Docs menu: Microsoft strategy
Provider strategy

vestibule_microsoft

Microsoft OAuth strategy that uses Microsoft Graph /me and supports tenant-specific sign-in.

When to use it

Use Microsoft if users sign in with Microsoft personal, work, or school accounts.

Default scopes: openid User.Read

Install

Vestibule packages are not available on Hex. Add them from GitHub with the moving v0 tag. Use Gleam 1.18 or later because companion packages use Git path dependencies.

[dependencies]
vestibule_microsoft = { git = "https://github.com/tylerbutler/vestibule.git", ref = "v0", path = "packages/vestibule_microsoft" }

Setup

  1. Create a Microsoft Entra ID app registration.
  2. Select the account types that your tenant supports.
  3. Add Web redirect URIs for each environment you demo from.
  4. Copy the Application client ID and client secret value.

Usage

import vestibule/config
import vestibule_microsoft
let strategy = vestibule_microsoft.strategy()
let tenant_strategy =
vestibule_microsoft.strategy_for_tenant(
"72f988bf-86f1-41af-91ab-2d7cd011db47",
)
let client_config =
config.new(
client_id: "microsoft-client-id",
redirect_uri: "http://localhost:8000/auth/microsoft/callback",
auth: config.ClientSecret("microsoft-client-secret"),
)

What Vestibule handles

  • The default strategy uses /common and performs no tenant validation.
  • strategy_for_tenant targets tenant-specific endpoints.
  • Tenant validation checks the tid claim in the returned ID token.
  • userPrincipalName becomes the nickname. It is not a verified email address.

What you handle

  • Pass the tenant GUID, not a verified domain, when restricting to one tenant.
  • Microsoft Graph /me does not include profile photos. Fetch photos separately if needed.