Changes for page Unternehmensanwendung registrieren in der Microsoft Entra ID
Last modified by Sabrina V. on 2026/10/06 06:27
From version 8.1
edited by Sabrina V.
on 2025/07/21 09:44
on 2025/07/21 09:44
Change comment:
There is no comment for this version
To version 12.1
edited by Sabrina V.
on 2026/10/06 06:27
on 2026/10/06 06:27
Change comment:
There is no comment for this version
Summary
-
Page properties (1 modified, 0 added, 0 removed)
Details
- Page properties
-
- Content
-
... ... @@ -2,18 +2,18 @@ 2 2 3 3 Enterprise applications are often used as an interface between Microsoft Entra and internally used applications, for example to give employees access to Microsoft 365. To do this, you need to register one or more applications centrally. This chapter provides an introduction to how you can register enterprise applications and assign permissions to them. It applies to the following areas of application: 4 4 5 -* [[Intune Management>>doc:ACMP.6 8.ACMP-Solutions.Intune Management.WebHome]]6 -* [[Microsoft 365>>doc:ACMP.6 8.ACMP-Solutions.Lizenzmanagement.Microsoft 365.WebHome]]7 -* [[Setting up OAuth2 on the ACMPServer>>doc:ACMP.68.ACMP-Solutions.System.Einstellungen.ACMP Server.OAuth2 am ACMP Server einrichten.WebHome]]8 -* [[ ACMPIntune Connector>>doc:ACMP.68.ACMP-Solutions.Client-Management.ACMP Intune Connector.WebHome]]5 +* [[Intune Management>>doc:ACMP.610.ACMP-Solutions.Intune Management.WebHome]] 6 +* [[Microsoft 365>>doc:ACMP.610.ACMP-Solutions.Lizenzmanagement.Microsoft 365.WebHome]] 7 +* [[Setting up OAuth2 on the acmp Server>>doc:ACMP.610.ACMP-Solutions.System.Einstellungen.ACMP Server.OAuth2 am ACMP Server einrichten.WebHome]] 8 +* [[acmp Intune Connector>>doc:ACMP.610.ACMP-Solutions.Client-Management.ACMP Intune Connector.WebHome]] 9 9 10 10 = Preparing for the Microsoft Entra ID = 11 11 12 -In order to work in one of the above application areas, you must first open the Microsoft Entra Admin Centre and register a company application. You will then need to grant the necessary permissions within that application. These steps are necessary to enable ACMPto access and import the required data.12 +In order to work in one of the above application areas, you must first open the Microsoft Entra Admin Centre and register a company application. You will then need to grant the necessary permissions within that application. These steps are necessary to enable acmp to access and import the required data. 13 13 14 14 == Register an Enterprise Application == 15 15 16 -First, log in to your [[Microsoft Entra ID>>url:https://aad.portal.azure.com/]]. Click the Identity > Manage tab > //Enterprise Applications// and create a new application registration. 16 +First, log in to your [[Microsoft Entra ID>>url:https://aad.portal.azure.com/]]. Click the //Identity //> //Manage //tab > //Enterprise Applications// and create a new application registration. 17 17 18 18 [[App registrations in Microsoft Entra ID>>image:68_Unternehmensanwendung registrieren_App Registrierung Oberfläche_1919.png]] 19 19 ... ... @@ -20,7 +20,7 @@ 20 20 Enter all the necessary information there: Assign an app name and select the accounts to be supported. 21 21 22 22 {{box}} 23 -**Note for [[setting up OAuth2 on the ACMPServer>>doc:ACMP.68.ACMP-Solutions.System.Einstellungen.ACMP Server.OAuth2 am ACMP Server einrichten.WebHome]]:**23 +**Note for [[setting up OAuth2 on the acmp Server>>doc:ACMP.610.ACMP-Solutions.System.Einstellungen.ACMP Server.OAuth2 am ACMP Server einrichten.WebHome]]:** 24 24 If only one account from the organisation directory is allowed to access it, you must select the first option. Under the redirect URI, you must enter the following: https://login.microsoftonline.com/common/oauth2/nativeclient 25 25 Register the application as //Public client/native (mobile & desktop)//. 26 26 {{/box}} ... ... @@ -81,7 +81,7 @@ 81 81 Only the application authorisations need to be assigned, not the delegated authorisations! 