Ticket: AUTH-T99 · Epic: E3 Authentication Core · Phase: Phase 5 — Backlog / spikes
Priority: Low · Estimate: 3 points · Labels: epic:auth-core, phase:5, spike, sso
Depends on:
Not a launch dependency. Investigate whether SGA can (a) get an app registered in Northeastern's Entra tenant via ITS, or (b) register a multi-tenant app in an SGA-owned tenant that Northeastern's tenant permits users to consent to, restricting sign-in to Northeastern's tenant id. If viable, prototype Better Auth's microsoft social provider behind a feature flag, linking to existing accounts by verified email. Report blockers, MFA inheritance (Duo), and the account-linking policy.
Acceptance criteria
Generated from the SGAuth design (docs/sgauth-design in SGAOperations/auth). SGAuth is built on Neon and does not use Supabase.
Ticket: AUTH-T99 · Epic: E3 Authentication Core · Phase: Phase 5 — Backlog / spikes
Priority: Low · Estimate: 3 points · Labels: epic:auth-core, phase:5, spike, sso
Depends on:
Not a launch dependency. Investigate whether SGA can (a) get an app registered in Northeastern's Entra tenant via ITS, or (b) register a multi-tenant app in an SGA-owned tenant that Northeastern's tenant permits users to consent to, restricting sign-in to Northeastern's tenant id. If viable, prototype Better Auth's
microsoftsocial provider behind a feature flag, linking to existing accounts by verified email. Report blockers, MFA inheritance (Duo), and the account-linking policy.Acceptance criteria
Generated from the SGAuth design (docs/sgauth-design in SGAOperations/auth). SGAuth is built on Neon and does not use Supabase.