MDM Lite – Setting Up Single Sign-On with Microsoft Entra ID

This document is intended for public publication. It is written for the IT/identity administration of customers adopting MDM Lite, and for Microsoft's Entra App Gallery reviewers as part of the Gallery submission for "MDM Lite – Data Prudentia". It contains only the information needed for single sign-on setup — no internal operational procedures, no customer-specific identifiers, and no credentials.

As of: 2026-09-23. A German version is available at entra-sso-setup.de.md.

Contents

  1. Introduction
  2. Licensing requirements
  3. Required roles
  4. Requested permissions
  5. Application identification
  6. How MDM Lite maps users
  7. Step-by-step setup
  8. Testing steps for pilot users
  9. Error handling
  10. Support

1. Introduction

MDM Lite is a SaaS application from Data Prudentia GmbH for centrally maintaining versioned reference and configuration data (https://mdm.data-prudentia.com). Employees of customer organizations sign in with their own corporate account — MDM Lite never creates guest accounts and never issues additional passwords. The customer's Entra directory fully authenticates the person, including multi-factor authentication and Conditional Access policies; MDM Lite then only determines the person's role within the application.

Protocol

CharacteristicValue
ProtocolOpenID Connect / OAuth 2.0
EndpointMicrosoft Identity Platform v2.0
FlowAuthorization Code Flow with PKCE, via MSAL Browser in the frontend
TenancyMulti-tenant — authorization against https://login.microsoftonline.com/organizations
Token confidentialityAccess tokens are kept only in the browser's MSAL cache; they are never logged server-side

Because authorization runs against the cross-tenant /organizations endpoint, any work or school account from any Microsoft Entra directory can technically authenticate. Whether that person actually gets access to MDM Lite afterwards is decided exclusively by authorization within MDM Lite (tenant membership, see Section 6) — not by Entra authentication alone.

Supported identity providers / account types

Account typeSupported
Microsoft Entra ID work or school accountYes — the only supported account type
Personal Microsoft account (Outlook.com, Xbox Live, …)No
Other identity providers (Google, SAML IdPs, Okta, …)No — MDM Lite offers SSO exclusively through Microsoft Entra ID
Entra ID B2B guest account in a foreign directoryTechnically possible, but not the intended path — see Section 6

2. Licensing requirements

ComponentRequirement
MDM LiteSaaS subscription from Data Prudentia GmbH. Specific plans, user counts, and terms are agreed with your Data Prudentia contact (see Section 10).
Microsoft Entra ID — basic SSOMicrosoft Entra ID Free is sufficient. Sign-in itself, admin consent, and directly assigning individual users to the enterprise application require no paid Entra ID license.
Microsoft Entra ID — Conditional Access / MFARequires Microsoft Entra ID P1 (or higher). Conditional Access policies for access to MDM Lite are optional but recommended.
Microsoft Entra ID — group assignmentAssigning security groups (instead of individual users) to the "MDM Lite – Data Prudentia" enterprise application also requires Entra ID P1.

MDM Lite itself requests no Microsoft Graph permissions (see Section 4) and is therefore usable independently of your Microsoft 365 licensing.


3. Required roles

On the customer IT side (in your own Entra directory)

Granting the application one-time consent (Admin Consent) requires one of the following Entra directory roles:

This role is only needed for the one-time consent. Ongoing operation (assigning users/groups, Conditional Access, revocation) still requires one of these roles, or a delegated permission on the relevant enterprise application.

On the MDM Lite side


4. Requested permissions

When signing in, MDM Lite requests only the following delegated permissions — all act on behalf of the signed-in person, never as an application permission (app-only):

Permission (scope)ResourceBusiness justification
openidMicrosoft Identity PlatformCore requirement for OpenID Connect: confirms the signed-in person's identity to MDM Lite.
profileMicrosoft Identity PlatformReads basic profile information of the signed-in account (name, account ID) so MDM Lite can display the person correctly in the UI and assign them a role.
offline_accessMicrosoft Identity PlatformEnables silent renewal of the access token during an active session, without requiring the person to sign in again.
api://f78dec68-a861-4a98-b8aa-9663fbba9953/access_as_userMDM Lite's own APIAllows the signed-in person to use the MDM Lite REST API on their own behalf (read/edit datasets according to their role). Without this scope the web UI cannot load any data.

Explicitly not requested: any Microsoft Graph permission — no reading of mailboxes, files, calendars, or Teams content, no directory or group access, no application permissions (app-only access). The app registration's requiredResourceAccess contains no resource other than its own API. MDM Lite can technically only do what the signed-in person is themselves allowed to do within MDM Lite.


5. Application identification

Check these values in the consent dialog and in your list of enterprise applications to uniquely identify the application:

AttributeValue
Application nameMDM Lite – Data Prudentia
Application ID (client ID)f78dec68-a861-4a98-b8aa-9663fbba9953
Verified publisherData Prudentia GmbH (verified through the Microsoft AI Cloud Partner Program)
Publisher domaindata-prudentia.com
Application address (redirect URI)https://mdm.data-prudentia.com
Privacy statementhttps://data-prudentia.de/datenschutz/
Terms of servicehttps://data-prudentia.de/impressum/
App registration signInAudienceAzureADMultipleOrgs (multi-tenant)

Consents granted before the branding update (2026-09-23) may still show the application under its earlier technical name mdm-lite-prod-frontend in your enterprise applications list. The application ID and publisher domain remain unchanged.


