Set Up Single Sign-on (SSO) Using OpenID Connect (OIDC) for Entra ID

Microsoft Entra ID is a multi-tenant, cloud-based identity management system. Blackbaud provides an option for Entra ID setup, but you can also set up an SSO connection through the OIDC authentication protocol that enables third-party applications to verify end users and specify Entra ID as your IdP. An organization admin or a user with admin rights must claim your organization's email domains, configure the OIDC connection, test the connection, and then turn on SSO.

Tip: Instead of using OIDC to set up a connection with Entra ID, we recommend our Entra ID setup that simplifies configuration and management of SSO connections.

To prevent inadvertent lockouts, make sure to:

  • Complete the setup during a maintenance window for your organization's network.

  • Create a Blackbaud ID outside of your claimed domains with access to the Authentication settings page in Security.

Blackbaud doesn't support IdP-initiated connections. If you need to enable users to connect to Blackbaud solutions through an app in your IdP's portal, then after you turn on SSO, you must configure that app to use the redirect URL for your live connection.

Configure SSO

To set up your SSO connection using OIDC for Entra ID, use the instructions in the following sections: