Does iDBQuery work with Microsoft Entra ID (Azure AD) single sign-on?

Yes. iDBQuery integrates with Microsoft Entra ID (formerly Azure AD) for single sign-on over SAML 2.0 and OpenID Connect, so users authenticate with their Microsoft work accounts. Entra groups can map to iDBQuery roles, and disabling a user in Entra immediately revokes their iDBQuery access.

If your organisation runs Microsoft 365, iDBQuery slots into your existing Entra ID (Azure AD) identity so people sign in with the account they already use.

  • Enterprise SSO - authentication happens through Entra over SAML or OpenID Connect; iDBQuery relies on your tenant's sign-in policies, including conditional access and MFA.
  • Group-driven roles - map Entra security groups to iDBQuery roles so permissions match your directory rather than being maintained by hand.
  • Instant deprovisioning - offboarding a user in Entra ends their iDBQuery session, which keeps access reviews simple.
  • Deploys anywhere - cloud, your VPC, or air-gapped on-prem; iDBQuery talks to whichever Entra endpoint your architecture allows.

A practical example: a new analyst is added to the 'Data Team' group in Entra, and on first visit to iDBQuery they land in the correct project with read access already applied. Nothing about SSO changes iDBQuery's core stance on data - it queries your sources in place, cites every figure back to the exact source row, and encrypts traffic in transit and data at rest. SSO simply lets your identity provider decide who gets in, while RBAC decides what they can see. Contact us for the Entra enterprise-application configuration steps.

Updated 2026-06-22