Product Overview

Overview of Microsoft Azure OIDC

Microsoft Azure OpenID Connect (OIDC) is an identity authentication protocol provided through Microsoft Entra ID that enables applications to securely authenticate users and obtain identity information using standardized tokens. Built on the OAuth 2.0 framework, Azure OIDC supports enterprise security features such as Single Sign-On (SSO), Multi-Factor Authentication (MFA), Conditional Access, and centralized identity management. In this integration, Microsoft Entra ID acts as the OpenID Connect Identity Provider (IdP), authenticating users and issuing identity tokens that enable secure access to Utimaco Enterprise Secure Key Manager (ESKM).

Overview of ESKM

ESKM is a centralized key management solution that securely stores, distributes, and manages encryption keys throughout their lifecycle. It supports industry standards, including the KMIP, enabling integration with various enterprise applications and storage systems.

Joint Value Proposition

The integration of Utimaco Enterprise Secure Key Manager (ESKM) with Microsoft Azure OpenID Connect (OIDC) combines the secure key management capabilities of ESKM with standards-based user authentication and identity services. By leveraging Azure OIDC as the authentication mechanism, organizations can provide secure and centralized access to ESKM while simplifying identity management. Key benefits of the integration include:

  • Centralized authentication – Users can authenticate to ESKM using their existing enterprise identities.

  • Single Sign-On (SSO) – Provides a seamless authentication experience and reduces the need for multiple credentials.

  • Simplified user management – User identities and access policies can be managed centrally through the identity provider.

  • Enhanced security – Authentication can leverage advanced security controls such as Multi-Factor Authentication (MFA) and Conditional Access policies.

  • Reduced administrative overhead – Eliminates the need to maintain separate authentication credentials for ESKM users

Integration Architecture

Slide1-20260709-122904.jpg


Integration architecture

The integration architecture enables users to authenticate to Utimaco Enterprise Secure Key Manager (ESKM) using Microsoft Entra ID through the OpenID Connect (OIDC) protocol. When a user accesses the ESKM Management UI, ESKM initiates an OIDC authentication request and redirects the user to Microsoft Entra ID. After successful authentication, Microsoft Entra ID returns an ID token containing the user's identity claims. ESKM validates the token and associated claims before granting access to the ESKM management and administration functions.