The verdict in three sentences
Adding Microsoft Entra ID SSO to an in-house business application costs USD 4,400 to 13,000 (EUR 4,000 to 12,000) for authentication via OIDC or SAML, and about USD 3,300 more for automatic SCIM provisioning. The work takes 2 to 4 weeks and removes local accounts, and with them forgotten passwords and still-active accounts of former staff. When 30% of support tickets are about passwords, payback is measured in months, and the security gain often justifies the budget on its own.
OIDC, SAML and SCIM: what to choose
The CISO of a 400-employee mid-sized company wants to remove local credentials from a field service app built six years ago. Toronto agency rates are in line with these ranges (multiply by about 1.37 for CAD).
| Component | Role | When to choose it | Indicative 2026 cost | Timeline |
|---|---|---|---|---|
| OIDC (OpenID Connect) | Modern token-based authentication | Recent web app, API, mobile | USD 4,400 to 8,800 | 1 to 2 weeks |
| SAML 2.0 | XML assertion-based authentication | Legacy app, enterprise client requirement | USD 6,600 to 13,000 | 2 to 3 weeks |
| SCIM 2.0 | Automatic account creation, update and removal | Over 100 users, frequent turnover | About +USD 3,300 | +1 week |
| Entra group to role mapping | App permissions driven by the directory | More than 3 business roles | +USD 1,600 to 3,300 | +3 to 5 days |
| Conditional access and MFA | Entra rules (compliant device, location) | Sensitive data, regulatory audits | Entra-side configuration, 0.5 to 2 days | Included |
| Local account removal | Migration and break-glass account | Always | USD 1,100 to 2,700 | 2 to 4 days |
For a recent web application, OIDC is the right default. SAML remains relevant if the code is old or a client requires that protocol.
Project steps
| Step | Content | Duration | Main risk |
|---|---|---|---|
| 1. Audit of the existing app | Session handling, roles, service accounts | 1 to 2 days | Forgotten technical accounts |
| 2. App registration in Entra | Redirects, secrets or certificates, claims | 0.5 day | Unmonitored expired secret |
| 3. OIDC or SAML development | Proven library, token validation | 3 to 8 days | Incomplete signature validation |
| 4. Role mapping | Entra groups to app roles | 2 to 4 days | Excessive default rights |
| 5. SCIM | Provisioning endpoint | 4 to 6 days | Late deactivation of leavers |
| 6. Testing and cutover | 20-user pilot then rollout | 3 to 5 days | Total lockout with no break-glass account |
Two non-negotiable security rules: use a maintained library rather than validating tokens by hand, and keep a protected, logged local break-glass account in case Entra is unavailable.
The security gain
A local account not deactivated after someone leaves is one of the most common weaknesses in internal applications. With SCIM, deactivation in Entra propagates to the app in under 40 minutes, instead of depending on a manual support request. Entra's multi-factor authentication and conditional access apply automatically, with no extra development. For companies facing SOC 2 or similar audits, it is also concrete evidence of access control.
Mini case study
Nadia, CISO of a 400-employee technical services company, prices the project: OIDC USD 7,700, SCIM USD 3,300, 5-role mapping USD 2,200, total USD 13,200. The app generates 160 tickets a month, 30% of them password-related, i.e. 48 tickets. At 20 minutes each and a USD 50 loaded hourly cost, that is USD 9,600 a year. Add 60 leavers a year handled manually at 30 minutes each, USD 1,500, and time lost by locked-out users, estimated at USD 3,800. Annual gain: about USD 14,900, for payback in 11 months, not counting the avoided risk of access by a former employee.
Need a professional website?
Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.
FAQ
Is a specific Entra licence required?
OIDC or SAML SSO works with Entra ID Free, included in Microsoft 365. Conditional access requires Entra ID P1, about USD 6 per user per month, often already included in Microsoft 365 Business Premium or E3.
How long are users disrupted?
With a one-week 20-person pilot and a Monday-morning cutover, disruption is close to zero. A two-line announcement and an internal FAQ are enough in 90% of cases.
Is SCIM essential?
Below 100 users with low turnover, just-in-time provisioning at first login is enough. Above that, the USD 3,300 for SCIM pays for itself through automatic deactivation of leavers alone.
Can we keep external accounts for contractors?
Yes, through Entra B2B guests, without recreating local accounts. Their access can be time-limited, for example 90 days renewable.
What if Entra is down?
Entra outages are rare, with a 99.99% commitment. The local break-glass account, reserved for 1 or 2 administrators with hardware MFA, covers that case.
Let's scope your project. Describe your application, its technical age and user count: we price the Entra integration via OIDC or SAML, with SCIM if useful, an indicative budget and a 2 to 4 week timeline. Detailed quote within 48 h. WhatsApp +221 77 596 93 33.
Mohamed Bah
Fondateur, Kolonell
Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.
