Include Page | ||||
---|---|---|---|---|
|
...
Info |
---|
Note: To do this operation you need to be an admin or application owner within Zilla |
...
and have admin access with your organization's Azure Active Directory-AAD |
...
application, specifically |
Login to Azure Active Directory with your admin credentials.
Click
Azure Active Directory
, from their you will be redirected to your tenant’s overview page.Save the Primary domain for the tenant you want to sync for use in a future step.
Login to Zilla with your admin credentials
...
.
You will see your Zilla
...
Applications tab,
...
click
Add Application
button at the right top
...
.
You will see Add Application screen with Search Library tab
...
. Type
aad
as search text,
...
and click
Add to Applications
button on the right side
...
of the Azure Active Directory entry.
...
Fill in the form with appropriate details and click
Add to Applications
button.
...
The AAD instance will
...
be added to your Applications,
...
click the Azure Active Directory application name.
You will see a detailed
...
application instance page.
...
Click
Sync now
in top right corner.A dialog appears,
...
enable API Integration.
Upon enabling the API Integration more customization options appear
...
.
...
First, in the
AAD tenant's domain name
- Fill in the domain name saved fromStep 4
in .Comma separated roles to be synced
- Provide an AAD Specific roles list
if you want only users of certain roles on AAD to get synced.
For example, if you want to sync all Azure
Active Directory users leave this box empty. If you only want all users which
have
Global administrator & Global reader
roles your configuration will look like
:
Note: If any roles are provided, the
Sync All Accounts? (Yes/No)
value will be consideredNo
, even if you sayYes
.
Is this a directory? (Yes/No)
- If this is your organization's directory then
input
Yes
otherwise if it is a non-directory
No
, e.g. An organization that uses AAD as the directory will have the following configuration, By default, it will beNo
application input
No
. By default the value isNo
.Sync All Accounts? ( Yes/No )
-
Yes
will sync all of your
organization’s users,
No
will sync only users who have any roles assigned to them
. Users without any roles will not be synced.
By default the value is
Yes
, unless roles are specified under
Comma separated roles to be synced
in which case this configuration will always beNo
.
Sync All Groups? ( Yes/No )
-Yes
will sync all groups from
Azure Active Directory if provided
Yes
, otherwise only security-enabled groups are synced.
By default the value is
No
None of the above 1-4 configs are mandatory. Click the Next
button,
...
.
Comma separated attributes that identify a user
- Provide an AAD specific attribute (job title, department, etc) for which you want to sync AAD users. For example, if you specify department, only accounts that have defined department will be imported.
Click
Next
.Click
Next
again.You will be taken to
Microsoft
site where you need to
...
login with the user with Admin (
Global administrator
) role for AAD
...
and grant consent on behalf of the organization. Click
Accept
...
. On successful OAuth, you will be redirected to Zilla
...
with
Sync in progress...
message for newly added AAD application instance.On successful sync, you will see
...
You are done, now you can visit various tabs of the Application Details page for AAD on Zilla, to see what application data is brought in by sync, e.g.
Accounts
tab will have details of user accounts that are brought in.If you see some errors or need further assistance, please contact Zilla Support.
the following notification:
Note: In some cases, the process of configuring and using the Azure Active Directory API through Zilla to sync permissions and users with your organization's AAD may be done by an Azure user with Global Reader permissions. When an Azure Global Reader makes the initial sync request the request will need to be approved within the Azure portal by a Global Administrator as shown in the steps below:
...
Step 1. Global Reader initiates Azure AD Sync Active Directoy sync to Zilla. A consent request will be created in the Azure AD Active Directory portal.
...
Step 2. In Azure AD Active Directory go to Enterprise Applicationsapplications, then Admin Consent Requestsconsent requests. The pending request appears waiting for approval.
...
Step 3. The Global Administrator approves the permissions request by clicking Accept
.
...
Note: If you try to sync in a tenant other than for which you have entered the domain, Microsoft will return an error message.
...
Include Page | ||||
---|---|---|---|---|
|