To enable Azure AD Authentication integration for your organization, Benemen Authenticator application must be registered to customer Active Directory in Azure management portal.
/note
If Multi Factor Authentication (MFA) is enabled on Azure AD, Benemen Datacenter IP Addresses (80.88.187.0/24) must be white listed. More information: https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-mfa-mfasettings#trusted-ips
Registering the Authenticator Application
- Log in to https://portal.azure.com
- Select Azure Active Directory -> App registrations
- Select New application registration
- Enter details and click Register
- Name for application, for example 'Benemen Authenticator'
- Accounts in this organization only
- Redirect URI is not needed
- Go to Authentication tab
- Implicit grant: ID tokens
- Treat application as a public client: Yes
- Click Save
- Go to Permissions tab
- Make sure that app have User.Read permission
- Click Grant admin consent and Yes to confirmation
- Make sure that there is green mark for Admin consent
- Go to Overview tab
- Send Application ID value to Benemen