Hello
We are evaluating EspoCRM authentication through OIDC with Microsoft Entra ID.
Microsoft Entra ID would enforce multi-factor authentication through its own policies. We would like to understand the recommended EspoCRM configuration for this setup.
Thank you.
We are evaluating EspoCRM authentication through OIDC with Microsoft Entra ID.
Microsoft Entra ID would enforce multi-factor authentication through its own policies. We would like to understand the recommended EspoCRM configuration for this setup.
- Should EspoCRM's native two-factor authentication be disabled for users authenticating through OIDC?
- Is Microsoft Entra OIDC with Entra MFA considered a supported production configuration?
- Can native EspoCRM authentication remain enabled for a local emergency administrator account?
- How should multi-factor authentication be enforced for such a local emergency account?
- Are there any known conflicts between forced EspoCRM 2FA and OIDC authentication?
- Is it possible to prevent regular users from using local password authentication while retaining it for a designated administrator?
Thank you.

Comment