Security & access
Authentication & session
Single sign-on — Microsoft Entra ID
OIDC · tenant contoso.onmicrosoft.com
Require multi-factor authentication (MFA)
Session timeout
30 minutes⌄
Secret storage
Azure Key Vault (managed identity)Recommended
Secrets are held server-side and never reach the browser.
Browser localStorageNot recommended
Plain-text, per-browser. Legacy / single-user only.
Roles & access (RBAC)
| ROLE | MEMBERS | SCOPE | PERMISSIONS |
|---|---|---|---|
| Administrator | 3 | All organizations | Manage config, secrets, roles; view all |
| Auditor | 5 | Assigned orgs | View all dashboards + audit log; export |
| Viewer | 24 | Assigned projects | View dashboards only |
Role and scope changes are recorded in the audit log.