Integrating Microsoft Entra ID with Security Center SaaS for SSO using OpenID Connect

2026-07-22Last updated

To enable single sign-on (SSO) throughout your organization, you can integrate Microsoft Entra ID with Security Center SaaS with help from the Genetec™ Technical Assistance Center (GTAC).

Before you begin

  • Learn about third-party authentication in Security Center SaaS.
  • Ensure you have administrator access to your Microsoft Entra ID tenant and permission to manage consent for enterprise applications.
  • Refer to your identity provider's documentation for the details on applying the generic instructions detailed here.

What you should know

Genetec schedules a collaborative setup call to configure and test your SSO integration. This typically lasts around 15 minutes.
After the integration is completed, SSO authentication is enabled for most Genetec cloud-based products and online services. Using the new integration, your users can sign in to the following:
  • Security Center SaaS
  • Genetec™ Airport Badging Solution (ABS)
  • Genetec ClearID™
  • Genetec Clearance™
  • Genetec Cloudrunner™
  • Genetec Operations Center
  • Genetec Portal (genetec.com)

Procedure

  1. Your integrator creates a new case with GTAC and includes the necessary information:
    • Email contact for the Microsoft Entra ID administrator. They must have sufficient privileges and expertise to set up an application integration for their identity provider and manage consent for enterprise applications.
    • Domains used by the users during sign-in. For example, for users who sign in with myuser@company.com, the domain is company.com.

      This list must include the domains for your users' emails and usernames. Corporate SSO does not work if the email and username domains are not configured for your integration.

  2. Genetec verifies the information in the case and schedules a call with the IT administrator to configure the setup together.
  3. Attend the setup call.
    Genetec provides a link to a sign-in test sandbox. After this first sign-in, the Genetec Login enterprise application is added to your Entra ID tenant.
  4. Genetec assists your administrator in applying the required consent settings:
    1. Review Microsoft's documentation on consent settings:
      Note:
      The Allow user consent for apps from verified publishers option produces the same result as Do not allow user consent, because Genetec Login isn’t published in the Microsoft Entra ID Marketplace.
      If you do not configure the consent settings, your users might encounter a "Need admin approval" dialog from Microsoft:
      Need admin approval dialog in Microsoft Entra ID indicating that Admin consent settings have not been configured.
    2. In the left sidebar of the Genetec Login enterprise application, click Admin consent requests, and configure the admin consent settings.
  5. Test your SSO integration.
    Signing in with the test link confirms that your identity provider is returning the expected responses.
  6. Genetec moves the server configuration out of the test sandbox to enable third-party authentication for all users. Using the new Microsoft Entra ID integration, your users can sign in to the following:
    • Security Center SaaS
    • Genetec ClearID™
    • Genetec Clearance™
    • Genetec Cloudrunner™
    • Genetec Operations Center
    • Genetec Portal (genetec.com)
    Note:
    Users must still be manually invited to your Security Center SaaS system. To automate this process, see Setting up automatic user provisioning.
  7. (Optional) To use Microsoft Entra ID Conditional Access policies, choose one of the following methods:
    Note:
    Microsoft Entra ID Conditional Access policies are not supported when signing in to the SC SaaS Operation mobile application.
    • Update the configuration files on the Genetec™ Operation desktop and Genetec™ Configuration desktop workstations to send Device identifier and Device state signals.
      1. On each workstation, open the generalsettings.gconfig file found in the %USERPROFILE%\AppData\Local\Programs\Genetec\Security Center SaaS\ConfigurationFiles folder.
      2. In the <configuration> section, add the following:
        <Login UseWebView2="true" />
        <WebBrowser AllowSingleSignOnUsingOsPrimaryAccount="true" />
        The AllowSingleSignOnUsingOsPrimaryAccount setting enables automatic sign-in using the workstation's current credentials.
    • Update your Microsoft Entra ID configuration to use a conditional access rule that does not rely on Device identifier and Device state signals.

After you finish

Transfer existing users to your new corporate SSO login service.