Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

As part of the process for deploying the SharePoint Online microservice, To manage SharePoint, the EmpowerID SharePoint Online (SPO) microservice requires a service principal application used to authenticate the App Service be registered in the SharePoint tenant to provide Azure AD authentication to the app service that hosts the SPO microservice must be registered in Azure.

Register

...

a service principal for app service auth

...

  1. In Azure, navigate to your Azure Active Directory.

  2. On the Azure Active Directory navbar, click App registrations.

  3. On the App registrations page, click New registration.

  4. Name the application, select the scope for the application (single or multitenant) and click Register.

  5. Once the application is registered, copy the Application (client) ID , and Directory (tenant) ID and Object ID from the Overview page. These values are used later to configure AD authentication for the SharePoint Online App service. The next step is to .

  6. Navigate to the Certificates & secrets blade for the application and upload the base-64 encoded certificate that you have selected to authenticate to the application.
    Insert excerptIL:Azure Cert RequirementsIL:Azure Cert Requirementsnopaneltrue

  7. Under Manage, click Certificates & secrets.

  8. Under Certificates, click Upload certificate and upload the base-64 encoded certificate.

  9. Under Client secrets, click New client secret. The secret is used by the application to prove its identity when requesting a token.

  10. Copy the secret. You will use it to configure Azure Active Directory Authentication.

...

  1. are using to secure HTTP traffic between EmpowerID and the microservice. The public key certificate that you upload to Azure must have a corresponding private key in the EmpowerID certificate store; otherwise, an error will occur when calling Azure’s API.

  2. Add a client secret and copy the value. You add this value to the Key Vault in your EmpowerID tenant.

    Image Added

...

Next steps

Register Service Principal with SharePoint API Permissions

Create an app service for the SharePoint Online Microservice

Create a key vault

Provision a Cosmos DB Account for SharePoint Online

Create a Function app to Update User Profiles

Add application settings to the app service

Add Secret to Key Vault in EmpowerID Tenant

Publish the SharePoint Online Microservice

Configuration of SharePoint Online Inventory - Not Applicable if using EmpowerID SaaS