentia" enterprise application. |
| AADSTS50011 — "The reply URL specified in the request does not match the reply URLs configured for the application" | Sign-in was started from an address other than https://mdm.data-prudentia.com, or there is a redirect URI configuration issue. | Access MDM Lite exclusively via https://mdm.data-prudentia.com. If the problem persists, contact support (see Section 10). |
9.2 Messages on the MDM Lite side
These messages appear after a successful Entra sign-in, while MDM Lite authorizes the sign-in:
| MDM Lite message | Meaning | Resolution |
|---|---|---|
| "Your organization is being set up" | Your directory has not yet been set up as a workspace in MDM Lite, or no first administrator has been invited yet. | Complete onboarding as described in Section 7.4, or check with Data Prudentia. |
| "No access to this workspace" | Your account is not (yet) a member of this workspace. | Contact your MDM Lite tenant admin — they invite you via "Manage users". |
| "Wrong directory" | This account does not belong to the Entra directory registered for your workspace. | Sign in with the account from the correct corporate directory. |
| "Access blocked" | An administrator has blocked this account's access to the workspace. | Contact your MDM Lite tenant admin. |
| "Account blocked" | The account has been blocked platform-wide. | Contact support (see Section 10). |
| "This invitation was sent to a different email address" | An attempt was made to accept an invitation with an account other than the invited one. | Sign in with exactly the invited account, or request a new invitation to the correct address. |
| "This invitation has expired" | The invitation link was not used in time. | Ask your tenant admin to resend the invitation. |
10. Support
For questions about the setup, please contact Data Prudentia GmbH:
- Email:
admin@data-prudentia.de - Website:
https://data-prudentia.de