Summary
During the configuration of DS Service with Active Directory in O365 (Azure AD), we need to create an application registration with rights to read Active Directory objects in your O365 tenant.
Create Azure app for mail sending function
1. Log on Azure portal with your Azure account.
2. If your account gives you access to more than one, click your account in the top right corner, and set your portal session to the desired Azure AD tenant.
3. In the left-hand navigation pane, click the Azure Active Directory service (if it absent, click on All services and find it by name), click App registrations → New registration.
4. When the Register an application page appears, enter your application's registration information:
- Name: Enter DSService.MachineName (or any name you want).
Note: Name of the web app must not include spaces or digits.
- Supported account types: Select ‘Accounts in this organizational directory only’.
5. When finished, click Register.
6. Go to Certificates & secrets → New client secret (key):
Note: Select ‘24 months’ for Expires
7. Add a description for your key and click [Add]. The right-most column will contain the key value (Password), after you save the configuration changes. Be sure to copy the Value for use in Digital Sign Service (inside it’s Password field), as it is not accessible once you leave this page.
8. Click [Overview] to go back. The Application (Client) ID field will contain App principal ID for Digital Sign Service.
9. Click the API Permissions section on the menu → Add a permission. Select tab Microsoft APIs → Click [Microsoft Graph].
10. In the opened panel, click [Application permissions], scroll down to Directory and check on permissions as shown in the following figures:
11. Click [Add permissions] at the bottom of the panel.
12. Then click [Grant admin consent for …] to finish.
You must collect this information for configuration in DS Service.
- Application (Client) ID must be entered in “App principal ID” field.
- Secret Key must be entered in “Client Secrets” field.
Properties
Applies to: DSS for Server 4.3
Reference: TFS #204048, 264043
Knowledge base ID: 0299
Last updated: June 29, 2021
Tuan Dinh Cong
Comments