6. How MDM Lite maps users

MDM Lite maps a signed-in Entra account to a user account in MDM Lite via the account's immutable object ID (the oid claim that Entra issues in the token on every sign-in) — not via the email address.


7. Step-by-step setup

  1. A Data Prudentia contact sends you a consent link following this pattern (with your own Entra directory ID already inserted):

    https://login.microsoftonline.com/<directory-id>/adminconsent?client_id=f78dec68-a861-4a98-b8aa-9663fbba9953&redirect_uri=https://mdm.data-prudentia.com
    

    <directory-id> is the directory (tenant) ID of your Entra directory (Entra portal → Overview → Tenant ID).

  2. Open the link — preferably in a private browser window — and sign in with an account that holds one of the roles listed in Section 3.

  3. Review the values from Section 5 in the consent dialog and confirm with "Accept".

  4. Entra then redirects to https://mdm.data-prudentia.com. Seeing only the sign-in page at first is normal.

Once MDM Lite is listed in the Microsoft Entra App Gallery, you will alternatively be able to add the application directly from the Gallery to your directory (Entra portal → Enterprise applications → New application → search for "MDM Lite" → Create). The subsequent consent step matches Section 7.1. This path is only available once the Gallery submission is complete.

7.3 Controlling access (Conditional Access, MFA, assignment)

After consent, you will find the application under Entra portal → Enterprise applications → MDM Lite – Data Prudentia. All further controls remain entirely in your hands:

7.4 Onboarding in MDM Lite

Granting admin consent alone does not yet unlock MDM Lite — MDM Lite must know about your directory before anyone can sign in. Afterwards, please tell Data Prudentia:

  1. that consent was granted,
  2. your directory ID (tenant ID) — Data Prudentia records it as the directory binding, so that only accounts from your directory can sign in to your workspace,
  3. the email address of the first administrator for MDM Lite.

Data Prudentia then sets up your workspace and invites the named person as tenant admin. This person accepts the invitation by signing in with their Entra account, and can then invite all further users themselves — without any further involvement from your IT or additional Entra changes.


8. Testing steps for pilot users

Before extending access to more people, we recommend a test run with a single pilot user:

  1. Have the tenant admin invite the pilot user via profile menu → "Manage users" → Invitations, choosing the desired role (Viewer, Editor, or Admin).
  2. The pilot user receives an invitation email with an acceptance link and opens it.
  3. They sign in with exactly the account to which the invitation was sent (see Section 6).
  4. Expected result: After signing in, the "Welcome!" confirmation appears and the person lands in their workspace, with exactly the assigned role.
  5. Also verify signing out (profile menu → "Sign out") and signing back in, to confirm the full sign-in cycle.
  6. If you have enabled Conditional Access or "Assignment required": verify the pilot user is assigned in the enterprise application, or satisfies the Conditional Access policy (e.g. registered device, MFA), before running the test.

Once the test run succeeds, the tenant admin can add further people through the same invitation flow.


9. Error handling

9.1 Errors on the Entra side (AADSTS codes)

Code / messageMeaningResolution
AADSTS65001 — "Need admin approval"Your directory has not yet consented to the requested permissions (user consent is disabled, or restricted to verified publishers with selected permissions).Grant admin consent as described in Section 7.1 from an authorized account.
AADSTS50020 — "The selected user account does not exist in this tenant…"The sign-in ran against a foreign directory (for example because the browser was still signed in with a different account), or the account is a guest account that has not yet been added to the target directory.Retry sign-in in a private browser window and make sure you sign in with your own corporate account.
AADSTS50105 — "The signed-in user is not assigned to a role for the application""Assignment required" is enabled on your enterprise application, but the person is not assigned (see Section 7.3).Assign the person or their group to the "MDM Lite – Data Prudentia" enterprise application.
AADSTS50011 — "The reply URL specified in the request does not match the reply URLs configured for the application"Sign-in was started from an address other than https://mdm.data-prudentia.com, or there is a redirect URI configuration issue.Access MDM Lite exclusively via https://mdm.data-prudentia.com. If the problem persists, contact support (see Section 10).

9.2 Messages on the MDM Lite side

These messages appear after a successful Entra sign-in, while MDM Lite authorizes the sign-in:

MDM Lite messageMeaningResolution
"Your organization is being set up"Your directory has not yet been set up as a workspace in MDM Lite, or no first administrator has been invited yet.Complete onboarding as described in Section 7.4, or check with Data Prudentia.
"No access to this workspace"Your account is not (yet) a member of this workspace.Contact your MDM Lite tenant admin — they invite you via "Manage users".
"Wrong directory"This account does not belong to the Entra directory registered for your workspace.Sign in with the account from the correct corporate directory.
"Access blocked"An administrator has blocked this account's access to the workspace.Contact your MDM Lite tenant admin.
"Account blocked"The account has been blocked platform-wide.Contact support (see Section 10).
"This invitation was sent to a different email address"An attempt was made to accept an invitation with an account other than the invited one.Sign in with exactly the invited account, or request a new invitation to the correct address.
"This invitation has expired"The invitation link was not used in time.Ask your tenant admin to resend the invitation.

10. Support

For questions about the setup, please contact Data Prudentia GmbH: