Odoo 19 identity and access
Microsoft sign-in for Odoo
A guided setup for employees, approved organisations, and external customers.
Microsoft Entra SSO gives Odoo administrators one clear place to connect Microsoft Entra ID or Microsoft Entra External ID. Match existing users, create approved accounts on first sign-in, and control how Microsoft-managed access maps into Odoo.
Audience
Choose who will sign in
Use one guided setup for each Microsoft audience.
People in your organisation
Connect one Microsoft Entra tenant for employees and other internal Odoo users.
People in approved organisations
Admit selected partner or customer tenants with an exact tenant allow-list that you control.
Customers and external users
Use Microsoft Entra External ID and create portal users by default for customer-facing access.
Connection
Connect your Microsoft application with confidence
Every required value, redirect URL, and check appears in one guided flow.
The wizard displays the Odoo callback and Microsoft logout URLs, then asks for the Tenant ID, Application ID, and client secret issued by Microsoft Entra.
Validate Microsoft discovery metadata and signing keys before activation, then complete an interactive sign-in test before making SSO available to users.
Exact configuration values
Copy the callback and logout URLs from Odoo and keep the Microsoft application identifiers together in the setup wizard.
Validate before activation
Check Microsoft discovery information and signing keys, then prove the connection with a real interactive sign-in.
Standards-based authentication
Use OpenID Connect authorization code flow with PKCE without requiring Microsoft Graph permissions for standard sign-in.
Provisioning
Decide how users join Odoo
Match an existing account or create only the users your connection admits.
Match existing users
Link Microsoft sign-in to one active Odoo user with the same email address.
Create approved users on first sign-in
Automatically create an Odoo account when an admitted person signs in for the first time.
Apply the right account type
Workforce connections create internal users, while External ID connections create portal users by default.
Access control
Control access after sign-in
Apply Microsoft identity and access rules without complicating the familiar Odoo login experience.
Microsoft group and app-role mapping
Map Entra security-group Object IDs or application roles to selected Odoo access groups.
Access synchronisation at sign-in
Keep Microsoft-managed access aligned whenever an existing user signs in again.
Useful sign-in events
Give administrators redacted diagnostic information without exposing credentials or tokens.
Microsoft-only interactive login
After testing, disable Odoo password login and require Microsoft SSO for interactive users.
Microsoft and Odoo logout
End the Odoo session, use Microsoft sign-out, and support front-channel logout.
Multiple connections
Configure separate connections for employees, approved organisations, and customer audiences.
Rollout
A clear path to go-live
Configure, validate, test, and only then enable Microsoft sign-in for your users.
Choose users
Select the employee, approved-organisation, or customer audience that needs access.
Register the application
Add the Odoo callback and logout URLs to your Microsoft Entra application.
Validate the connection
Run the built-in checks and activate the connection only after they pass.
Test sign-in
Complete a real Microsoft sign-in before enabling Microsoft-only login.
Microsoft sign-in for Odoo
Ready to connect Odoo and Microsoft Entra?
Purchase the module on Odoo Apps. Configuration and access remain controlled by your own Odoo and Microsoft Entra environments.