---
title: PingAccess for Azure AD
description: Configure PingAccess to provide secure external access to legacy on-premises applications using PingAccess for Azure AD and Microsoft Entra ID (formerly Microsoft Azure AD).
component: pingaccess
version: 9.0
page_id: pingaccess:token_providers:pa_for_azure_ad
canonical_url: https://docs.pingidentity.com/pingaccess/9.0/token_providers/pa_for_azure_ad.html
revdate: March 27, 2024
---

# PingAccess for Azure AD

Configure PingAccess to provide secure external access to legacy on-premises applications using PingAccess for Azure AD and Microsoft Entra ID (formerly Microsoft Azure AD).

|   |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| - | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|   | The PingAccess for Azure AD program ends on December 31, 2025. To continue using PingAccess, you must upgrade to a commercial PingAccess license. Learn more in:- [PingAccess for Azure AD Overview](../introduction_to_pingaccess/pa_for_azure_ad_intro.html) for an overview of license differences

- [Manage license keys](https://support.pingidentity.com/s/manage-license-keys)

- [View or upload a new license](../pingaccess_user_interface_reference_guide/pa_license.html) |

In this scenario, PingAccess provides an external path to legacy on-premises applications using the Entra ID Application Proxy through the use of header based authentication. Additionally, Microsoft Entra ID acts as the token provider for associated sessions.

PingAccess for Azure AD is a limited, free version of PingAccess for Microsoft Entra ID customers that provides protection for up to 20 applications.

This solution requires you to perform the following tasks:

* [Configure PingAccess to use Microsoft Entra ID as the token provider](pa_configure_pa_to_use_azure_ad_as_the_token_provider.html)

* [Configure a PingAccess application](pa_configuring_apps_for_azure.html) for each application you want to protect and make available to Microsoft Entra ID as part of this solution. Applications require the configuration of:

  * A virtual host

  * A web session

  * An identity mapping

  * A site

  * An application

After you complete the configuration, you can test the application using the home page URL that you create in Microsoft Entra ID.
