---
title: OIDC Providers
slug: manufacturing-connect-edge/oidc-providers
docTags: 
createdAt: 2026-03-17T18:04:54.358Z
---

You can enable authentication through the OpenID Connect (OIDC) protocol to log in using your organization's identity provider. Manufacturing Connect acts as an OIDC client that connects to a configured OIDC provider. Manufacturing Connect supports both static and dynamic client registration.&#x20;

The OIDC providers page allows you to:

- View the list of configured OIDC providers.
- Add, edit, and delete OIDC providers.
- Assign Role-Based Access Control (RBAC) groups to users authenticating through OIDC.

:::hint{type="success"}
**Important Note:&#x20;**&#x57;hen working with OIDC providers, remember that:

- OIDC provider configurations are included in system backups.
- Users can export and import configurations through templates.
- The assigned RBAC Groups determine user access levels upon authentication.
:::

# Required OIDC Scopes for Microsoft Entra ID

When configuring Microsoft Entra ID as an OIDC provider for Manufacturing Connect, ensure the following standard scopes are enabled:

- openid
- email
- profile

Manufacturing Connect uses these scopes to authenticate users and retrieve basic identity information. No additional custom scopes or permissions are required.

# Access OIDC Providers

Navigate to **System&#x20;**>**&#x20;Access Control&#x20;**>**&#x20;OIDC Providers**. Here you can:

- **Add a provider**
  See [Add an OIDC Provider](docId\:b75Kv8Uhp3zkc_TOcnxrS) for details.
- **Name**
  View the identifier for the OIDC provider, for example, Keycloak or Okta.
- **Client ID**
  View the unique identifier for the client registered with the OIDC provider.
- **RBAC Group(s)**
  View user roles assigned via Role-Based Access Control (RBAC)
- **Actions**
  Access options to edit or delete an OIDC provider.

::Image[]{src="https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/MYYPRI7AqTlgdlHkxf0c7_image.png" size="80" width="1630" height="593" position="flex-start" showCaption="false"}

