Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

  1. Login to Azure Active Directory with your admin credentials.

  2. Click Azure Active Directory, and from their there you will be redirected to your tenant’s overview page.

    Image Modified
  3. Save the Primary domain for the tenant you want to sync for use in a future step.

    Image Modified

  4. Login to Zilla with your admin credentials.

    Image Modified

  5. You will see your Zilla Applications tab, click Add Application button at the top right top.

    Image Modified

  6. You will see Add Application screen with Search Library tab. Type aad AAD as search text, and click Add to Applications button on the right side of the Azure Active Directory entry.

    Image Modified

  7. Fill in the form with appropriate details and click Add to Applications button.

    Image Modified

  8. The AAD instance will be added to your Applications, click the Azure Active Directory application name.

    Image Modified

  9. You will see a detailed application instance page. Click Sync now in the top right corner.

    Image Modified

  10. A dialog dialogue appears, enable API Integration.

    Image Modified

  11. Upon enabling the API Integration more customization options appear.

    Image RemovedImage Added

  12. AAD tenant's domain name - Fill in the domain name saved from Step

    4 in .

    Comma separated roles to be synced - Provide an AAD Specific roles list if you want only users of certain roles on AAD to get synced. For example, if you want to sync all Azure Active Directory users leave this box empty. If you only want all users which have Global administrator & Global reader roles your configuration will look like:

    Note: If any roles are provided, the Sync All Accounts? (Yes/No) value will be considered No, even if you say Yes.

    Image Removed

    3.

  13. Sync All Accounts? ( Yes/No ) - Yes will sync all of your organization’s users, No will sync only users who have any roles assigned to them. Users without any roles will not be synced. By default, the value is Yes

    , unless roles are specified under Comma separated roles to be synced in which case this configuration will always be No

    .

  14. Sync All Groups? ( Yes/No ) - Yes will sync all groups from Azure Active Directory if provided, otherwise, only security-enabled groups are synced. By default, the value is No.

  15. Comma-separated attributes that identify a user - Provide an AAD-specific attribute (job title, department, etc) for which you want to sync AAD users. For example, if you specify a department, only accounts that have a defined department will be imported.

    Image Added
  16. Click NextAuto Discover Azure Cloud subscriptions? (Yes/No) - Yes allows you to auto-discover all the Azure Cloud subscriptions, by default the value is No.

  17. Auto Sync Child Apps? (Yes/No ) - Yes allows the auto-discovered subscriptions to be automatically synced when the parent is synced, by default the value is No. This value should be set to No if Auto Discover Azure Cloud subscriptions? (Yes/No) is set to No.

  18. Click Sync Now.

  19. Click Next again.

    Image Modified

  20. You will be taken to the Microsoft site where you need to login log in with the user with the Admin (Global administrator) role for AAD and grant consent on behalf of the organization.

  21. The consent screen will look like the image below when Auto Discover Azure Cloud subscriptions? (Yes/No) is set to Yes.

    Image Added

  22. The consent screen will look like the image below when Auto Discover Azure Cloud subscriptions? (Yes/No) is set to No.

    Image Added

  23. Click Accept. On successful OAuth, you will be redirected to Zilla with Sync in progress... message for newly added AAD application instance.

    Image Removed

  24. On successful sync, you will see the following notification:

    Image Modified

Note: In some cases, the process of configuring and using the Azure Active Directory API through Zilla to sync permissions and users with your organization's AAD may be done by an Azure user with Global Reader permissions. When an Azure Global Reader makes the initial sync request the request will need to be approved within the Azure portal by a Global Administrator as shown in the steps below:

Step 1. Global Reader initiates Azure Active Directoy Directory sync to with Zilla.  A consent request will be created in the Azure Active Directory portal.

...