---
title: "Microsoft Entra SSO for Odoo 19 - WebsiteFuze"
description: "Connect Odoo 19 to Microsoft Entra ID or External ID with guided setup, approved provisioning, access mapping, PKCE, and controlled sign-in."
canonical_url: "https://websitefuze.com/modules/microsoft-entra-sso"
last_updated: "2026-07-18T12:37:46.783Z"
keywords: ["Microsoft Entra SSO for Odoo", "Azure SSO for Odoo", "Odoo 19 Microsoft login", "Microsoft Entra External ID Odoo", "Odoo OpenID Connect", "Odoo single sign-on module", "Microsoft SSO Odoo app"]
---

# Microsoft Entra SSO for Odoo

Category: Odoo

Compatibility: Odoo 19

Connect Odoo 19 to Microsoft Entra ID or External ID with guided setup, approved provisioning, access mapping, PKCE, and controlled sign-in.

Category: Odoo 19 identity and access

## Microsoft sign-in for Odoo

> A guided setup for employees, approved organisations, and external customers.

Microsoft Entra SSO gives Odoo administrators one clear place to connect Microsoft Entra ID or Microsoft Entra External ID. Match existing users, create approved accounts on first sign-in, and control how Microsoft-managed access maps into Odoo.

### Requirements

Requires Odoo 19, a Microsoft Entra tenant, and the PyJWT package with cryptography support installed on the Odoo server.

Category: Audience

## Choose who will sign in

> Use one guided setup for each Microsoft audience.

- **People in your organisation**: Connect one Microsoft Entra tenant for employees and other internal Odoo users.
- **People in approved organisations**: Admit selected partner or customer tenants with an exact tenant allow-list that you control.
- **Customers and external users**: Use Microsoft Entra External ID and create portal users by default for customer-facing access.

Category: Connection

## Connect your Microsoft application with confidence

> Every required value, redirect URL, and check appears in one guided flow.

The wizard displays the Odoo callback and Microsoft logout URLs, then asks for the Tenant ID, Application ID, and client secret issued by Microsoft Entra.

Validate Microsoft discovery metadata and signing keys before activation, then complete an interactive sign-in test before making SSO available to users.

- **Exact configuration values**: Copy the callback and logout URLs from Odoo and keep the Microsoft application identifiers together in the setup wizard.
- **Validate before activation**: Check Microsoft discovery information and signing keys, then prove the connection with a real interactive sign-in.
- **Standards-based authentication**: Use OpenID Connect authorization code flow with PKCE without requiring Microsoft Graph permissions for standard sign-in.

Category: Provisioning

## Decide how users join Odoo

> Match an existing account or create only the users your connection admits.

- **Match existing users**: Link Microsoft sign-in to one active Odoo user with the same email address.
- **Create approved users on first sign-in**: Automatically create an Odoo account when an admitted person signs in for the first time.
- **Apply the right account type**: Workforce connections create internal users, while External ID connections create portal users by default.

Category: Access control

## Control access after sign-in

> Apply Microsoft identity and access rules without complicating the familiar Odoo login experience.

- **Microsoft group and app-role mapping**: Map Entra security-group Object IDs or application roles to selected Odoo access groups.
- **Access synchronisation at sign-in**: Keep Microsoft-managed access aligned whenever an existing user signs in again.
- **Useful sign-in events**: Give administrators redacted diagnostic information without exposing credentials or tokens.
- **Microsoft-only interactive login**: After testing, disable Odoo password login and require Microsoft SSO for interactive users.
- **Microsoft and Odoo logout**: End the Odoo session, use Microsoft sign-out, and support front-channel logout.
- **Multiple connections**: Configure separate connections for employees, approved organisations, and customer audiences.

Category: Rollout

## A clear path to go-live

> Configure, validate, test, and only then enable Microsoft sign-in for your users.

1. **Choose users**: Select the employee, approved-organisation, or customer audience that needs access.
2. **Register the application**: Add the Odoo callback and logout URLs to your Microsoft Entra application.
3. **Validate the connection**: Run the built-in checks and activate the connection only after they pass.
4. **Test sign-in**: Complete a real Microsoft sign-in before enabling Microsoft-only login.

Category: Microsoft sign-in for Odoo

## Ready to connect Odoo and Microsoft Entra?

Purchase the module on Odoo Apps. Configuration and access remain controlled by your own Odoo and Microsoft Entra environments.

## Purchase

[Purchase on Odoo Apps](https://www.odoo.com/)
