Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

The SCIM microservice uses Azure AD authentication to call the Azure API. For this to occur, you need to register a new application (service principal) for EmpowerID in your Azure Active Directory.

...

  1. n Azure, navigate to your Azure Active Directory.

  2. On the Azure Active Directory navbar, click App registrations.

  3. On the App registrations page, click New registration.

  4. Name the application, select the scope (single or multitenant), and click Register.

  5. Once the application is registered, copy the Application (client) ID and Directory (tenant) ID from the Overview page. These values are used later.

  6. Navigate to the Certificates & secrets blade for the application and upload the base-64 encoded certificate you are using to secure HTTP traffic between EmpowerID and the microservice. The public key certificate that you upload to Azure must have a corresponding private key in the EmpowerID certificate store; otherwise, an error will occur when calling Azure’s API.

  7. Add a client secret and copy the value. You need this Under Client secrets, click New client secret.

  8. Enter a description for the secret, select the desired expiration time and click Add.

  9. Copy the Secret Value and Secret ID. You need these when setting up authentication.

...

Create an App Service for the SCIM microservice

Configure SCIM App Service Authentication

Publish the SCIM Microservice to Azure

...