Table of Contents | ||||||||||
---|---|---|---|---|---|---|---|---|---|---|
|
...
Creating Azure Application for Microsoft Partner Center
Step 1a: Login to https://portal.azure.com/ using MFA Enabled Global Administrator Role to get Client ID, Secret ID and set permissions.
Step 1b: In the Microsoft Azure Portal, search for Azure Active Directory and select it.
...
Step 3c: Under API Permissions, Click on Microsoft Graph.
Search permission for the name Organization and select the Organization.Read.All permissions.
Search permission for the name User and select the User.Read permissions.
Once done, click on Update Permissions.
...
Step 3d: Once permissions are set, on the same page, please grant admin access by clicking on the Grant admin consent for Connect Secure and click on Yes button
...
It will lead to add credentials for your Azure AD CSP. Provide details as requested.
...
...
Add Azure AD CSP Credentials
Click on + to add Azure AD CSP credentials.
Choose a Name for the credentials for your reference.
By default Azure CSP Authentication Endpoint will be Global Service, it can be changed by dropdown if the Microsoft login mail id is associated with .us or .com (US government/ Global Service)
Provide Tenant ID - This is the Tenant ID from the created applications. (This is same for both the applications created- Single tenant and Multi-Tenant).
Provide Client ID and Client Secret for created Azure application for Microsoft Partner Center (Single Tenant).
Provide Client ID and Client Secret for created Azure application for Azure Active Directory(Multi-Tenant).
Click on Save to save these credentials successfully. This will lead to the Microsoft login page to ask asking for a consent.
Once the login is successful, the Azure AD Credentials will be stored successfully.
A user having a an MFA EnabledGlobal Administrator role/permissions is required to be used for login.
Using the above method you can add multiple credentials.
...
Click on “Please Click HERE to provide consent” to provide consent on behalf of the company.
By clicking the here, it will redirect to the Microsoft user login screen. Please use the appropriate global admin account to provide consent to successfully add the company and sync the data into CyberCNS.
After clicking on Accept, please close the Microsoft login window.(If it again pop-ups as login to the account)
There is an option to Delete the integration mapping using the Action column. Any company mapping can be deleted if needed.
...
When Azure AD credentials and Company Mapping are added, the two tabs Azure Active Directory and Microsoft Secure Score will be enabled under the Company view> Company that have the mapping.
Please wait for the sync to complete to get the data under Azure Active Directory and Microsoft Secure Score section.
Under Azure Active Directory> Sync Now can help you sync the data at any point of time.
Once Sync now is selected, the Jobs > Azure Active Directory jobs section will show a job for sync in progress. Once it is completed, the data will be successfully shown under Azure Active Directory and Microsoft Secure Score.
...