# Authentication You can authenticate either by Entra ID applications or by Azure Managed Identities. ### Authentication Based on Entra ID Applications Microsoft integrations (Graph and Azure) in Cortex XSOAR use Entra ID applications to authenticate with Microsoft APIs. These integrations use OAuth 2.0 and OpenID Connect standard compliant authentication services, which use an application to sign in or delegate authentication. For more information, see the Microsoft identity platform overview. There are two application authentication methods available: * [Cortex XSOAR Application](https://xsoar.pan.dev/docs/reference/articles/microsoft-integrations---authentication#cortex-xsoar-application) * [Self-Deployed Application](https://xsoar.pan.dev/docs/reference/articles/microsoft-integrations---authentication#self-deployed-application) Depending on the authentication method that you use, the integration parameters might change. To use the **Cortex XSOAR application** and allow Cortex XSOAR access to O365 Outlook Mail Single User, an administrator has to approve our app using an admin consent flow by clicking this **[link](https://oproxy.demisto.ninja/ms-graph-mail-listener)**. After authorizing the Cortex XSOAR app, you will get an ID, Token, and Key which should be inserted in the integration instance settings fields. **Note**: These credentials are valid for a single instance only. **Note**: When authenticating with the Cortex application, sign in with the same user you want to integrate with. Since this user must grant consent for the app's permissions, they must be an **administrator**. To let a non-admin user use the app instead, after an admin has consented to the application once, go to the [Azure Portal](https://portal.azure.com/) > **Enterprise applications**, find the app, and set **Assignment required?** to **No**. This way, other users can obtain the Cortex application credentials without needing to sign in or consent themselves. Alternatively, you can use a **[Self-Deployed Application](https://xsoar.pan.dev/docs/reference/articles/microsoft-integrations---authentication#self-deployed-application)**. ### Authentication Based on Azure Managed Identities ##### Note: This option is relevant only if the integration is running on Azure VM. Follow one of these steps for authentication based on Azure Managed Identities: - ##### To use System Assigned Managed Identity - Select the **Use Azure Managed Identities** checkbox and leave the **Azure Managed Identities Client ID** field empty. - ##### To use User Assigned Managed Identity 1. Go to [Azure Portal](https://portal.azure.com/) -> **Managed Identities** 2. Select your User Assigned Managed Identity -> copy the Client ID -> paste it in the **Azure Managed Identities Client ID** field in the instance settings. 3. Select the **Use Azure Managed Identities** checkbox. For more information, see [Managed identities for Azure resources](https://learn.microsoft.com/en-us/azure/active-directory/managed-identities-azure-resources/overview). --- [View Integration Documentation](https://xsoar.pan.dev/docs/reference/integrations/microsoft-graph-mail-single-user)