evosecurity

Integrations

Microsoft EAM integration

Overview

This guide walks you through connecting Microsoft Entra ID’s External Authentication Method (EAM) with the Evo Portal, so your users can satisfy Microsoft’s MFA prompts using Evo’s authentication. Microsoft EAM integration will be set up on a per-directory basis.

Note: Users must be synced via an Entra ID Directory ( Formerly Azure Active Directory ) for this integration to work. Required Roles to manage EAM integration on the Evo Portal. Evo Admin → Permissions → Roles

  • View Directories Section
  • Add Policy
  • Edit Policy
  • View Policy

Setup

  1. Locate the Integrations tab under Evo Admin
  1. Navigate to Microsoft EAM and hit Configure
Notion image
  1. Once here you’ll be shown the list of Directories you have Microsoft EAM configured for. To select a new directory hit the +New on the top right
Notion image
  1. From here you will select the Directory you wish to Enable with Microsoft EAM and once selected hit Enable EAM on far right
Notion image

Once here you’re going to be greeted with settings to bring over and configure in your Microsoft Entra ID ( Formerly Azure Active Directory ) application.

Notion image

Setup Instructions:

  1. Access Microsoft Entra Admin Center: Log in to your Entra ID tenant at https://entra.microsoft.com as a global administrator.
  1. Navigate to Authentication Methods: Go to Authentication Methods → Policies.
  1. Add External Method: Click + Add External Method.
  1. Configure Method Details: Enter a descriptive name (e.g., "Evo MFA") - users will see this name during authentication. Copy and paste the Client ID from above Copy and paste the Discovery Endpoint from above Copy and paste the App ID from above
    1. Notion image
  1. Grant Admin Consent: If you see "Request permission" instead of "Admin consent granted", verify the App ID is correct, then click the permission button and check "Consent on behalf of your organization" before accepting.
  1. Configure User Targeting: Choose which groups should have access to this authentication method. By default, it applies to all users with MFA requirements. (If using EAM for Web Accounts, setup a group for the Web Accounts users and target that group)
  1. Enable the Method in Entra: In Entra, below the fields toggle Enable from Off to On if you want to activate immediately.
  1. Save Configuration: Click Save to create the Evo external authentication method.
 

Note: Microsoft Entra ID may take up to 10-15 minutes to apply new External Authentication Settings. If sign-ins fail during this time, try again shortly.

 

Microsoft EAM is now setup!

Notion image
 

Configuration

Notion image

The EAM integration now includes additional configuration options to simplify assigning newly created web accounts to the appropriate Microsoft Entra group and External Authentication Method.

Select the Microsoft Entra group targeted by your EAM policy. New web accounts created through this tenant will automatically be added to this group, making them eligible to use the configured external authentication method (EAM). Additionally, you can Create the Security Group from within the Evo portal.

Notion image

Select the External Authentication Method (EAM) configured on the Setup tab. This method will be assigned to each web account created through the integration, ensuring the account is configured to authenticate using the intended EAM method.

Conditional Access Requirements for Microsoft EAM

Evo's Microsoft External Authentication Method (EAM) integration supports Microsoft Entra Conditional Access policies configured to Require multifactor authentication.

However, Microsoft currently does not support external authentication methods with Conditional Access authentication strengths.

Supported Conditional Access Settings

When configuring Conditional Access policies for Evo EAM, use the following settings:

  • Supported: Require multifactor authentication
  • Not Supported: Require authentication strength

The following authentication strengths are not currently compatible with Evo EAM:

  • Multifactor authentication strength
  • Passwordless MFA strength
  • Phishing-resistant MFA strength
  • Custom authentication strengths

Important Considerations

If a Conditional Access policy is configured to Require authentication strength, Microsoft Entra will not offer Evo EAM as an authentication option.

Instead, users will be required to authenticate using a Microsoft Entra-supported method that meets the configured authentication strength.

Note: This is a current Microsoft Entra limitation affecting external authentication methods, rather than a limitation specific to Evo.

Microsoft Documentation

Did this answer your question?
😞
😐
🤩