1. Self-Hosting
  2. Single Sign-On
  3. Microsoft Entra
  • Home
  • What is TileDB?
  • Get Started
  • Explore Content
  • Accounts
    • Individual Accounts
      • Apply for the Free Tier
      • Profile
        • Overview
        • Cloud Credentials
        • Storage Paths
        • REST API Tokens
        • Credits
    • Organization Admins
      • Create an Organization
      • Profile
        • Overview
        • Members
        • Cloud Credentials
        • Storage Paths
        • Billing
      • API Tokens
    • Organization Members
      • Organization Invitations
      • Profile
        • Overview
        • Members
        • Cloud Credentials
        • Storage Paths
        • Billing
      • API Tokens
  • Catalog
    • Introduction
    • Data
      • Arrays
      • Tables
      • Single-Cell (SOMA)
      • Genomics (VCF)
      • Biomedical Imaging
      • Vector Search
      • Files
    • Code
      • Notebooks
      • Dashboards
      • User-Defined Functions
      • Task Graphs
      • ML Models
    • Groups
    • Marketplace
    • Search
  • Collaborate
    • Introduction
    • Organizations
    • Access Control
      • Introduction
      • Share Assets
      • Asset Permissions
      • Public Assets
    • Logging
    • Marketplace
  • Analyze
    • Introduction
    • Slice Data
    • Multi-Region Redirection
    • Notebooks
      • Launch a Notebook
      • Usage
      • Widgets
      • Notebook Image Dependencies
    • Dashboards
      • Dashboards
      • Streamlit
    • Preview
    • User-Defined Functions
    • Task Graphs
    • Serverless SQL
    • Monitor
      • Task Log
      • Task Graph Log
  • Scale
    • Introduction
    • Task Graphs
    • API Usage
  • Structure
    • Why Structure Is Important
    • Arrays
      • Introduction
      • Quickstart
      • Foundation
        • Array Data Model
        • Key Concepts
          • Storage
            • Arrays
            • Dimensions
            • Attributes
            • Cells
            • Domain
            • Tiles
            • Data Layout
            • Compression
            • Encryption
            • Tile Filters
            • Array Schema
            • Schema Evolution
            • Fragments
            • Fragment Metadata
            • Commits
            • Indexing
            • Array Metadata
            • Datetimes
            • Groups
            • Object Stores
          • Compute
            • Writes
            • Deletions
            • Consolidation
            • Vacuuming
            • Time Traveling
            • Reads
            • Query Conditions
            • Aggregates
            • User-Defined Functions
            • Distributed Compute
            • Concurrency
            • Parallelism
        • Storage Format Spec
      • Tutorials
        • Basics
          • Basic Dense Array
          • Basic Sparse Array
          • Array Metadata
          • Compression
          • Encryption
          • Data Layout
          • Tile Filters
          • Datetimes
          • Multiple Attributes
          • Variable-Length Attributes
          • String Dimensions
          • Nullable Attributes
          • Multi-Range Reads
          • Query Conditions
          • Aggregates
          • Deletions
          • Catching Errors
          • Configuration
          • Basic S3 Example
          • Basic TileDB Cloud
          • fromDataFrame
          • Palmer Penguins
        • Advanced
          • Schema Evolution
          • Advanced Writes
            • Write at a Timestamp
            • Get Fragment Info
            • Consolidation
              • Fragments
              • Fragment List
              • Consolidation Plan
              • Commits
              • Fragment Metadata
              • Array Metadata
            • Vacuuming
              • Fragments
              • Commits
              • Fragment Metadata
              • Array Metadata
          • Advanced Reads
            • Get Fragment Info
            • Time Traveling
              • Introduction
              • Fragments
              • Array Metadata
              • Schema Evolution
          • Array Upgrade
          • Backends
            • Amazon S3
            • Azure Blob Storage
            • Google Cloud Storage
            • MinIO
            • Lustre
          • Virtual Filesystem
          • User-Defined Functions
          • Distributed Compute
          • Result Estimation
          • Incomplete Queries
        • Management
          • Array Schema
          • Groups
          • Object Management
        • Performance
          • Summary of Factors
          • Dense vs. Sparse
          • Dimensions vs. Attributes
          • Compression
          • Tiling and Data Layout
          • Tuning Writes
          • Tuning Reads
      • API Reference
    • Tables
      • Introduction
      • Quickstart
      • Foundation
        • Data Model
        • Key Concepts
          • Indexes
          • Columnar Storage
          • Compression
          • Data Manipulation
          • Optimize Tables
          • ACID
