Configuring SSO via the Enhanced Web Interface: Microsoft Azure
2024-06-04
Version 1.0
If you don't have an account in Azure AD, you can register for a free account here: https://azure.microsoft.com/
Obtain the redirectUri for the account by adding your account ID at the end of the below redirectUri:
https://auth.eagleeyenetworks.com/login/oauth2/code/<account ID>
Log in to the Azure console https://portal.azure.com/#home and navigate to Manage Microsoft Entra ID (Previously known as Azure AD).
Select App Registrations.
Click Create New Registration.
Click Register an Application Wizard.
Select Register an Application.
Name the application.
Select Accounts in this organizational directory only.
Use the redirectUri obtained above as the Redirect URI.
Select Application Overview.
Click Add a certificate or secret.
Click New client secret.
Provide a description of the secret and the expiry date.
Copy the Value field to a text file as this can not be viewed later.
Also on the application overview page, you can find the Application ID.
10. Select API Permission.
11. Click Add a permission.
12. Click Microsoft Graph.
13. Select email and openid.
14. Select Token Configuration.
15. Click Add optional claim.
16. Select Adding verified_primary_email is optional.
You can update the consent page in Branding & Properties.
Assigning Users
Click Home.
Select Manage Microsoft Entra ID.
Click Enterprise Applications.
Select Your Application.
Click Assign Users and Groups.
Search for or add Users as needed.
The organizational Microsoft SSO should be configured as below:
Update Client ID (Application (client) ID) and “Client secret” with values you got from the Azure AD application created in the first section.
You can find the<tenant-id> on the application overview page.
Test logging in to the application:
Provide a non-admin user account at the identifier-first page.
Login with Azure AD and provide consent.
Update the homepage URL in Branding & Properties as follows:
https://auth.<domain-branding>/sso?issuer=<registration-id>&target_link_uri=<webapp-url>.
domain-branding can be eagleeyenetworks.com, mobotixcloud.com, etc.
registration-id is your account id. This is found at the end of redirectUri.
Then navigate to the Enterprise application tab as previously done and select your application
Click Manage.
Select Properties.
Update Visible to users to Yes.
Go to https://myapplications.microsoft.com?tenantId=<tenant-id>.
Log in with a user from your EEN account.
Click Your Application.
You should be redirected to your application for sign-in.
Select Add new users if they do not already exist.
Click Save Changes.
Test logging in to the application:
Go to https://myapplications.microsoft.com?tenantId=<tenant-id>.
Log in with a user that does not have an EEN account.
Click Application.
You should be redirected to the application and auto-provisioned.
For support please email: support@een.com
or give us a call at: 512-473-0501
US: +1-512-473-0501
EU: 31 (0) 20 26 10 461
ASIA PACIFIC: +81-(3)-6869-5477
#1 In Cloud Media Video Surveillance Worldwide