Configuring AzureAD for user synchronization
This page is for older ‘pull based’ user synchronization, which reads AzureAD information via GraphAPI.
We have newer and better ‘push based’ SCIM user synchronization, which should be used if you are implementing new user data synchronization.
General
There are three separate synchronization options to synchronize user data from Azure Active Directory to Enreach Cloud systems.
User data synchronization
Directory synchronization of users
Directory synchronization of directory entries
Synchronization is done as a daily batch job by default.
Reading AzureAD information is done via Azure Graph API. This requires that new application must be registered to Azure Active Directory in Azure portal and rights to read directory data must be granted.
Registering Directory Synchronization on Azure Portal
1. Log in https://portal.azure.com as an administrator
Log in https://portal.azure.com as an administrator
2. Select Azure Active Directory -> App registrations -> New application registration
3. Enter describing name for the application, and click Register. Redirect URI: https://discover.enreachvoice.com/
4. Select API Permissions.
Add Microsoft Graph -> Application permissions
Add following permissions
Group/ Group.Read.All
User/ User.Read.All
Click Grant admin consent and then Yes for confirmation pop-up
4. Make sure that Admin consent status is granted for all permissions
5. Select Certificates & secrets.
Add new client secret
Enter a proper description, select Expires = Never and click Add
Copy value of new secret to be sent to Enreach
6. Go to overview tab and copy value of Application (client) ID
Send Application ID and Secret to Benemen
© Enreach, Mannerheimintie 117, 00280 Helsinki, Finland
+358 40 450 3000, www.enreach.fi