Use Entra ID tenant restrictions through a corporate proxy

Configure SFTPPlus MFT to trust your corporate proxy's certificates when using Microsoft Entra ID with tenant restrictions v2.

SFTPPlus MFT can integrate with Microsoft Entra ID in networks that use a corporate proxy to apply tenant restrictions v2. These restrictions control access to external applications when people use accounts from other organizations on your network.

The proxy adds a policy header to Microsoft sign-in requests, and Entra ID enforces the policy. To insert that header, the proxy decrypts the HTTPS connection and presents a certificate issued by your organization's certificate authority (CA). SFTPPlus MFT needs to trust that CA to connect through the proxy.

Prepare the proxy ​

Ask your identity and network administrators to configure the policy and proxy using Microsoft's tenant restrictions v2 guide. The proxy inserts sec-Restrict-Tenant-Access-Policy with your tenant ID and policy ID for the Microsoft sign-in domains listed in that guide.

Proxy header insertion protects sign-ins; it does not block anonymous access to resources. Make sure the intended browser and server traffic passes through the configured proxy. Configuring a proxy in SFTPPlus MFT alone does not configure users' browsers.

Trust the proxy certificates in SFTPPlus MFT ​

Obtain the proxy's root and intermediate or issuing CA certificates from your network administrator. Create a separate trusted-certificates item in the SFTPPlus MFT vault containing those certificates.

Edit your Entra ID authentication method and set tls_trusted_certificates to the UUID of that vault item. This adds trust for the proxy CA on outgoing Entra ID and Microsoft Graph HTTPS connections. The Microsoft CAs distributed with SFTPPlus MFT remain trusted.

If you need an explicit proxy, set the authentication method's proxy option, for example to connect://proxy.example.com:3128. Leave it empty to inherit the general proxy configuration. See proxy connectivity for the available routing options.

SFTPPlus MFT Web Manager showing an Entra ID proxy and the CA V2 Chain vault item selected as additional trusted certificates in light mode.
Configure the proxy and select its CA certificate vault item under Additional trusted certificates in Web Manager.

Check sign-in through the proxy ​

Try a fresh Entra ID sign-in to the Web Client or Web Manager from the intended network. Confirm that permitted access succeeds and that an external account covered by a blocking policy is rejected.

If the connection fails with a certificate validation error, check the vault item and its CA chain with your network administrator. For a policy rejection, ask your identity administrator to review the Entra sign-in logs and the policy selected by the proxy header. After a proxy CA change, update the vault item and repeat the sign-in checks.