...
To manage SharePoint, the EmpowerID SharePoint Online (SPO) microservice requires a service principal application be registered in the SharePoint tenant to provide Azure AD authentication to the app service that hosts the SPO microservice.
...
...
API / Permissions Name
...
Description
...
Microsoft Graph
...
Sites.FullControl.All
...
Have full control of all site collections
...
User.Read
...
Sign and read user profile
...
User.ReadWrite.All
...
Read and write all users' full profiles
...
SharePoint
...
Sites.FullControl.All
...
Have full control of all site collections
...
User.Read.All
...
Read user profiles
...
User.ReadWrite.All
...
Read and write user profiles
Register a service principal for app service auth
In Azure, navigate to your Azure Active Directory.
On the Azure Active Directory navbar, click App registrations.
On the App registrations page, click New registration.
Name the application, select the scope (single or multitenant) and click Register.
Once the application is registered, copy the Application (client) ID and Directory (tenant) ID from the Overview page. These values are used later.
Navigate to the Certificates & secrets blade for the application and upload the base-64 encoded certificate you are using to secure HTTP traffic between EmpowerID and the microservice. The public key certificate that you upload to Azure must have a corresponding private key in the EmpowerID certificate store; otherwise, an error will occur when calling Azure’s API.
Add a client secret
...
...
and copy the value. You add this value to the
...
Register a service principal for SharePoint API calls
Register a second service principal in Azure AD.
After the service principal is registered, navigate to API permissions for the application, click Add a permission and then add the application permissions specified in the above table.
When completed, your application permissions should look like those show in the below image.Grant admin consent for the application.
...
style | float: left; position: fixed;padding: 5px; |
---|
IN THIS ARTICLE
...
Key Vault in your EmpowerID tenant.
...
Next steps
Register Service Principal with SharePoint API Permissions
Create an app service for the SharePoint Online Microservice
Provision a Cosmos DB Account for SharePoint Online
Create a Function app to Update User Profiles
Add application settings to the app service
Add Secret to Key Vault in EmpowerID Tenant
Publish the SharePoint Online Microservice
Configuration of SharePoint Online Inventory - Not Applicable if using EmpowerID SaaS