# Uibuilder Azure Login

**URL:** <https://discourse.nodered.org/t/uibuilder-azure-login/100511>\
**Category:** General\
**Tags:** uibuilder\
**Created:** [6 March 2026 16:00 UTC](https://discourse.nodered.org/t/uibuilder-azure-login/100511 "2026-03-06T16:00:54Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![ChrisWeb71](https://avatars.discourse-cdn.com/v4/letter/c/53a042/32.png) [@ChrisWeb71](https://discourse.nodered.org/u/ChrisWeb71)\
**Post date:** [6 March 2026 16:00 UTC](https://discourse.nodered.org/t/uibuilder-azure-login/100511/1 "2026-03-06T16:00:55Z")

</div>

Hi everyone,

I'm desperately trying to implement a login with uibuilder and Microsoft Azure, so far without success.  
Has anyone managed to get this working? The login/logout doesn't work on the uibuilder pages.

Here's my flow that works:

 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/5/7/5731522218d82c21c4f422893ff91a1018858c3e.png)

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [6 March 2026 16:03 UTC](https://discourse.nodered.org/t/uibuilder-azure-login/100511/2 "2026-03-06T16:03:44Z")

</div>

> [@ChrisWeb71](#):
>
> I'm desperately trying to implement a login with uibuilder and Microsoft Azure, so far without success.

Hi, how are you trying this? Generally, the sensible approach is to handle the IdM tasks in a proxy. The IdM will add appropriate headers to web requests that uibuilder can then use if needed but the main principal is that the proxy will not allow access at all unless the request comes from a suitable authenticated user.

---

<div class="post-metadata">

**Author:** ![DestyNova](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/destynova/32/106092_2.png) [@DestyNova](https://discourse.nodered.org/u/DestyNova)\
**Post date:** [7 March 2026 02:14 UTC](https://discourse.nodered.org/t/uibuilder-azure-login/100511/3 "2026-03-07T02:14:02Z")

</div>

That seems like a good general suggestion, although it would also be nice if there was a way to integrate SSO with OAuth2/OIDC at the app level in a way that's reusable across multiple pages, without having to go the reverse proxy/session injection route.

---

<div class="post-metadata">

**Author:** ![leftymuller](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/leftymuller/32/102326_2.png) [@leftymuller](https://discourse.nodered.org/u/leftymuller)\
**Post date:** [8 March 2026 05:32 UTC](https://discourse.nodered.org/t/uibuilder-azure-login/100511/4 "2026-03-08T05:32:53Z")

</div>

Can I ask why you would not use radius ?  
I could be wrong.. I dont know the whole scope of your project BUT it seems that your banging your head against a wall when there are other options?

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [9 March 2026 13:57 UTC](https://discourse.nodered.org/t/uibuilder-azure-login/100511/5 "2026-03-09T13:57:11Z")

</div>

> [@DestyNova](#):
>
> although it would also be nice if there was a way to integrate SSO with OAuth2/OIDC at the app level in a way that's reusable across multiple pages

The issue here is that it would be a far more complex and fragile approach, especially across multiple end points with potentially different security settings. It is actually easier to maintain a secure stance using more dedicated tools that have been battle tested.

Using a proxy offloads several workloads to a more appropriate infrastructure and also introduces some potentially significant performance boosts along with the better security and reliability.

This would be the case on any infrastructure, but if you are using Microsoft based Azure infrastructure, this is even more the case since you could, if desired, use a Microsoft Active Directory as the IdM core along with IIS and a simple extension as the proxy to link everything together. This is, indeed, Microsoft's recommended architecture.

There is really no need to add this complexity to either UIBUILDER or Node-RED. There are really only downsides.

Having said that, it _is_ possible to add OAuth to Node-RED since you can leverage its use of ExpressJS. However, personally I don't recommend that and I have no experience of doing it.

---

<div class="post-metadata">

**Author:** ![DestyNova](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/destynova/32/106092_2.png) [@DestyNova](https://discourse.nodered.org/u/DestyNova)\
**Post date:** [10 March 2026 17:08 UTC](https://discourse.nodered.org/t/uibuilder-azure-login/100511/6 "2026-03-10T17:08:52Z")

</div>

> [@TotallyInformation](#):
>
> The issue here is that it would be a far more complex and fragile approach, especially across multiple end points with potentially different security settings. It is actually easier to maintain a secure stance using more dedicated tools that have been battle tested.

Fair points. I guess it would be a good scenario for integrating something like Authentik or Authelia in front of the app. Not sure if they handle registration of new accounts though.

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [10 March 2026 17:31 UTC](https://discourse.nodered.org/t/uibuilder-azure-login/100511/7 "2026-03-10T17:31:00Z")

</div>

> [@DestyNova](#):
>
> I guess it would be a good scenario for integrating something like Authentik or Authelia in front of the app

Well they will integrate nicely with NGINX I think and that will enable you to have any number of separately or commonly authenticated and authorised endpoints with ease.

Let's leave Node-RED to do what it is good at eh. 🙂

> [@DestyNova](#):
>
> Not sure if they handle registration of new accounts though.

I can't remember off the top of my head how they deal with that. But again, this is easy to configure with NGINX (or similar) such that lack of authentication redirects to a login page and lack of authorisation goes to wherever you want. This is especially important if you insist on using Node-RED's Dashboard since that only actually provides a single end-point per node-red instance (it is an SPA). If you want more control, you either need to use several node-red instances or, more easily perhaps, use UIBUILDER. 😃

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [8 June 2026 17:31 UTC](https://discourse.nodered.org/t/uibuilder-azure-login/100511/8 "2026-06-08T17:31:34Z")

</div>

This topic was automatically closed 90 days after the last reply. New replies are no longer allowed.