          • Serverless SQL
          • SQL Connectors
          • Dataframes
          • CSV Ingestion
      • Tutorials
        • Basics
          • Ingestion with SQL
          • CSV Ingestion
          • Basic S3 Example
          • Running Locally
        • Advanced
          • Scalable Ingestion
          • Scalable Queries
      • API Reference
    • AI & ML
      • Vector Search
        • Introduction
        • Quickstart
        • Foundation
          • Data Model
          • Key Concepts
            • Vector Search
            • Vector Databases
            • Algorithms
            • Distance Metrics
            • Updates
            • Deployment Methods
            • Architecture
            • Distributed Compute
          • Storage Format Spec
        • Tutorials
          • Basics
            • Ingestion & Querying
            • Updates
            • Deletions
            • Basic S3 Example
            • Running Locally
          • Advanced
            • Versioning
            • Time Traveling
            • Consolidation
            • Distributed Compute
            • RAG LLM
            • LLM Memory
            • File Search
            • Image Search
            • Protein Search
          • Performance
        • API Reference
      • ML Models
        • Introduction
        • Quickstart
        • Foundation
          • Basics
          • Storage
          • Cloud Execution
          • Why TileDB for Machine Learning
        • Tutorials
          • Ingestion
            • Data Ingestion
              • Dense Datasets
              • Sparse Datasets
            • ML Model Ingestion
          • Management
            • Array Schema
            • Machine Learning: Groups
            • Time Traveling
    • Life Sciences
      • Single-cell
        • Introduction
        • Quickstart
        • Foundation
          • Data Model
          • Key Concepts
            • Data Structures
            • Use of Apache Arrow
            • Join IDs
            • State Management
            • TileDB Cloud URIs
          • SOMA API Specification
        • Tutorials
          • Data Ingestion
          • Bulk Ingestion Tutorial
          • Data Access
          • Distributed Compute
          • Basic S3 Example
          • Multi-Experiment Queries
          • Appending Data to a SOMA Experiment
          • Add New Measurements
          • SQL Queries
          • Running Locally
          • Shapes in TileDB-SOMA
          • Drug Discovery App
        • Spatial
          • Introduction
          • Foundation
            • Spatial Data Model
            • Data Structures
          • Tutorials
            • Spatial Data Ingestion
            • Access Spatial Data
            • Manage Coordinate Spaces
        • API Reference
      • Population Genomics
        • Introduction
        • Quickstart
        • Foundation
          • Data Model
          • Key Concepts
            • The N+1 Problem
            • Architecture
            • Arrays
            • Ingestion
            • Reads
            • Variant Statistics
            • Annotations
            • User-Defined Functions
            • Tables and SQL
            • Distributed Compute
          • Storage Format Spec
        • Tutorials
          • Basics
            • Basic Ingestion
            • Basic Queries
            • Export to VCF
            • Add New Samples
            • Deleting Samples
            • Basic S3 Example
            • Basic TileDB Cloud
          • Advanced
            • Scalable Ingestion
            • Scalable Queries
            • Query Transforms
            • Handling Large Queries
            • Annotations
              • Finding Annotations
              • Embedded Annotations
              • External Annotations
              • Annotation VCFs
              • Ingesting Annotations
            • Variant Statistics
            • Tables and SQL
            • User-Defined Functions
            • Sample Metadata
            • Split VCF
          • Performance
        • API Reference
          • Command Line Interface
          • Python API
          • Cloud API
      • Biomedical Imaging
        • Introduction
        • Foundation
          • Data Model
          • Key Concepts
            • Arrays
            • Ingestion
            • Reads
            • User Defined Functions
          • Storage Format Spec
        • Quickstart
        • Tutorials
          • Basics
            • Ingestion
            • Read
              • OpenSlide
              • TileDB-Py
          • Advanced
            • Batched Ingestion
            • Chunked Ingestion
            • Machine Learning
              • PyTorch
            • Napari
    • Files
  • API Reference
  • Self-Hosting
    • Installation
    • Upgrades
    • Administrative Tasks
    • Image Customization
      • Customize User-Defined Function Images
      • AWS ECR Container Registry
      • Customize Jupyter Notebook Images
    • Single Sign-On
      • Configure Single Sign-On
      • OpenID Connect
      • Okta SCIM
      • Microsoft Entra
  • Glossary

