Microsoft SSO Set Up

Modified on Tue, 8 Sep at 3:43 AM

TABLE OF CONTENTS

Overview

We have introduced a mechanism to log in with Single Sign-On (SSO). As of now, we are supporting Microsoft SSO using OAuth.
Expectations:

  • Each tenant has their own Microsoft account and active directory, and they maintain their own users.

  • Separate Azure App to support AssetWhere.

  • Clients will configure the app and provide required info for SSO to the Tes AssetWhere team.



Creating the App

  1. Visit Microsoft Azure https://portal.azure.com/ 

  2. Click Menu > Entra ID

  3. Click on Menue > App Registration

  4. Click on + New Registration and add the below details
    Name: AssetWhere (recommended)
    Support Account Types: Select Accounts in this organisational directory only (Default Directory only Single Tenant)
    Redirect URI: Can be left empty for now

  5. Click Register

App Configuration


  1. Click Menu App Registration

  2. Select the app created for AssetWhere

  3. Configuring Redirect URI

  4. Microsoft SSO requires a redirect URI. As a user, once you have logged in with SSO, then you will be redirected to this URI which will complete the login process.

  5. Click on Authentication
     

  6. Under Platform Configurations

    • Click on Authentication

    • Choose Web

    • Enter

      • Redirect URI:  https://education-horizons-p1.fusionauth.io/oauth2/callback

      • Implicit grant and hybrid flows: 

        • Select both:

          • Access Token

          • ID Tokens

      • Click Save


Configure Permissions

  1. Go to API Permissions
    For AssetWhere to read critical information for successful login, we need to set four API permissions. The four required are:

    • email

    • openid

    • profie

    • User.Read

  2. After adding these permissions click grant admin consent for <Organisation Name> for each API

    • Where organisation name is your school's name or your organisations tenant name.

    • A Microsoft Entra Administrator may be required to approve the requested permissions

  3. Confirm the permissions show a status of Granted for <organisation name>


Configure Credentials

Skip steps 1-4 if you are already in the AssetWhere App

  1. Visit Microsoft Azure https://portal.azure.com/

  2. Click Menu > Entra ID

  3. Click Menu App Registration

  4. Select the app created for AssetWhere

  5. Click on Certificates & Secrets

  6. Click on New Client Secret

  7. Add description: AssetWhere Client Secret (or any description that suits your organisation)

  8. Click Add

  9. You will see the Value & Secret ID, copy the Value & Secret ID, and keep it somewhere secure. You will need this Value to send to the Tes AssetWhere team for them to complete the SSO set up.


Sending Details

  1. Click on Menu > Overview

  2. Please send the following values to your Tes representative or to assetwheresupport@tes.com 

    • Directory (tenant) ID

    • Application (tenant) ID

    • Under Certificates and Secrets

      • Value (also known as secret value) generated in Step 10 of Configure Credentials



Once the values have been received by the Tes AssetWhere team, we will complete the set up and confirm successful log in with yourself or staff member with AssetWhere access. 























Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article