Microsoft Entra ID and Dome
Entra already knows your people. Now your agents do.
An agent sends the user's Entra access token with each call. Dome verifies it against your tenant, and rules decide on that person's app roles. Audit records the agent and the person, every time.
How Dome helps
Dome provides verified identity and access control with Microsoft Entra ID
Verified against your tenant
Dome checks each token's signature, its issuer and its expiry. A token from another tenant fails the issuer check.
Rules read app roles
Entra puts the user's app roles in the roles claim by name. Rules match on them directly.
Groups when you need them
Security groups arrive as object IDs in the groups claim. Rules can match an ID as written.
Get started
Entra ID in three steps
Register your tenant with Dome, put roles in your app's access token, and have the agent pass the token on. Dome needs no Entra credentials of its own.
01
Register your tenant as a verification provider
Use the v2.0 issuer for your tenant ID. Pin the audience to your app's client ID.
$ dome verification-providers create \--name corporate-entra \--method oidc \--oidc-url https://login.microsoftonline.com/<tenant-id>/v2.0 \--oidc-expected-audience <client-id>02
Issue v2 tokens with roles
Set requestedAccessTokenVersion to 2 in your app's manifest, or tokens carry the v1 issuer and are refused. Define app roles and assign them; add the groups and email claims under Token configuration if rules need them.
03
Pass the user's token with each call
The agent keeps its own Dome key and adds the person's access token for your app as a header.
from openai import OpenAIclient = OpenAI(base_url=f"{GATEWAY_URL}/v1",api_key=DOME_AGENT_KEY,default_headers={"X-Dome-Act-As": user_entra_token},)
Commands and rules tested against a Dome workspace on October 1, 2026. For anything about Microsoft Entra ID itself, see Microsoft's documentation.
Rules
A rule on an Entra app role
Only people with the Repo.Maintainer app role may have an agent merge a pull request. Everyone else can still use the agent for the rest.
forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)when { resource.connection_name == "github" && resource.tool_name == "merge_pull_request"}unless { principal has act_as && principal.act_as.roles.contains("Repo.Maintainer")};Try it
One call, two outcomes
Switch the caller or the argument and watch the same call decide differently. Every decision lands in audit.
Acting for
- CallerToken verified against corporate-entra
- RolesRepo.Maintainer
- RuleMerges are open to Repo.Maintainer
Agent workflow
Bringing it together
Connecting Microsoft Entra ID to registered agents, tools, and models in Dome completes a governed agent application.
Acting for
Identity
Microsoft Entra ID
This page
Control point
Gateway
- Rules
- Guards
- Quotas
Every call decided and audited
FAQ
Common questions
Can Dome read Entra group names?
No. Entra puts group object IDs in the groups claim, so rules match the ID or use app roles, which arrive by name.
What happens when a user is in too many groups?
Above 200 groups, Entra leaves the groups claim out of the token. Rules on app roles keep working.
Which Entra token should the agent send?
A v2 access token issued for your own app. Tokens issued for Microsoft Graph don't verify outside Microsoft.
Does Dome need SCIM provisioning from Entra?
No. Dome has no SCIM endpoint and reads identity from each verified token as the call arrives.
Explore
More of what Dome works with
Model
Claude Fable
Fable 5.1 from Anthropic and Amazon Bedrock in one failover pool, open to one group and capped by quota.
Read moreProvider
Anthropic
The Claude API behind the Model Broker: the key held in Dome, every call authorized, metered and audited.
Read moreMCP server
Atlassian
The Atlassian Rovo MCP server behind the Tool Gateway, with rules that decide each Jira and Confluence call on its tool and site.
Read moreRuntime
OpenAI Agents SDK
OpenAI Agents SDK agents with their models on the Model Broker and their MCP tools on the Tool Gateway.
Read moreClient
Claude Code
Claude Code on a Dome Gateway with per-developer sign-in, rules on every tool call, and audit by name.
Read moreAgent service
TinyFish
TinyFish's web agents behind the Tool Gateway, with rules that decide each run on the site it targets.
Read moreNext steps
Talk with our FDE team
Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.
No card required to start. Register your first agent in minutes.
Identity providers for AI agents: a verified person on every call
Your identity provider already knows your people. Dome verifies that identity on every agent call, so rules and audit name the person an agent acted for.
See them all