Azure Active Directory Authentication Server Setup¶
This article assumes that you have set up your Azure Active Directory such that it will function with TRiA. If you have not done so, or need assistance in doing so, see Azure Active Directory.
To create an Azure Active Directory Authentication Server:
Click
Identity Managementfrom the navigation sidebar, and then clickAuthentication Serversfrom the top.Click
Add ServerEnter whatever you like for the nickname, and then select ‘Azure Active Directory’ for the
Server Type.For ‘Tenant’, you should provide the domain name associated with the Azure Active Directory instance you are authenticating against.
Unless you have a private Azure instance from Microsoft, you probably want to leave the Authority Host URL set to
https://login.microsoftonline.com. If you _are_ using a private Azure instance, the Authority Host URL should be the authoritative login URL for that private instance.For
Application ID, you want to provide theApplication IDguid from the Azure App Registration. We previously identified this in step 5 of Azure Active Directory.For
Client Secret, use the secret key value that we created in step 7 of Azure Active Directory. If that key is not available, create a new one as per the instructions.
We will verify that the values you entered are correct when you click ‘Submit’. If an error message appears, please check that the values you entered are correct for the Active Directory instance you are trying to authenticate to.
Note: Because the Azure Active Directory instance uses an oAuth mechanism for authentication, you won’t be
able to assign usernames to users authenticating against the Azure Active Directory system. Instead, you
must use the email address for that user as it is in the Azure Active Directory for both the name and
email values when creating users for this Authentication Server.