Azure Active Directory Authentication Server Setup

This article assumes that you have set up your Azure Active Directory such that it will function with TRiA. If you have not done so, or need assistance in doing so, see Azure Active Directory.

To create an Azure Active Directory Authentication Server:

  1. Click Identity Management from the navigation sidebar, and then click Authentication Servers from the top.

  2. Click Add Server

  3. Enter whatever you like for the nickname, and then select ‘Azure Active Directory’ for the Server Type.

  4. For ‘Tenant’, you should provide the domain name associated with the Azure Active Directory instance you are authenticating against.

  5. Unless you have a private Azure instance from Microsoft, you probably want to leave the Authority Host URL set to https://login.microsoftonline.com. If you _are_ using a private Azure instance, the Authority Host URL should be the authoritative login URL for that private instance.

  6. For Application ID, you want to provide the Application ID guid from the Azure App Registration. We previously identified this in step 5 of Azure Active Directory.

  7. For Client Secret, use the secret key value that we created in step 7 of Azure Active Directory. If that key is not available, create a new one as per the instructions.

We will verify that the values you entered are correct when you click ‘Submit’. If an error message appears, please check that the values you entered are correct for the Active Directory instance you are trying to authenticate to.

Note: Because the Azure Active Directory instance uses an oAuth mechanism for authentication, you won’t be able to assign usernames to users authenticating against the Azure Active Directory system. Instead, you must use the email address for that user as it is in the Azure Active Directory for both the name and email values when creating users for this Authentication Server.