# Authenticate against Azure AD/OAuth

**URL:** <https://forums.rocket.chat/t/authenticate-against-azure-ad-oauth/10420>\
**Category:** Community Support\
**Tags:** design, rocketchat-apps\
**Created:** [February 22, 2021, 12:07am UTC](https://forums.rocket.chat/t/authenticate-against-azure-ad-oauth/10420 "2021-02-22T00:07:08Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![realzenu](https://avatars.discourse-cdn.com/v4/letter/r/13edae/32.png) [@realzenu](https://forums.rocket.chat/u/realzenu)\
**Post date:** [February 22, 2021, 12:07am UTC](https://forums.rocket.chat/t/authenticate-against-azure-ad-oauth/10420/1 "2021-02-22T00:07:08Z")

</div>

### Description

Unable to get authentication using Azure AD and RocketChat OAuth.

Does anyone have a good guide to point to?

### Server Setup Information

- Version of Rocket.Chat Server: 3.10.5
- Operating System: Redhat Enterprise 8
- Deployment Method: SNAP
- Number of Running Instances: 1
- DB Replicaset Oplog:
- NodeJS Version: v12.18.4
- MongoDB Version: 3.6.14
- Proxy: nginx
- Firewalls involved:

### Any additional Information

my current config

URL: [https://login.microsoftonline.com/common/](https://login.microsoftonline.com/common/)  
Token Path: /oauth2/token  
Token Sent Via: Header  
Identity Token Sent Via: Same as “Token Sent Via”  
Identity Path: /openid/userinfo  
Authorize Path: /oauth2/authorize  
Scope:openid  
Param Name for access token: access\_token  
id:azure app id  
secret: app secret  
login style: popup

---

<div class="post-metadata">

**Author:** ![MJPGPleasant](https://avatars.discourse-cdn.com/v4/letter/m/f14d63/32.png) [@MJPGPleasant](https://forums.rocket.chat/u/MJPGPleasant)\
**Post date:** [March 2, 2021, 4:42pm UTC](https://forums.rocket.chat/t/authenticate-against-azure-ad-oauth/10420/2 "2021-03-02T16:42:41Z")

</div>

Hello,

Never found a good guide but did manage to get the environment up and functioning. Used [Is RocketChat not compatible with OAuth2 and Office365? · Issue #6809 · RocketChat/Rocket.Chat · GitHub](https://github.com/RocketChat/Rocket.Chat/issues/6809) as a base point to start.

The current config you have above is identical - With the caveat that we point the logon URL direct to the tenant: [https://login.microsoftonline.com/](https://login.microsoftonline.com/){tenant id}/
