# Proxy in front of OIDC configuration Azure Entra App

**URL:** <https://discuss.elastic.co/t/proxy-in-front-of-oidc-configuration-azure-entra-app/373871>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [January 30, 2025, 6:44am UTC](https://discuss.elastic.co/t/proxy-in-front-of-oidc-configuration-azure-entra-app/373871 "2025-01-30T06:44:47Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![tdvo1996](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tdvo1996/32/123454_2.png) [@tdvo1996](https://discuss.elastic.co/u/tdvo1996)\
**Post date:** [January 30, 2025, 6:44am UTC](https://discuss.elastic.co/t/proxy-in-front-of-oidc-configuration-azure-entra-app/373871/1 "2025-01-30T06:44:47Z")

</div>

Hi,

We are running Elastic with an ECK Operator in Openshift.  
The namespace that Elastic is running on has strict network access in and out.  
Let's say we have an OIDC configuration with an Azure Entra App.  
Is it possible to add a proxy between Elastic and the URL's being called in the OIDC configuration ([login.microsoftonline.com](http://login.microsoftonline.com), [sts.windows.net](http://sts.windows.net), etc)?

For example, adding an environment variable ES\_JAVA\_OPTS with proxy configuration. When the OIDC endpoints are being called, it should go through the proxy where we have whitelisted the given OIDC URL's.

Is this achievable?

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [February 3, 2025, 4:39am UTC](https://discuss.elastic.co/t/proxy-in-front-of-oidc-configuration-azure-entra-app/373871/2 "2025-02-03T04:39:46Z")

</div>

There are proxy settings for the OIDC realm.  
See

- [Security settings in Elasticsearch | Elasticsearch Guide [8.17] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-settings.html#ref-oidc-settings)
