Configuring Azure AD for Benemen Auth entication integration
To enable Azure AD Authentication integration for your organization, Benemen Authenticator application must be registered to customer Active Directory in Azure management portal.
If Multi Factor Authentication (MFA) is enabled on Azure AD, Benemen Datacenter IP Addresses (80.88.187.0/24) must be white listed. More information: https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-mfa-mfasettings#trusted-ips
Registering the Authenticator Application
- Log in to https://portal.azure.com
- Select Azure Active Directory -> App registrations
- Select New application registration
- Enter details and click Register
- Name for application, for example 'Benemen Authenticator'
- Accounts in this organization only
- Redirect URI is not needed
- Go to Authentication tab
- Implicit grant: ID tokens
- Treat application as a public client: Yes
- Click Save
- Go to Permissions tab
- Make sure that app have User.Read permission
- Click Grant admin consent and Yes to confirmation
- Make sure that there is green mark for Admin consent
- Go to Overview tab
- Send Application ID value to Benemen