Skip to main content

Signing In with Microsoft Azure

This article lists the steps you need to take in order to link Medialake to Microsoft Azure through

B
Written by Ben Keeling

Signing In with Microsoft Azure

How Microsoft Azure sign-in works in Medialake, how a Site Admin switches it on, and what has changed if you connected Azure through SAML2 in the past.



​

What to expect

Medialake offers Microsoft Azure as a single sign-on (SSO) option. When a Site Admin enables it, the login page shows a Microsoft Azure button. A user selects it, chooses or signs in to their Microsoft account, and is returned to Medialake already signed in. Nobody types a Medialake password, and Medialake never sees the Microsoft one.

There is nothing to configure on the Azure side. The app registration that connects Medialake to Microsoft is provisioned as part of your Medialake environment, so the only control in Medialake is the Azure switch on the Access page.


​

If you connected Azure through SAML2 in the past

Earlier versions of Medialake connected Azure by pasting an App Federation Metadata URL, an Identifier (Entity ID) and a Reply URL from an Azure enterprise application into a SAML2 form under Administration → Settings. That form no longer exists, and Azure is no longer connected through SAML2.

  • Azure sign-in is now switched on and off from Administration → Access, in the SSO section. No metadata, entity ID or reply URL is needed, and you do not need to maintain an enterprise application for Medialake in the Azure portal.

  • SAML2 in Medialake is now used for Ping and Okta. If your organization must sign in through one of those, see Setting Up SAML2 Single Sign-On with Ping or Okta.

  • The button on the login page reads Microsoft Azure.

  • Accounts created while the SAML2 connection was in use are ordinary Medialake accounts. People keep signing in to the same account as long as the address Microsoft reports for them matches the email address on the account — see Which accounts can sign in below.


​

Before you begin

  • You need to be a Site Admin. Regular users do not see the Administration menu.

  • SAML2 must be switched off. While a SAML2 provider is enabled, the SSO switches are locked and the section shows a SAML2 active tag.


​

Turning Microsoft Azure sign-in on or off

  1. Open the side menu and select Administration → Access.

  2. In the SSO section, find the Azure row.

  3. Turn the Enabled switch on. The Status changes to Connected and the Microsoft Azure button appears the next time the login page loads.

Turn the switch off to remove the button again. Either way, people who are already signed in stay signed in.


​

What users see

  1. On the login page, select Microsoft Azure.

  2. Microsoft shows its account picker. Medialake always asks Microsoft to offer the picker, so someone with several Microsoft accounts can choose the right one before signing in.

  3. After signing in at Microsoft, the user lands in Medialake.

If your organization's Microsoft settings require an administrator to approve applications before users can consent to them, Microsoft shows its own approval page instead of returning the user to Medialake. A Microsoft administrator must approve Medialake in your tenant before anyone can sign in this way.


​

Which accounts can sign in

Matching by email address. Medialake identifies the person by the User Principal Name of their Microsoft account — the sign-in name, for example [email protected] — and treats it as their email address. If a Medialake account with exactly that address exists, they sign in to it and keep their teams, roles and content.

If a person's User Principal Name is not the same as the email address on their Medialake account — for example [email protected] against [email protected] — Medialake does not recognize them as the same person. Either change the email address on their Medialake account from Manage Users to match the User Principal Name, or ask them to keep signing in with their email and password.

People without an account get one created on their first Microsoft sign-in only if their email address or domain is on the registration whitelist. Otherwise they are returned to the login page with Email or Domain registration not authorised. To allow them, open Administration → Manage Users, then the Settings tab, and use Add Whitelist in the Whitelist section to add a DOMAIN or an EMAIL — or invite them from Administration → Invitations, which adds their address to the whitelist automatically. A new account takes its name from the Microsoft display name, gets a personal team, and is a Regular User; a Site Admin can change the account type in Manage Users.

Deactivated accounts cannot sign in with Microsoft Azure.

Which Microsoft accounts are accepted — only accounts from your organization's tenant, or any Microsoft account — depends on how your Medialake environment was provisioned. Contact [email protected] if you need sign-in limited to your own tenant.


​

Using Azure alongside other sign-in methods

  • Email & password and Google can stay enabled at the same time. A user with a password can use either.

  • Enabling SAML2 (Ping or Okta) switches Azure and Google off and locks their switches. Disabling SAML2 later does not switch them back on — turn Azure on again yourself. If SAML2 is the only enabled method, enable Email & password before disabling it, because Medialake will not switch off the last sign-in method.


​

Troubleshooting

Symptom

What to check

The Microsoft Azure button is missing from the login page

The Azure switch is off, or SAML2 is enabled and has replaced the SSO buttons with its own Sign in with Ping or Sign in with Okta button.

The Azure switch is grayed out and the heading shows SAML2 active

Switch SAML2 off on the same page, then enable Azure.

SSO is disabled because one or more SAML2 integrations are active.

Same cause — disable SAML2 first.

At least one sign-in method must remain enabled.

You tried to switch off the last enabled method. Enable another one first.

A new user is returned to the login page with Email or Domain registration not authorised.

Their email address or domain is not on the registration whitelist. Add it, or invite them.

Someone signs in with Microsoft and lands in an empty account instead of their existing one

Their User Principal Name differs from the email address on their Medialake account. Align the two as described above.

Microsoft shows a page saying approval is needed

Your Microsoft tenant requires administrator consent for new applications. A Microsoft administrator needs to approve Medialake.

If the issue continues, contact [email protected] with your Medialake address and the message the user saw.


​

Related articles


Questions about Microsoft Azure sign-in? Contact [email protected].

Did this answer your question?