Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

  • Do You Want to Configure Application Authentication Settings? – Select Yes or No

  • Do You Want to Configure Application Extension Settings? – Select Yes or No

Image Removed
  • Azure Application Name – Enter a name for the application

  • Azure Description – Enter a description for the application

Image Added

Excerpt
nameCreateAzureAppWF-Screen1

Application Type

Macrosuite divider macro
dividerWidth80
dividerTypetext
emoji{"id":"smile","name":"Smiling Face with Open Mouth and Smiling Eyes","short_names":["smile"],"colons":":smile:","emoticons":["C:","c:",":D",":-D"],"unified":"1f604","skin":null,"native":"😄"}
textColor#000000
dividerWeight1
labelPositionmiddle
textAlignmentcenter
iconColor#000000
fontSizemedium
textSelect Integration Type
emojiEnabledfalse
dividerColor#000000
dividerIconfont-awesome/Rocket
  • Which Type of Azure Application Do You Wish to Onboard? – Select the type of application you wish to integrate with Azure. Types include:

    • Non-gallery Enterprise Applications (SAML)

    • Gallery Enterprise Applications (SAML)

    • Application Registration (OIDC)

  • In Which Environment Will It Be Deployed? – Select the appropriate environment for the application. Depending on the value of the AzureAppApplicationLine list data set, the environment choices displayed may differ from those shown below.

Image Removed
  • The option selected has no effect on where the application is created; it is metadata that EmpowerID stores in an extension attribute on the application.

Image Added

Macrosuite divider macro
dividerWidth80
dividerTypetext
emoji{"id":"smile","name":"Smiling Face with Open Mouth and Smiling Eyes","short_names":["smile"],"colons":":smile:","emoticons":["C:","c:",":D",":-D"],"unified":"1f604","skin":null,"native":"😄"}
textColor#000000
dividerWeight1
labelPositionmiddle
textAlignmentcenter
iconColor#000000
fontSizemedium
textSelect a Location
emojiEnabledfalse
dividerColor#000000
dividerIconfont-awesome/Rocket
Easy html macro
theme{"label":"solarized_dark","value":"solarized_dark"}
contentByMode{"html":"<!doctype html>\r\n<link href=\"https://cdn.jsdelivr.net/npm/bootstrap@5.0.2/dist/css/bootstrap.min.css\" rel=\"stylesheet\" integrity=\"sha384-EVSTQN3/azprG1Anm3QDgpJLIm9Nao0Yz1ztcQTwFspd3yD65VohhpuuCOmLASjC\" crossorigin=\"anonymous\">\r\n<link href=\"https://docs.empowerid.com/new_docs.css\" rel=\"stylesheet\">\r\n<script src=\"https://cdn.jsdelivr.net/npm/bootstrap@5.0.2/dist/js/bootstrap.bundle.min.js\" integrity=\"sha384-MrcW6ZMFYlzcLA8Nl+NtUVF0sA7MsXsP1UyJoMp4YLEuNSfAP+JcXn/tWtIaxVXM\" crossorigin=\"anonymous\"></script>\r\n <p class = \"bd-callout bd-callout-info\">The visibility of this section of the form and the controls within it are \r\n controlled by the <b>ApplicationType_Location_IsVisible</b>, <b>ApplicationType_Location_Tenant_IsVisible</b>, and <b>ApplicationType_Location_SelectaLocation_IsVisible</b>\r\n parameters of the workflow.</p>","javascript":"","css":""}

  • Select a Tenant – Search for and select the Azure tenant in which the application is to be created.

  • Select a Location – Select a location in EmpowerID for the application. This location is for RBAC delegation only.
    If there is a location selected by default and you wish to change it, click the link for the location and then search for and select the desired location from the Location tree.

