Configure Azure Active Directory App Registration (2024)

User Workspace Manager

Home

>

This document provides instructions to create an Application Registration on your Microsoft Azure Active Directory (AAD) instance, and to allow connection of User Workspace Manager Consoles and Agents to your AAD instance.

Instructions

The endpoint and console require an application registration to be set up in the AAD domain. This application uses a client certificate to allow the endpoint to access AAD without any user interaction. Steps to create the application are performed in the AAD portal using a suitably privileged account and are as follows:

  1. Go to 'Azure Active Directory’ page for the tenant. Click on ‘App Registrations’ in the left pane then ‘New Registration’ on the right.

  2. Enter a name for the registration and ‘single tenant’ for the account type. A redirect URI is not required at this stage. Click on ‘Register’.

  3. Click on ‘Authentication’ on the left pane. On the right pane, click ‘Add a platform’ then click ‘Mobile and Desktop Applications’. Tick the first redirect URL:

    https://login.microsoftonline.com/common/oauth2/nativeclient

  4. Create or acquire a certificate for use by the endpoint. The application registration on the portal requires only the public key. Each endpoint needs the certificate with the private key installed in the Local Computer - Personal store. The certificate may be self-signed if required. A simple method to create the certificate is via PowerShell 'New-SelfSignedCertificate' cmdlet (see later).

  5. Add the certificate to the application by going to the overview page and clicking on ‘Add certificate or secret’ and uploading the .cer file. The portal will display the certificate thumbprint, which is needed by the console when adding AAD conditions.

  6. Click on ‘API Permissions’ and add permissions as detailed below. Grant administrative consent for them where required.

Microsoft Graph Application Permissions (Endpoint)

  • Device.Readall

  • Group.Readall

  • User.Readall

Microsoft Graph Delegated Permissions (Console)

Creating a Self-Signed Certificate

From an elevated PowerShell prompt, enter:

$certname = "My UWM Certificate"

$cert = New-SelfSignedCertificate -Subject "CN=$certname"

-CertStoreLocation "Cert:\CurrentUser\My"

-KeyExportPolicy Exportable -KeySpec Signature -KeyLength 2048

-KeyAlgorithm RSA -HashAlgorithm SHA256

This will create the certificate in the current user personal store with an exportable private key. It can be exported either by using certmgr.msc or with the following PowerShell commands (using the $cert variable from above):

Export-Certificate -Cert $cert -FilePath "$certname.cer"

  • Exports the .cer file for upload to the portal

$pwd = ConvertTo-SecureString -String "myPassword" -Force -AsPlainText

Export-PfxCertificate -Cert $cert -FilePath "$certname.pfx"

-Password $pwd

  • Exports a .pfx file protected by the specified password. This contains the private key needed by endpoints.

The certificate may be deleted from the current user personal store after generating the .pfx and .cer files.

Console AAD Condition Support

The configuration contains Azure AD Tenant details providing connection information for endpoints. The information can be entered via the Manage tab for Environment Manager, the Global Settings tab for Application Control, and the Resources Setup tab for Performance Manager. The following links pertain to specific AAD functionality for each product.

Application Control:

Creating a connection to Azure Active Directory

Group Rules

User Rules

Environment Manager:

Creating a connection to Azure Active Directory

Performance Manager:

Creating a connection to Azure Active Directory

Was this article useful?

Copyright © 2023, Ivanti, Inc. All rights reserved.

Privacy and Legal

Configure Azure Active Directory App Registration (2024)
Top Articles
Best Crypto Exchanges of 2024: A Comprehensive Guide for Investors
How can I calculate break-even analysis in Excel?
DPhil Research - List of thesis titles
Television Archive News Search Service
Citibank Branch Locations In Orlando Florida
Ret Paladin Phase 2 Bis Wotlk
Shorthand: The Write Way to Speed Up Communication
David Packouz Girlfriend
Student Rating Of Teaching Umn
Everything You Need to Know About Holly by Stephen King
Sarpian Cat
Chic Lash Boutique Highland Village
Gino Jennings Live Stream Today
N2O4 Lewis Structure & Characteristics (13 Complete Facts)
2 Corinthians 6 Nlt
Lancasterfire Live Incidents
Google Flights Missoula
Walmart stores in 6 states no longer provide single-use bags at checkout: Which states are next?
Urban Airship Expands its Mobile Platform to Transform Customer Communications
How Much Is Tay Ks Bail
Union Ironworkers Job Hotline
Vandymania Com Forums
Hampton University Ministers Conference Registration
Walgreens 8 Mile Dequindre
Rek Funerals
Weathervane Broken Monorail
11526 Lake Ave Cleveland Oh 44102
CVS Health’s MinuteClinic Introduces New Virtual Care Offering
Mynahealthcare Login
Buhl Park Summer Concert Series 2023 Schedule
The Powers Below Drop Rate
Joplin Pets Craigslist
Tamil Play.com
Maybe Meant To Be Chapter 43
Aveda Caramel Toner Formula
Leatherwall Ll Classifieds
Craigslist Tulsa Ok Farm And Garden
Gvod 6014
2 Pm Cdt
Download Diablo 2 From Blizzard
Craigslist Boats Dallas
5A Division 1 Playoff Bracket
11 Best Hotels in Cologne (Köln), Germany in 2024 - My Germany Vacation
FREE - Divitarot.com - Tarot Denis Lapierre - Free divinatory tarot - Your divinatory tarot - Your future according to the cards! - Official website of Denis Lapierre - LIVE TAROT - Online Free Tarot cards reading - TAROT - Your free online latin tarot re
Craigslist Food And Beverage Jobs Chicago
Deezy Jamaican Food
VerTRIO Comfort MHR 1800 - 3 Standen Elektrische Kachel - Hoog Capaciteit Carbon... | bol
The Pretty Kitty Tanglewood
Ty Glass Sentenced
Raley Scrubs - Midtown
Tamilblasters.wu
Tamilyogi Cc
Latest Posts
Article information

Author: Ouida Strosin DO

Last Updated:

Views: 6049

Rating: 4.6 / 5 (56 voted)

Reviews: 87% of readers found this page helpful

Author information

Name: Ouida Strosin DO

Birthday: 1995-04-27

Address: Suite 927 930 Kilback Radial, Candidaville, TN 87795

Phone: +8561498978366

Job: Legacy Manufacturing Specialist

Hobby: Singing, Mountain biking, Water sports, Water sports, Taxidermy, Polo, Pet

Introduction: My name is Ouida Strosin DO, I am a precious, combative, spotless, modern, spotless, beautiful, precious person who loves writing and wants to share my knowledge and understanding with you.