Base44 SSO with Microsoft Entra ID: which plan, what it covers, and the other route

Yes, a Base44 app can use Microsoft Entra ID sign-in, but only on an Enterprise plan (Business or Enterprise), which you buy through sales. Workspaces created before October 1, 2026 can still get it on Elite. The documentation doesn’t say how app roles come from Entra or whether an open session ends when IT disables someone. The other route is running the app on your own servers with Entra sign-in, while the team keeps building in Base44.

Updated October 9, 2026Based on Base44’s documentation and a lab test10 min read

Company sign-in for a Base44 app: three options

What IT usually asks about sign-in, and what each option answers. The first two columns come from Base44’s documentation as of October 9, 2026. The third is what Keep44 sets up, tested in a lab (details below).

IT questionPlans with public pricing (Free to Elite 1)Enterprise plans (Business or Enterprise, via sales)App on your own servers
1. Do people sign in with their work account, limited to your directory?NoYes, over OIDCYes, over OIDC with your tenant
2. Does Entra’s MFA apply?NoYesYes
3. Do app roles come from Entra?NoNot documentedYes, at every sign-in
4. Someone disabled in Entra: what happens to an open session?Removed by hand in the appNew sign-ins blocked; open sessions not documentedClosed within 5 minutes 2
5. Can password sign-in be turned off?NoSSO can be the only methodYes, with an optional emergency admin
6. Is there a record of who changed what?NoAudit logs at workspace levelWhatever IT configures on its server and database
7. Does the app spend Base44 credits in production?YesYesNo
8. What does it cost?$16 to $160 a month 3Quote from salesMigration from $5,000, plus a Base44 plan to keep editing

1 Elite workspaces created before October 1, 2026 keep app SSO. 2 3.6 minutes in the lab test; a new sign-in is blocked by Microsoft right away. 3 Billed annually, per Base44’s pricing page on October 9, 2026.

Which Base44 plan includes SSO?

Since October 1, 2026, SSO for apps is on the Enterprise plans, which Base44 calls Business and Enterprise. Neither appears on the pricing page: the public plans go from Free to Elite ($160 a month, billed annually), and Enterprise says to talk to sales for a quote.

Workspaces created before that date keep the earlier rule, Elite or higher. That’s why third-party reviews disagree on which plan you need: some were written before the change. Before talking to sales, check when your workspace was created.

One more thing to know before you ask: a “Sign in with Microsoft” button on a public plan isn’t company SSO. It accepts any Microsoft account and doesn’t remove someone who leaves.

On your own servers, sign-in is part of the app’s server, set up against your tenant. It doesn’t depend on the Base44 plan.

Workspace SSO or app SSO: which one does IT need?

Base44 has two separate features with similar names, and its docs cover them on different pages:

  • Workspace SSO is for the people who build in the Base44 editor. They sign in to the workspace with their company account. Adding and removing members automatically (SCIM) is set up separately.
  • App SSO is for the employees who use the published app. It supports Microsoft Entra ID, Google Workspace, Okta, GitHub and any OIDC provider. SAML isn’t listed.

For an internal app, the one IT asks about is app SSO: it decides who sees company data. Workspace SSO only controls who can edit the app.

On your own servers, the employees sign in to your server with Entra. The Base44 workspace is left to the few people who build, and they only see test data.

What Base44’s SSO docs leave out

The documentation explains how to connect the provider. It doesn’t answer four questions an IT review will ask:

  • Roles. It doesn’t say whether an app role (admin, user) can come from Entra, or whether it’s set by hand inside the app.
  • Leavers with an open session. To block someone it says to “remove or suspend them in your identity provider”. That stops the next sign-in. Whether a session that’s already open ends, and when, isn’t stated.
  • Audit. The audit logs API is for Enterprise workspaces. It isn’t stated whether it records changes to the app’s own data.
  • Sign-in domain. By default the login goes through app.base44.com even if the app has its own domain. There’s a setting to use your domain instead.

Context, not a warning: in July 2025, Wiz found a flaw that let anyone into private Base44 apps without signing in, SSO included. It was fixed within 24 hours. It shows that, in the cloud, the sign-in layer is the platform’s and not yours.

Entra ID sign-in on your own servers: what was tested

Keep44 moves the app’s backend to your server and adds its own sign-in layer in front of it. That layer lives outside the code Base44 syncs, so a change made in the editor can’t overwrite it. It uses OpenID Connect with PKCE, checks the token’s signature, and creates or updates the user in your database with no password.

Entra ID sign-in for a Base44 app on your own server An employee signs in with their work account and Microsoft MFA. Entra ID, your directory, assigns the app role or blocks the account. The sign-in layer on your server reads the role at every sign-in and checks every 5 minutes that the account is still enabled. Behind it runs the app built in Base44, with real data in your database. Syncs from Base44 update the app but never the sign-in layer. EMPLOYEE Work account Microsoft sign-in with MFA YOUR DIRECTORY Entra ID Assigns the role or blocks the account YOUR SERVER Sign-in layer Role at every sign-in rechecked every 5 min YOUR SERVER The app Built in Base44 real data in SQL Base44 syncs never touch sign-in
The app keeps being built in Base44. Sign-in belongs to your server and your directory.