Macrosuite divider macro
dividerWidth80
dividerTypetext
emoji{"id":"smile","name":"Smiling Face with Open Mouth and Smiling Eyes","short_names":["smile"],"colons":":smile:","emoticons":["C:","c:",":D",":-D"],"unified":"1f604","skin":null,"native":"😄"}
textColor#000000
dividerWeight1
labelPositionmiddle
textAlignmentcenter
iconColor#000000
fontSizemedium
textAdvanced ConfigurationApplication Instance Details
emojiEnabledfalse
dividerColor#000000
dividerIconfont-awesome/Rocket
Easy html macro
theme{"label":"solarized_dark","value":"solarized_dark"}
contentByMode{"html":"<!doctype html>\r\n<link href=\"https://cdn.jsdelivr.net/npm/bootstrap@5.0.2/dist/css/bootstrap.min.css\" rel=\"stylesheet\" integrity=\"sha384-EVSTQN3/azprG1Anm3QDgpJLIm9Nao0Yz1ztcQTwFspd3yD65VohhpuuCOmLASjC\" crossorigin=\"anonymous\">\r\n<link href=\"https://docs.empowerid.com/new_docs.css\" rel=\"stylesheet\">\r\n<script src=\"https://cdn.jsdelivr.net/npm/bootstrap@5.0.2/dist/js/bootstrap.bundle.min.js\" integrity=\"sha384-MrcW6ZMFYlzcLA8Nl+NtUVF0sA7MsXsP1UyJoMp4YLEuNSfAP+JcXn/tWtIaxVXM\" crossorigin=\"anonymous\"></script>\r\n <p class = \"bd-callout bd-callout-info\">This section of the form only appears when selecting <b>Yes</b>\r\n for <b>Do You Want to Configure Application Authentication Settings?</b> under <b>Advanced Configuration</b>.</p>","javascript":"","css":""}
Macrosuite divider macro
dividerWidth80
dividerTypetext
emoji{"id":"smile","name":"Smiling Face with Open Mouth and Smiling Eyes","short_names":["smile"],"colons":":smile:","emoticons":["C:","c:",":D",":-D"],"unified":"1f604","skin":null,"native":"😄"}
textColor#000000
dividerWeight1
labelPositionmiddle
textAlignmentcenter
iconColor#000000
fontSizemedium
textSupported Account Types
emojiEnabledfalse
dividerColor#000000
dividerIconfont-awesome/Rocket

Select the scope for selecting which accounts can use the application. Default options include the following:

  • Personal Microsoft accounts only

  • Accounts in this organizational directory only (Single tenant)

  • Accounts in any organizational directory (Any Azure AD directory - Multitenant) and personal Microsoft accounts (e.g., Skype, Xbox)

  • Accounts in any organizational directory (Any Azure AD directory - Multitenant)

Image Added

Macrosuite divider macro
dividerWidth80
dividerTypetext
emoji{"id":"smile","name":"Smiling Face with Open Mouth and Smiling Eyes","short_names":["smile"],"colons":":smile:","emoticons":["C:","c:",":D",":-D"],"unified":"1f604","skin":null,"native":"😄"}
textColor#000000
dividerWeight1
labelPositionmiddle
textAlignmentcenter
iconColor#000000
fontSizemedium
textOwners and Deputies
emojiEnabledfalse
dividerColor#000000
dividerIconfont-awesome/Rocket
Easy html macro
theme{"label":"solarized_dark","value":"solarized_dark"}
contentByMode{"html":"<!doctype html>\r\n<link href=\"https://cdn.jsdelivr.net/npm/bootstrap@5.0.2/dist/css/bootstrap.min.css\" rel=\"stylesheet\" integrity=\"sha384-EVSTQN3/azprG1Anm3QDgpJLIm9Nao0Yz1ztcQTwFspd3yD65VohhpuuCOmLASjC\" crossorigin=\"anonymous\">\r\n<link href=\"https://docs.empowerid.com/new_docs.css\" rel=\"stylesheet\">\r\n<script src=\"https://cdn.jsdelivr.net/npm/bootstrap@5.0.2/dist/js/bootstrap.bundle.min.js\" integrity=\"sha384-MrcW6ZMFYlzcLA8Nl+NtUVF0sA7MsXsP1UyJoMp4YLEuNSfAP+JcXn/tWtIaxVXM\" crossorigin=\"anonymous\"></script>\r\n <p class = \"bd-callout bd-callout-info\">The individuals >Users selected as Application Owner owner and deptuies will be \r\n Deputies must have an account in the Azure tenant hosting the applicationgiven the <b>Configuration Owner</b> role for the application in Azure.</p>","javascript":"","css":""}

  • Application Owner – Search for and select the application owner. This field only returns people with an account in the Azure tenant.

  • Select Deputies – Search for and select one or more application deputies. This field only returns people with an account in the Azure tenant.