On this page

  • Prerequisites
  • Process
    • Create a new app registration in Azure
    • Get the issuer URL
    • Add a client secret
    • Add a claim
    • Upgrade your TileDB cluster
    • Test the configuration
  1. Self-Hosting
  2. Single Sign-On
  3. Microsoft Entra

Microsoft Entra SSO

Learn how to enable Microsoft Entra SSO in your TileDB workspace.

The goal of this guide is to help customers enable Microsoft Entra SSO for their clusters.

Warning

The procedures outlined in this doc depend on Microsoft Azure and its components. Microsoft Azure is subject to change at any time. Thus, you may need to take additional steps not highlighted in this doc to successfully set up Entra SSO with TileDB.

Prerequisites

To enable Entra SSO, you must complete the following:

  • Have a TileDB self-hosted cluster.
  • Have access to the Azure Portal.
  • Configure Microsoft Entra for each user. Each user must have an email address associated with their account, set in the Email field, with your organization’s Primary domain in Azure.
  • Have access to the original YAML file used to deploy the cluster.
  • Have knowledge and access to Helm.
  • Have knowledge and access to a terminal.

Process

The process for configuring Entra SSO with TileDB involves the following high-level steps:

  1. Create a new app registration in Azure.
  2. Get the issuer URL.
  3. Add a client secret.
  4. Add a claim.
  5. Upgrade your TileDB cluster.
  6. Test your configuration.

Create a new app registration in Azure

  1. Log in to your Azure Portal.
  2. Open Microsoft Entra ID.
  3. From the Overview window, take note of the Primary domain (which this tutorial references as <SSO_DOMAIN>).
  4. Under the Manage menu, select App registrations.
  5. Select + New registration.
  6. Enter a Name for the registration.
  7. Select the appropriate Supported account types.
  8. Enter a Redirect URI. The Redirect URI is of the form <scheme>://<uri>/auth/sso/callback/perdomain, where <scheme> is the scheme you use for your site (http or https), and <uri> is the console URI you use to log in to TileDB (which you can find in your values.yaml file under tiledb-cloud-ui.ingress.url[0]).
  9. Select Register.

Get the issuer URL

  1. On the App registrations page, make note of the Application (client) ID, referenced as <SSO_CLIENT_ID>.
  2. On the App registrations page, select Endpoints.
  3. Find the OpenID Connect metadata document field, and copy the URL. Paste the URL in a new tab or window in your browser.
  4. Find and copy the issuer details, referred to as <SSO_OIDC_ISSUER_URL>.

Add a client secret

  1. On the App registrations page, select Certificates & secrets.
  2. In the Azure Portal, open the Registered app page.
  3. In the Azure Portal, open the application you created, and navigate to Manage > Certificates & secrets.
  4. From the Client secrets tab, select + New client secret. Set a description to help others identify this secret and an expiration date.
  5. Select Add to create the secret.
  6. In the Value column, select the Copy to clipboard button to copy the client secret. Copy the Value (referenced as <SSO_CLIENT_SECRET>). Note: The Value will only display once and disappear after navigating away from the current page.

Add a claim

  1. Navigate to Manage > Token configuration.
  2. Add the following optional claims:
    • email: The addressable email for this user, if the user has one. Note: The email claim is mandatory to exist for SSO to work with TileDB.
    • preferred_username: The preferred username claim, so apps can give username hints and show human readable display names.

Upgrade your TileDB cluster

  1. Update your values.yaml file with the following information, creating any missing keys if necessary:

    tiledb-cloud-rest:
      restConfig:
        SSO:
          OIDC:
            - Domain: <SSO_DOMAIN>
              OIDCIssuer: <SSO_OIDC_ISSUER_URL>
              OIDCClientID: <SSO_CLIENT_ID>
              OIDCClientSecret: <SSO_CLIENT_SECRET>
  2. Run an upgrade on your cluster, swapping your initial helm install command with helm upgrade (or helm upgrade --install if you prefer) and submitting your new values file configurations. For example:

    helm upgrade --install \
     --namespace tiledb-cloud \
     --values values.yaml \
     tiledb-cloud \
     tiledb/tiledb-cloud-enterprise

Test the configuration

  1. Open the TileDB console, and select Company SSO.
  2. Enter your email address in the Corporate email field, and select Continue with single sign-on. If everything is configured correctly, your browser should bring you to the Microsoft login, where you’ll sign in with your Microsoft credentials.
  3. After signing in, you should be redirected back to the TileDB console, where you’ll be logged in.
Okta SCIM
Glossary