Entra ID / Azure AD

With native support for EntraID SSO, you can integrate users and administrators with SFTPPlus HTTP based services.

Integrating Entra ID SSO with SFTPPlus MFT

SFTPPlus MFT (Managed File Transfer) offers native support for Entra ID (formerly Azure Active Directory) SSO (Single Sign-On), enabling organizations to leverage their existing identity management systems for file transfer operations. This integration streamlines user authentication, enhances security, and simplifies user administration by centralizing control within a single system.

Authentication with Entra ID

The authentication process in SFTPPlus MFT for Entra ID users is based on the OAuth 2.0 Connect ID protocol, a modern and secure standard for delegated authentication. When an Entra ID user attempts to access an SFTPPlus service, they're redirected to the Microsoft identity platform to authenticate. This process ensures that SFTPPlus never has direct access to user credentials.

The integration supports authentication for multiple services, including:

  • HTTPS file transfers: Users can securely transfer files via the web interface using their Entra ID credentials.
  • Administration: Entra ID users can be granted administrative permissions to manage the SFTPPlus MFT server, providing a consistent authentication experience for both end-users and administrators.

Key Benefits of Integration

Integrating Entra ID SSO with SFTPPlus MFT provides several advantages:

  • Centralized User Management: User accounts are managed directly within Entra ID. When a user is added, removed, or updated in Entra ID, these changes are reflected in SFTPPlus, reducing administrative overhead and ensuring account consistency.
  • Enhanced Security: Leveraging Entra ID for authentication allows organizations to enforce multi-factor authentication (MFA), conditional access policies, and other security measures that are already configured in their identity system.
  • Simplified User Experience: Users can access SFTPPlus MFT using the same credentials they use for other Microsoft services, such as Office 365, providing a seamless and familiar login experience. This eliminates the need for users to remember separate passwords for file transfer services.

Technical Overview

You can check our documentation page dedicated to Entra ID for a detailed technical description on how to integrate SFTPPlus MFT and Entra ID.

To configure the integration, an administrator registers SFTPPlus as an application within the Entra ID tenant. This process generates the necessary client ID and secret, which are then configured within the SFTPPlus management console.

The Entra ID OAuth 2.0 workflow is initiated when a user attempts to log in.

You can configure different permissions and access level in SFTPPlus based on different Entra ID group membership.

Get support and assistance from file transfer experts

With more than two decades of experience, our support team has assisted organizations in implementing secure transfers and migrating from older systems.

Whether you're moving from legacy OS or LDAP users to stand-alone application users or to cloud SSO systems like Entra ID, our team is available to help.

Contact us to learn how we can assist with your Entra ID implementation.