82 82 {{/aagon.warnungsbox}} 83 83 84 -=== Setting up OAuth 2 on the ACMPServer ===84 +=== Setting up OAuth 2 on the acmp Server === 85 85 86 86 |**Type: Delegated** 87 87 |IMAP.AccessAsUser.All ... ... @@ -89,7 +89,7 @@ 89 89 |SMTP.Send 90 90 |offline_access 91 91 92 -=== ACMPIntune Connector ===92 +=== acmp Intune Connector === 93 93 94 94 |**Type: Delegated**|**Type: Applicatione** 95 95 |DeviceManagementManagedDevices.Read.All|DeviceManagementApps.Read.All ... ... @@ -124,8 +124,8 @@ 124 124 Certificates can be used as an authentication method to log in to Microsoft Entra ID. A certificate always consists of a public and a private part, with the public key being loaded directly into Microsoft Entra ID. Both parts are required at a later stage when you add the certificate to the connection information for creating a new portal. This certificate pair must be generated in advance. Read here how to create a certificate via [[Microsoft>>url:https://learn.microsoft.com/en-us/azure/app-service/configure-ssl-certificate?tabs=apex%2Cportal]] or Open SSL. Due to the higher security level, Microsoft recommends using a certificate as login information 125 125 126 126 {{aagon.infobox}} 127 -The PKCS#12 or PFX/P12 format is often used for certificates. This is not supported by ACMP, as the certificate and key files are combined in a single file. However, you can use the OpenSSL commands openssl pkcs12 -in path.p12 -out newfile.crt -clcerts –nokeys for the certificate and openssl pkcs12 -in path.p12 -out newfile.pem -nocerts –nodes for the private key to generate two files from the file.128 -You can find continuing info on this topic in the section [[Managing certificates>>doc:ACMP.6 8.ACMP-Solutions.System.Einstellungen.ACMP Server.WebHome||anchor="HEnde-zu-Ende-VerschlFCsselung"]].127 +The PKCS#12 or PFX/P12 format is often used for certificates. This is not supported by acmp, as the certificate and key files are combined in a single file. However, you can use the OpenSSL commands openssl pkcs12 -in path.p12 -out newfile.crt -clcerts –nokeys for the certificate and openssl pkcs12 -in path.p12 -out newfile.pem -nocerts –nodes for the private key to generate two files from the file. 128 +You can find continuing info on this topic in the section [[Managing certificates>>doc:ACMP.610.ACMP-Solutions.System.Einstellungen.ACMP Server.WebHome||anchor="HEnde-zu-Ende-VerschlFCsselung"]]. 129 129 {{/aagon.infobox}} 130 130 131 131 Navigate to the //Certificates & Secrets// item within the previously registered application. Click on the //Certificates //tab in the details and upload the certificate you created earlier. ... ... @@ -152,11 +152,11 @@ 152 152 [[Add secret client key>>image:68_Unternehmensanwendung registrieren_Geheimen Clientschlüssel hinzufügen_1919.png||alt="68_Unternehmensanwendung registrieren_Geheimen Clientschlüssel_1919.png"]] 153 153 154 154 {{aagon.infobox}} 155 -If you want to use the secret client key for the ACMPIntune Connector, you must create a new key after the validity period has expired and store it in theAESB.155 +If you want to use the secret client key for the acmp Intune Connector, you must create a new key after the validity period has expired and store it in the aesb. 156 156 {{/aagon.infobox}} 157 157 158 158 {{aagon.infobox}} 159 -You will need the secret client key you created at a later point (e.g. when setting up AESBor in Microsoft 365 to create new portals in theACMP Console). Therefore, save the secret client key so that you can access it later.159 +You will need the secret client key you created at a later point (e.g. when setting up aesb or in Microsoft 365 to create new portals in the acmp Console). Therefore, save the secret client key so that you can access it later. 160 160 {{/aagon.infobox}} 161 161 162 162 = Next steps = ... ... @@ -163,8 +163,8 @@ 163 163 164 164 Now that you have registered the company application and granted the necessary permissions, you can switch to the respective application area and continue with your work: 165 165 166 -* [[Intune Management>>doc:ACMP.6 8.ACMP-Solutions.Intune Management.WebHome]]167 -* [[Microsoft 365>>doc:ACMP.6 8.ACMP-Solutions.Lizenzmanagement.Microsoft 365.WebHome]]168 -* [[Setting up OAuth2 on the ACMPServer>>doc:ACMP.68.ACMP-Solutions.System.Einstellungen.ACMP Server.OAuth2 am ACMP Server einrichten.WebHome]]169 -* [[ ACMPIntune Connector>>doc:ACMP.68.ACMP-Solutions.Client-Management.ACMP Intune Connector.WebHome]]166 +* [[Intune Management>>doc:ACMP.610.ACMP-Solutions.Intune Management.WebHome]] 167 +* [[Microsoft 365>>doc:ACMP.610.ACMP-Solutions.Lizenzmanagement.Microsoft 365.WebHome]] 168 +* [[Setting up OAuth2 on the acmp Server>>doc:ACMP.610.ACMP-Solutions.System.Einstellungen.ACMP Server.OAuth2 am ACMP Server einrichten.WebHome]] 169 +* [[acmp Intune Connector>>doc:ACMP.610.ACMP-Solutions.Client-Management.ACMP Intune Connector.WebHome]] 170 170

