This page outlines the process of configuring and using the Azure Active Directory API through Zilla to sync permissions and users.
Note: To do this operation you need to be an admin within Zilla ( Specifically SuperAdmin
role ) & admin access with your organization's Azure Active Directory-AAD ( Specifically Global administrator
role ) application.
Login to Zilla with your admin credentials,
You will see your Zilla applications tab, Locate
Add Application
button at the right top, click it,
You will see
Add Application
screen withSearch Library
tab where you may see AAD entry at the top or you may need to typeaad
as search text, You will see an entry forAzure Active Directory
withAdd to Applications
button on the right side, click it,
A dialog appears, add the required field
Instance Name
& you can choose to fill in optional fields for Owner & criticality. ClickAdd to Applications
The AAD instance will get added to your
Applications
, You can see it appear there. Click on the AAD app name,
You will see a detailed AAD Application page. On the right top, you will see
Sync now
button click it,
A dialog appears, Enable
API Integration
Upon enabling the
API Integration
more customization options appear,
First, in those is
Comma separated roles to be synced
provide an AAD Specific roles list, if you want only users of certain roles on AAD to get synced. e.g. If you want all users which are havingGlobal administrator & Global reader
roles your configuration will look like as follows,Second,
Is this a directory? (Yes/No)
if this is your organization directory then sayYes
otherwise if it is a non-directory app sayNo
, e.g. An organization that uses AAD as the directory will have the following configuration, By default, it will beNo
Sync All Accounts? ( Yes/No )
fillingYes
here would sync all your organization users,No
will sync only users who have any roles assigned to them, User without any roles will not be synced. Default valueNo
Finally,
Sync All Groups? ( Yes/No )
will sync all groups from AAD if providedYes
otherwise only security-enabled groups are synced. Default isNo
None of the above 1-4 configs is mandatory. Click the Next
button,
Next, you will see a small dialog
In the next step, you may be asked to log in to Azure Active Directory - first instance, and then sync will start automatically.
ClickNext
You will be taken to
Microsoft
site where you need to log in with the user with Admin (Global administrator
) role for AAD & grant consent on behalf of the organization. ClickAccept
, On successful OAuth, you will be redirected to Zilla Web Application. WithSync in progress...
message for newly added AAD application.
On successful sync, you will see a notification as follows,
You are done, now you can visit various tabs of the Application Details page for AAD on Zilla, to see what application data is brought in by sync, e.g.
Accounts
tab will have details of user accounts that are brought in.If you see some errors or need further assistance, please contact Zilla Support.