Image Added

Macrosuite divider macro
dividerWidth80
dividerTypetext
emoji{"id":"smile","name":"Smiling Face with Open Mouth and Smiling Eyes","short_names":["smile"],"colons":":smile:","emoticons":["C:","c:",":D",":-D"],"unified":"1f604","skin":null,"native":"😄"}
textColor#000000
dividerWeight1
labelPositionmiddle
textAlignmentcenter
iconColor#000000
iconSizemedium
fontSizemedium
textAzure Application Authentication
emojiEnabledfalse
dividerColor#000000
dividerIconfont-awesome/Rocket
Easy html macro
theme{"label":"solarized_dark","value":"solarized_dark"}
contentByMode{"html":"<!doctype html>\r\n<link href=\"https://cdn.jsdelivr.net/npm/bootstrap@5.0.2/dist/css/bootstrap.min.css\" rel=\"stylesheet\" integrity=\"sha384-EVSTQN3/azprG1Anm3QDgpJLIm9Nao0Yz1ztcQTwFspd3yD65VohhpuuCOmLASjC\" crossorigin=\"anonymous\">\r\n<link href=\"https://docs.empowerid.com/new_docs.css\" rel=\"stylesheet\">\r\n<script src=\"https://cdn.jsdelivr.net/npm/bootstrap@5.0.2/dist/js/bootstrap.bundle.min.js\" integrity=\"sha384-MrcW6ZMFYlzcLA8Nl+NtUVF0sA7MsXsP1UyJoMp4YLEuNSfAP+JcXn/tWtIaxVXM\" crossorigin=\"anonymous\"></script>\r\n <p class = \"bd-callout bd-callout-info\">This section of the form only appears when selecting <b>Yes</b>\r\n for <b>Do You Want to Configure Application Authentication Settings?</b> under <b>Advanced Configuration</b>.</p>","javascript":"","css":""}

  • Web Redirect URI – Enter the location where the client is to be directed after the account authorization is successful.

  • Front-Channel Logout URL – Optional

  • Issue Access token (used for implicit flows)

  • Issue ID tokens (used for implicit and hybrid flows)

  • Allow Public Client Flows – Select Yes or No

  • Service Principal Settings

  • Enabled for users to sign-in? – Enabled by default

  • Assignment required? – Enabled by default

    Select A Platform – Select a platform the application is targeting. Options include:

    • Web – Build, host, and deploy web server applications

    • Single-page application – Configure browser client applications and progressive web applications

    • Mobile and desktop applications – iOS/macOS, Android applications

  • Front-Channel Logout URL – Enter URL as needed

  • Issue Access token (used for implicit flows) – Select as needed

  • Issue ID tokens (used for implicit and hybrid flows) – Select as needed

  • Allow Public Client Flows – Specifies whether the application is a public client. Appropriate for apps using token grant flows that don’t use a redirect URI.

  • User Access Settings

    • Enabled for users to sign-in? – Enabled by default

    • Assignment required? – Enabled by default

Macrosuite divider macro
dividerWidth80
dividerTypetext
emoji{"id":"smile","name":"Smiling Face with Open Mouth and Smiling Eyes","short_names":["smile"],"colons":":smile:","emoticons":["C:","c:",":D",":-D"],"unified":"1f604","skin":null,"native":"😄"}
textColor#000000
dividerWeight1
labelPositionmiddle
textAlignmentcenter
iconColor#000000
iconSizemedium
fontSizemedium
textIAM Shop Settings
emojiEnabledfalse
dividerColor#000000
dividerIconfont-awesome/Rocket

  • Set Requestable Setting – Specifies whether the application is requestable in the IAM Shop. When selected, the below settings are relevant.

  • Select Access Request Policy – Select the Access Request policy that specifies how requests for the application are processed.

  • Select Assignees – Search for and select users who are eligible for the application. Users must have one of the below eligibility assignments to view the application in the IAM Shop.

    • Eligible Assignees – Choose the type (Person, Group, SetGroup, Management Role, Business Role and Location), and then search for and select the specific assignees eligible for the application.

    • Preapproved Assignees – Choose the type (Person, Group, SetGroup, Management Role, Business Role and Location), and then search for and select the specific assignees pre-approved for the application.

    • Suggested Assignees – Choose the type (Person, Group, SetGroup, Management Role, Business Role and Location), and then search for and select the specific assignees suggested for the application.

Page Properties
hiddentrue
Macrosuite divider macro
dividerWidth80
dividerTypetext
emoji{"id":"smile","name":"Smiling Face with Open Mouth and Smiling Eyes","short_names":["smile"],"colons":":smile:","emoticons":["C:","c:",":D",":-D"],"unified":"1f604","skin":null,"native":"😄"}
textColor#000000
dividerWeight1
labelPositionmiddle
textAlignmentcenter
iconColor#000000
fontSizemedium
textAzure Application Extensions
emojiEnabledfalse
dividerColor#000000
dividerIconfont-awesome/Rocket
  • Conditional Access Policy – Optional; select a conditional access policy for the application if needed. Please note that the policy must exist in Azure and be inventoried by EmpowerID.

  • UPX-ID – Optional; enter as needed

  • Device Status – Optional; select the appropriate setting as needed

Image Added