Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

  1. Log into your Azure Portal as an Administrator.
    1. https://portal.azure.com/
  2. Select Microsoft Entra ID (previously named Azure Active Directory).
  3. Click Groups
    1.  
  4. Click New group
    1.  
  5. Enter the following for the New Group:
    1. Group type = Security
    2. Group name = i21:[i21UserRole]

      1. Replace [i21UserRole] with any roles from i21. E.g. i21:PETRO ADMIN. Anything after "i21:" will be the role of the users in this group.
    3. Group description = Enter any description you want for this group.
    4. Membership type = Assigned
    5. Under Members, click No members selected hyperlink then add members/users.
    6. Click Create
  6. Add all of the 365 accounts that correspond to the active i21 users.
    1. Image Added

Step 2 - App Registration

  1. Select App registrations then New registration.
    1.  
  2. In the Register an application form, enter the following:
    1. Name = iRely i21
    2. Supported account types = Accounts in this organizational directory only (single tenant)
    3. Important: Follow the steps below depending on what version of iRely i21 you are running.
      1. iRely i21 version 23.1 and Prior:
        1. Redirect URI (web) = The URL of the i21 plus /identityserver
        2. E.g. https://helpdesk.irely.com/identityserver
      2. iRely i21 version 24.1 and newer:
        1. Redirect URI (web) = The URL of the i21 plus /signin-oidc
        2. E.g. https://helpdesk.irely.com/signin-oidc
      3. Note: This is case sensitive.
    4. Click Register
  3. Go back to App registrations and select the app that you have just created (iRely i21)
  4. Click Certificates & secrets and create a Secret
    1. Important: Make sure you copy the "value" field of the client secret value and save it locally because you won't be able to read it again after you leave this page. 
    2.  
  5. Under API permissions, verify that the following are present especially those underlined ones. If not, add those permissions.
    1. Group.Read.All
    2. User.Read.All
    3.  
  6. Under Authentication, make sure the Access Tokens and ID Tokens checkboxes are checked.
  7. Ensure your Web Redirect URIs are correct.

...