...
On the navbar, expand Single Sign-On > SSO Connections and click OAuth / OpenID Connect.
Select the External OAuth Services tab and then search for AzureAD.
Click the Provider link for AzureAD.
Click the Edit button for AzureAD.
Update the Callback Url field with the FQDN of your EmpowerID server. The value entered should look similar to
https://sso.empoweriam.com/WebIdPForms/OAuth/V2
, wheresso.empoweriam.com
, is the FQDN of the EmpowerID web server in your environment.Click Save.
On the navbar, expand Admin > Miscellaneous and click Lists.
From the Lists tab, search for Whitelisted and then click the Display Name link for the Azure Multi-Tenant Whitelisted Domains record.
Expand the Items accordion and then click the Add button in the grid header.
Add your domain as a List Item. Enter the domain name in all three fields.
Click Save.
On the navbar, expand Admin > Applications and Directories and click Account Stores and Systems.
Search for AzureGlobalIdP and then click the Account Store link for the record.
On the Account Store Details page that appears, click the Edit link to put the account store in edit mode.
From the Settings tab of the Edit Account Store page, go to the Provisioning Settings pane and locate the Default Person Business Role and Default Person Location settings.
Under Default Person Business Role, click the Select a Business Role link and then search for and select the desired Business Role for the Person objects EmpowerID provisions from the account store.
Click Save.
Under Default Person Location (leave blank to use account container, click the Select a Location link and then search for and select the desired location for the Person objects EmpowerID provisions from the account store.
Click Save.
Info |
---|
If you want to configure domain specific Business Role and Location allocation for the people EmpowerID provisions, please follow the below steps. |
Configuring domain specific Business Role and Locations
On the navbar, expand Admin > Miscellaneous and click Lists.
From the Lists tab of the find ListDataItemSet page that appears, search for FQN and then click the Display Name link for FQN to BusinessRoleLocationMapping.
On the ListDataItemSet page, expand the Items accordion and click the Add button on the grid header.
In the List Items pane, add the following information:
Name / Key — Name of your domain
Display Name — Display name for your domain
Value — The OrgRoleOrgZoneID of the Business Role and Location combination in which you want people to be placed in.
Click Save.
Add a Login Button for Azure Native Authentication
On the navbar, expand Single Sign-On > SSO Connections and click SSO Connections.
Select the IdP Domains tab and then click the IdP Domains link for the IdP Domain where you want the Login button to appear.
Select the External OAuth Providers tab and then select the Azure Native Authentication provider.
Click Save.
Insert excerpt | ||||||
---|---|---|---|---|---|---|
|