Guidance on how to build Login Screen with Entra ID

David G 0 Reputation points
2025-10-16T08:19:07.0133333+00:00

We are seeking guidance on how to build an advanced login screen utilizing Microsoft Entra ID Exterrnal ID.

This is the login experience we want to achieve for our customers:

User's image

Pleas note the "Microsoft" button. It redirects to https://login.microsoftonline.com/common/oauth2/v2.0/authorize
and enables logging in with all Kinds of Microsoft account types ('Accounts in any organizational directory (Any Microsoft Entra ID tenant - Multitenant) and personal Microsoft accounts (e.g. Skype, Xbox)'). Users are also able to sign-up and sign-in using their email addresses ('local' Accounts).

Our Architecture as we envision it right now on a high level:

We will have multiple frontend Apps (single-page and web apps) and backend services (web apis). The apps and services will be fronted by a BFF ("backend for frontends") which is a ASP.NET Core Web API utilizing YARP (yet another reverse proxy).

The BFF will also be responsible to validate the Browser cookies and fetch the tokens to enable proper auth accessing downstream apis.

Is it possible to manage access to the downstream apis for all types of customers - that is local, any Microsoft Entra ID tenant, as well as the other social IDPs and custom IDPs - utilizing only Microsoft Entra ?

I would have thought that this scenario is the most important real-world application that one would want to achieve for their customers, but I couldn't find any concise examples or tutorials, and after two days of reading through the Microsoft documentation, I have more questions than answers about which of the many Entra components I would need to combine to create a user experience like the one I described.

Any advice on this is very welcome!

Thanks! David

Microsoft Security | Microsoft Entra | Microsoft Entra External ID

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.