Configure Azure Active Directory App Registration (2024)

User Workspace Manager

Home

>

This document provides instructions to create an Application Registration on your Microsoft Azure Active Directory (AAD) instance, and to allow connection of User Workspace Manager Consoles and Agents to your AAD instance.

Instructions

The endpoint and console require an application registration to be set up in the AAD domain. This application uses a client certificate to allow the endpoint to access AAD without any user interaction. Steps to create the application are performed in the AAD portal using a suitably privileged account and are as follows:

  1. Go to 'Azure Active Directory’ page for the tenant. Click on ‘App Registrations’ in the left pane then ‘New Registration’ on the right.

  2. Enter a name for the registration and ‘single tenant’ for the account type. A redirect URI is not required at this stage. Click on ‘Register’.

  3. Click on ‘Authentication’ on the left pane. On the right pane, click ‘Add a platform’ then click ‘Mobile and Desktop Applications’. Tick the first redirect URL:

    https://login.microsoftonline.com/common/oauth2/nativeclient

  4. Create or acquire a certificate for use by the endpoint. The application registration on the portal requires only the public key. Each endpoint needs the certificate with the private key installed in the Local Computer - Personal store. The certificate may be self-signed if required. A simple method to create the certificate is via PowerShell 'New-SelfSignedCertificate' cmdlet (see later).

  5. Add the certificate to the application by going to the overview page and clicking on ‘Add certificate or secret’ and uploading the .cer file. The portal will display the certificate thumbprint, which is needed by the console when adding AAD conditions.

  6. Click on ‘API Permissions’ and add permissions as detailed below. Grant administrative consent for them where required.

Microsoft Graph Application Permissions (Endpoint)

  • Device.Readall

  • Group.Readall

  • User.Readall

Microsoft Graph Delegated Permissions (Console)

Creating a Self-Signed Certificate

From an elevated PowerShell prompt, enter:

$certname = "My UWM Certificate"

$cert = New-SelfSignedCertificate -Subject "CN=$certname"

-CertStoreLocation "Cert:\CurrentUser\My"

-KeyExportPolicy Exportable -KeySpec Signature -KeyLength 2048

-KeyAlgorithm RSA -HashAlgorithm SHA256

This will create the certificate in the current user personal store with an exportable private key. It can be exported either by using certmgr.msc or with the following PowerShell commands (using the $cert variable from above):

Export-Certificate -Cert $cert -FilePath "$certname.cer"

  • Exports the .cer file for upload to the portal

$pwd = ConvertTo-SecureString -String "myPassword" -Force -AsPlainText

Export-PfxCertificate -Cert $cert -FilePath "$certname.pfx"

-Password $pwd

  • Exports a .pfx file protected by the specified password. This contains the private key needed by endpoints.

The certificate may be deleted from the current user personal store after generating the .pfx and .cer files.

Console AAD Condition Support

The configuration contains Azure AD Tenant details providing connection information for endpoints. The information can be entered via the Manage tab for Environment Manager, the Global Settings tab for Application Control, and the Resources Setup tab for Performance Manager. The following links pertain to specific AAD functionality for each product.

Application Control:

Creating a connection to Azure Active Directory

Group Rules

User Rules

Environment Manager:

Creating a connection to Azure Active Directory

Performance Manager:

Creating a connection to Azure Active Directory

Was this article useful?

Copyright © 2023, Ivanti, Inc. All rights reserved.

Privacy and Legal

Configure Azure Active Directory App Registration (2024)
Top Articles
Instant money transfer explained: Speed, rates and advantages
Instant bank transfers and how do they work | Western Union
Where are the Best Boxing Gyms in the UK? - JD Sports
Stretchmark Camouflage Highland Park
Celebrity Extra
Booknet.com Contract Marriage 2
Amtrust Bank Cd Rates
Boomerang Media Group: Quality Media Solutions
PRISMA Technik 7-10 Baden-Württemberg
T&G Pallet Liquidation
The Wicked Lady | Rotten Tomatoes
Marion County Wv Tax Maps
Buy PoE 2 Chaos Orbs - Cheap Orbs For Sale | Epiccarry
Are They Not Beautiful Wowhead
Justified Official Series Trailer
Georgia Vehicle Registration Fees Calculator
Praew Phat
Jellyfin Ps5
Royal Cuts Kentlands
Rugged Gentleman Barber Shop Martinsburg Wv
Adt Residential Sales Representative Salary
27 Paul Rudd Memes to Get You Through the Week
Dtm Urban Dictionary
4 Methods to Fix “Vortex Mods Cannot Be Deployed” Issue - MiniTool Partition Wizard
Publix Near 12401 International Drive
John Philip Sousa Foundation
Healthy Kaiserpermanente Org Sign On
Imagetrend Elite Delaware
Nurtsug
Luciipurrrr_
Gabrielle Enright Weight Loss
Desirulez.tv
Metro 72 Hour Extension 2022
Games R Us Dallas
Craigslist List Albuquerque: Your Ultimate Guide to Buying, Selling, and Finding Everything - First Republic Craigslist
Unifi Vlan Only Network
Cheetah Pitbull For Sale
Wait List Texas Roadhouse
Rhode Island High School Sports News & Headlines| Providence Journal
Improving curriculum alignment and achieving learning goals by making the curriculum visible | Semantic Scholar
Brandon Spikes Career Earnings
Nu Carnival Scenes
Eat Like A King Who's On A Budget Copypasta
Gary Vandenheuvel Net Worth
Actress Zazie Crossword Clue
17 of the best things to do in Bozeman, Montana
15:30 Est
Estes4Me Payroll
Bob Wright Yukon Accident
Dumb Money Showtimes Near Regal Stonecrest At Piper Glen
Koniec veľkorysých plánov. Prestížna LEAF Academy mení adresu, masívny kampus nepostaví
Latest Posts
Article information

Author: Ouida Strosin DO

Last Updated:

Views: 6049

Rating: 4.6 / 5 (56 voted)

Reviews: 87% of readers found this page helpful

Author information

Name: Ouida Strosin DO

Birthday: 1995-04-27

Address: Suite 927 930 Kilback Radial, Candidaville, TN 87795

Phone: +8561498978366

Job: Legacy Manufacturing Specialist

Hobby: Singing, Mountain biking, Water sports, Water sports, Taxidermy, Polo, Pet

Introduction: My name is Ouida Strosin DO, I am a precious, combative, spotless, modern, spotless, beautiful, precious person who loves writing and wants to share my knowledge and understanding with you.