Clever IDM Enterprise Product Guide

Azure OAuth 2.0 Setup

  1. From portal.azure.com, select Azure Active Directory.

    Azure_1.png
  2. Select App Registrations.

    Azure_2.png
  3. Click New Registration.

    Azure_3.png
  4. Provide a Name for use within the API, select either single-tenant or multi-tenant, and click Register.

    Azure_4.png
  5. Once Registered, take note of the Client ID.

    Azure_5.png
  6. Select API Permissions in the left menu, and then click Add Permissions.

    Azure_6.png
  7. Go to Microsoft Graph.

    Azure_7_-_2.png
  8. Then select Application Permissions.

    Azure_8_-_2.png
  9. Search for the Directory.ReadWrite.All permission. Select it, then click Add Permission.

    Azure_9_-_2.png
  10. Select Grant Admin consent for Identity Automation permissions.

    Azure_8.png
  11. Go to Certificates & Secrets and select New Client Secret.

    Azure_9-2.png
  12. Add New Client Secret.

    Azure_10.png

    Note

    Make sure to save the Value that shows when the Client Secret is created. This page is the only time it will be viewable, so ensure it is captured for future use and stored in a secure place, such as a password vault.

    The maximum amount of time for the secret is 24 months, even if Custom is selected.

  13. Go to Roles and Administrators | Preview, and select here to go to the directory-level roles.

    Azure_13.png
  14. Search for Helpdesk Administrator and select the row.

    Note

    If you would like to also update administrator passwords, you can use the Global Administrator role or create a custom role.

    Azure_14.png
  15. Select Add Assignments.

    Azure_15.png
  16. Search for the application you registered in step 4 and select it. Once selected, click Add to add it to the role. This gives the application the permissions to set non-administrator passwords.

    Azure_16.png
  17. Go back to the All Roles view by clicking All Roles at the top of the window.

    Azure_17.png
  18. Search for User Administrator and select the row.

    Azure_18.png
  19. Select Add Assignments.

    Azure_19.png
  20. Search for the application you registered in Step 4 and select it. Once selected, click Add to add it to the role. This gives the application the permissions to delete non-administrator accounts.

    Azure_20.png