Results of the lab test:

  • Work accounts: two test users signed in with their Microsoft account, including the password change and Authenticator on first sign-in.
  • Roles from Entra: one user was assigned the admin role and the other the user role. The server read the role at sign-in and enforced it (the user list loaded for the admin and was refused for the user).
  • No role, no entry: an account in the directory with no app role got past Microsoft but was turned away by the app, with a message to ask an administrator.
  • Offboarding: a user disabled in Entra while signed in was logged out 3.6 minutes later, with nothing touched on the server. A new sign-in was blocked by Microsoft.
  • Password sign-in off: the only way in was Entra.
  • A change from Base44: the text of the app’s own login screen was changed in the editor and synced to the server. Open sessions stayed valid, new sign-ins worked, and the sign-in page was still the company one.
Testing status

Tested in the lab on October 7 and 8, 2026: Windows Server 2025, IIS, SQL Server, Node.js and a free Entra ID tenant, with a demo app built in Base44. Not tested yet: HTTPS (the lab ran on localhost), roles assigned by group, Okta or Google, and on-premises Active Directory. This is the setup Keep44 offers; it hasn’t run with a client yet. Base44’s own SSO wasn’t tested: it needs an Enterprise plan, and everything said about it here comes from its documentation.

What the Entra admin should expect

If you manage Entra, none of this is new. These are the details that came up in the lab, in the order they appear:

  1. One app registration with app roles (for example admin and user) and assignment required turned on, so only people you assign can sign in.
  2. A Graph application permission (User.Read.All, with admin consent) so the server can check every few minutes that an account is still enabled. That’s what closes open sessions.
  3. A client secret with an expiry date. In the lab it was set to 180 days; renewing it is one command on the server. Put the date in IT’s calendar.
  4. MFA from the first sign-in. New tenants come with security defaults on, so users register Microsoft Authenticator the first time. Nothing to change on the app side.
  5. Roles by group need Entra ID P1 or P2. On the free tier, roles are assigned user by user.
  6. A long redirect. A guest account’s sign-in response was over 2,048 characters, the default query string limit in IIS, and the request never reached the app. Raising maxQueryString fixed it.

Registering the app and its roles took 20 to 30 minutes in the portal, plus one minute to configure the server. That was measured once, so take it as a rough guide.

One known gap: taking someone’s role away without disabling the account doesn’t end an open session until it expires (12 hours in the lab). Disabling the account does. If your process removes roles rather than accounts, say so in the Diagnosis.

Most companies with an on-premises Active Directory already sync it to Entra ID (Entra Connect or the newer Cloud Sync). In that case the same sign-in works: people use the account they already have.

If the directory never touches the cloud, the option is Windows Authentication in IIS on the internal network. Keep44 hasn’t tested it in the lab yet, so it’s checked case by case in the Diagnosis, never promised.

Base44 Enterprise or your own servers?

OptionWhen it fitsWhat stays the same
Enterprise planSign-in is IT’s only objection, and a new vendor review isn’t a problemThe app and its data run in Base44’s cloud; production spends credits; the contract and price are set by sales
Your own serversIT wants sign-in, data and backups inside its own systems, or the app has to reach internal systemsThe team keeps building in Base44 (Builder plan or higher, for GitHub sync)

On every plan except Enterprise, Base44’s license also allows company data to be used to train AI models. On your own servers that question goes away, because Base44 only sees test data. The full list of IT questions is in the Base44 security review checklist for IT, and how the move works is in the guide to running a Base44 app on-premise.

When Keep44 isn’t the answer: if your company already has a Base44 Enterprise plan, or a quote it’s happy with, and IT accepts the app in the cloud, set up Entra in Base44 following its documentation. Before signing, ask sales the four questions in what the docs leave out.

What IT needs to know

To paste into the review ticket. Each point needs a written answer before approval.

  • Plan: which Base44 plan the workspace is on, and when it was created (before or after October 1, 2026).
  • Which SSO: app SSO for the employees, not only workspace SSO for the builders.
  • Directory: sign-in limited to your tenant, with Entra’s MFA.
  • Roles: where each app role is assigned, in Entra or by hand in the app.
  • Leavers: what happens to an open session when an account is disabled, and how long it lasts.
  • Passwords: whether password sign-in is off, and who holds the emergency access.
  • Audit: where sign-ins and changes to the app’s data are recorded.
  • Secret: who renews the client secret, and when it expires.
  • Owner: who maintains the app and its sign-in, and what happens if the Base44 plan changes.

If you built the app

You don’t have to rebuild it. You keep changing it in Base44 with test data, and the changes reach the company server. The login screen you designed in Base44 is replaced in production by the company sign-in. You need a Base44 plan with GitHub sync (Builder, $40 a month billed annually, or higher). Bring IT this guide and the checklist above: it answers the sign-in part of their review before they ask.

Sources

Company sign-in that IT controls, without leaving Base44.

The Diagnosis reviews your app piece by piece and gives you a report to decide on: whether it can run on your servers with Entra ID sign-in, what has to be rebuilt, what IT needs to prepare, and a fixed price for the migration. All it takes is the code export and 30 minutes with someone who knows the infrastructure. See a sample report.

$500 · Fully credited if you go ahead with the migration · If the report doesn’t make the next step clear, you get a full refund

Not ready to book? Take the free 3-minute check and get a short report on screen.