Microsoft Entra ID is often at the center of an organization's identity and access strategy. But as organizations adopt Zero Trust, simply authenticating a user is no longer enough. Access decisions increasingly need to consider additional authentication requirements, device context, and organizational security policies.
For organizations already using Microsoft Entra ID, replacing the existing identity provider may be unnecessary and disruptive. What if organizations could keep Microsoft Entra ID as their primary Identity Provider while adding another layer of authentication and access controls?
With the new SureIdP External Authentication Method (EAM) integration for Microsoft Entra ID (now referred to by Microsoft as External MFA), organizations can do exactly that.
SureIdP can act as an external MFA provider while Microsoft Entra ID continues to handle primary authentication and access decisions. The integration works with Microsoft Entra Conditional Access and does not require domain federation.
The Challenge
Adding another authentication provider to an existing identity environment can introduce unnecessary complexity. Organizations may not want to replace Microsoft Entra ID, federate their domain, or maintain a separate authentication architecture.
At the same time, some applications and access scenarios may require an additional authentication step beyond primary authentication. Organizations need a way to extend their existing Entra authentication environment without disrupting their existing identity architecture.
What's New: SureIdP as an External Authentication Method
SureIdP can now be configured as an External Authentication Method in Microsoft Entra ID.
Microsoft Entra ID continues to handle primary authentication and remains the organization's primary IdP. When a Conditional Access policy requires multifactor authentication, Microsoft Entra ID can invoke SureIdP to complete the additional authentication step.
The flow is simple:
User signs in to Microsoft Entra ID → Conditional Access evaluates the request → SureIdP performs external MFA → Microsoft Entra validates the result → Application access is granted
This allows organizations to add SureIdP authentication to their existing Entra environment without changing their primary identity architecture.
Trigger SureIdP Authentication with Conditional Access
The integration brings SureIdP into the Microsoft Entra Conditional Access workflow.
Administrators can configure Conditional Access policies to determine when additional authentication is required. When those conditions are met, SureIdP can be invoked as the external authentication method.
This allows organizations to apply stronger authentication based on specific access requirements, users, groups, or applications instead of applying the same authentication requirements to every sign-in.
Keep Microsoft Entra ID as the Primary IdP
A key advantage of SureIdP EAM is that organizations don't have to replace Microsoft Entra ID or federate their domain.
Each platform continues to serve its intended role:
- Microsoft Entra ID: Primary identity provider and access control platform
- Conditional Access: Determines when additional authentication is required
- SureIdP: Performs the external authentication step
- Applications: Continue to use the existing Entra authentication flow
This enables organizations to extend their existing Microsoft Entra authentication environment while continuing to use their current identity and access architecture.
Simplify Onboarding with JIT Provisioning
SureIdP EAM also supports Just-in-Time (JIT) provisioning.
When enabled, users who don't already have a SureIdP account can be automatically provisioned during their first successful external authentication. This reduces the need for administrators to manually create users before they can use SureIdP authentication.
Organizations that require tighter control can disable JIT provisioning and use their preferred user provisioning process.
Key Benefits
Extend Microsoft Entra Without Replacing It
Add SureIdP authentication while keeping Microsoft Entra ID as the primary IdP.
Add Authentication Where It Matters
Introduce an additional authentication layer for applications and access scenarios that require stronger verification.
Use Conditional Access
Let Microsoft Entra Conditional Access determine when SureIdP authentication should be triggered.
Avoid Domain Federation
Integrate SureIdP as an external authentication method without federating the organization's domain.
Simplify User Onboarding
Use JIT provisioning to automatically provision users when they authenticate through SureIdP for the first time.
Final Thoughts: Extend Microsoft Entra with SureIdP
Organizations can extend their existing Microsoft Entra authentication environment without replacing their primary identity provider.
With SureIdP External Authentication Method for Microsoft Entra ID, organizations can keep Entra ID as their primary identity provider, use Conditional Access to determine when additional authentication is required, and leverage SureIdP for the external authentication step.
FAQs
What is Microsoft Entra External Authentication Method (EAM)?
Microsoft Entra External Authentication Method (EAM), also referred to as External MFA, allows organizations to integrate an external authentication provider with Microsoft Entra ID. Entra ID continues to handle primary authentication, while the external provider performs the additional MFA step.
How does Microsoft Entra Conditional Access work with SureIdP?
Administrators can configure Microsoft Entra Conditional Access policies to determine when additional authentication is required. When a sign-in meets the configured conditions, Entra ID can invoke SureIdP as the external MFA provider. SureIdP completes the additional authentication step, and Entra ID validates the result before granting access.
Does integrating SureIdP require federating our domain or replacing Microsoft Entra ID?
No. SureIdP integrates as an External Authentication Method (EAM) via OpenID Connect (OIDC). Microsoft Entra ID remains the primary Identity Provider (IdP), and your domain setup stays intact without requiring federation.
Do users need to be pre-provisioned in SureIdP before authenticating?
Not necessarily. SureIdP EAM supports Just-in-Time (JIT) provisioning, which automatically creates a user account in SureIdP during their first successful authentication attempt. However, administrators can disable JIT provisioning and use manual or other supported user provisioning methods instead.

