Versions Compared
Key
- This line was added.
- This line was removed.
- Formatting was changed.
The IT Shop Microservices allow users to shop for any resources to which they may eligible to receive. As part of the process for deploying the IT Shop, a service principal application used to authenticate the App Service that hosts the microservice must be registered in Azure.
How to register a service principal app
for the IT Shop MicroserviceLog in to your Azure portal as a user with the necessary permissions to create an application in Azure AD.
In Azure, navigate to your Azure Active Directory.
On the Azure navbar, click App registrations.
Image RemovedImage AddedOn the App registrations page, click New registration.
Image RemovedImage AddedName the application, select the scope for the application (single or multitenant) and click Register.
Image RemovedImage Added
Configure the
ITIAM Shop API app
Navigate to the IT IAM Shop API application you created above.
Select Branding on the application navbar and update the the settings accordingly. The Home page URL should be set to the URL for the IT Shop UI app services.
Image RemovedImage AddedWhen you have completed updating the Branding settings, click Save.
Image RemovedImage AddedSelect Authentication from the application navbar and then click Add a platform.
Image RemovedImage AddedUnder Web applications, select Web.
Image RemovedImage AddedIn the Configure Web pane do the following:
In the Redirect URIs field, enter the URL for the IT Shop UI Web Service, such as
https://{{it-shop-ui-url}}/callback
, where{{it-shop-ui-url}}
is the URL for the IT Shop UI App Service you created.Under Implicit grant, select both Access tokens and ID tokens.
Click Configure.
Image RemovedImage Added
After the application configuration completes, click Add URI to add another redirect URI to the application.
Image RemovedImage AddedEnter
https://{{it-shop-ui-url}}/.auth/login/aad/callback
, where{{it-shop-ui-url}}
is the URL for the IT Shop UI Web Service you created.Click Save.
Image RemovedImage AddedClick Expose an API on the application navbarand then click the Application ID URI Set link.
Image RemovedImage AddedIn the Application ID URI field of the Set the App ID URI dialog, enter the URL for the IT Shop API App Service you created earlier and then click Save.
Image RemovedImage Added
The URI should look similar tohttps://it-shop-api.azurewebsites.net
Under Scopes defined by this API, click Add a scope.
Image RemovedImage AddedIn the Add a scope dialog, do the following
Scope name — Enter – Enter itshop.all
Who can consent? — Select – Select Admins and users.
Admin consent display name — Enter – Enter a desired display name.
State — Select – Select Enabled.
Click Add Scope.
On the navbar go to the API Permissions page and then click Add Permission.
Select APIs my organization uses.
Search for and select the it-shop-ad application.
Select Delegated permissions.
Select the itshop.all scope.
Click Add permissions.
Insert excerpt | ||||||
---|---|---|---|---|---|---|
|
Div | ||||||||
---|---|---|---|---|---|---|---|---|
| ||||||||
IN THIS ARTICLE
|