Security & access

Authentication & session

Single sign-on — Microsoft Entra ID

OIDC · tenant contoso.onmicrosoft.com


Require multi-factor authentication (MFA)

Session timeout
30 minutes

Secret storage

Azure Key Vault (managed identity)Recommended

Secrets are held server-side and never reach the browser.

Browser localStorageNot recommended

Plain-text, per-browser. Legacy / single-user only.

Roles & access (RBAC)

ROLEMEMBERSSCOPEPERMISSIONS
Administrator3All organizationsManage config, secrets, roles; view all
Auditor5Assigned orgsView all dashboards + audit log; export
Viewer24Assigned projectsView dashboards only

Role and scope changes are recorded in the audit log.