Changes for page Microsoft 365
Last modified by Sabrina V. on 2025/05/15 12:38
From version 6.1
edited by Sabrina V.
on 2025/05/15 12:38
on 2025/05/15 12:38
Change comment:
There is no comment for this version
To version 1.4
edited by Sabrina V.
on 2025/02/13 10:11
on 2025/02/13 10:11
Change comment:
There is no comment for this version
Summary
-
Page properties (1 modified, 0 added, 0 removed)
Details
- Page properties
-
- Content
-
... ... @@ -1,10 +1,100 @@ 1 1 {{aagon.floatingbox/}} 2 2 3 -= Registerpreparationsfor Microsoft Entra IDand enterprise application=3 += Preparing for the Microsoft Entra ID = 4 4 5 -To use Microsoft 365, you must first navigate to the Microsoft Entra Admin Centre, register a businessapplication, and grant the necessary permissions within that application. These steps are necessarytoallowACMP to access and import the required Microsoft 365 data.Detailed instructions on how to do this can be found [[here>>doc:ACMP.68.Unternehmensanwendung registrieren in der Microsoft Entra ID.WebHome]], along with all the permissions you will need to grant.5 +To use Microsoft 365, you must first navigate to the Microsoft Entra Admin Centre, register an enterprise application, and grant the necessary permissions within that application. These steps are necessary for ACMP to access and import the required Microsoft 365 data. 6 6 7 +== Register an Enterprise Application == 7 7 9 +First, log in to your [[Microsoft Entra ID>>url:https://aad.portal.azure.com/]] . Click the //Manage// tab > //Enterprise Applications// and create a new application registration. 10 + 11 +[[Application registrations in Microsoft Entra ID>>image:67_Microsoft 365_App-Registrierung in der Entra_2910.png]] 12 + 13 +Enter all required information: Enter an application name and select the accounts to support. Click //Register// to complete the process. 14 + 15 +[[Registering an application>>image:67_Microsoft 365_Anwendung registrieren_2262.png]] 16 + 17 +When you open the created application, you will see a summary of the information added. You will need the application and directory ID from this for the next step when you create a new portal for Microsoft 365. 18 + 19 +[[Application information summary>>image:67_Microsoft 365_Zusammenfassung der Anwendungsinformationen_3344.png]] 20 + 21 +== Distribute permissions == 22 + 23 +Next, grant the required permissions to the business application so that the interface can be accessed. To do this, go to the Permissions section within the registered application (//Security// > //Permissions//). 24 + 25 +[[Permissions>>image:67_Microsoft 365_Berechtigungen_2720.png]] 26 + 27 +Click //Add Permission//. This will open a page where you can request API permissions. In this step you need to select Microsoft Graph. 28 + 29 +[[API Permissions: Request Microsoft Graph>>image:67_Microsoft 365_Microsoft Graph_1284.png||data-xwiki-image-style-alignment="center" height="822" width="650"]] 30 + 31 +**Only the application permissions are required to use Microsoft 365. Add the following values one at a time and repeat the process until both list entries are added:** 32 + 33 +* **User.Read.All (Type: Application)** 34 +* **Organisation.Read.All (Type: Application)** 35 + 36 +{{aagon.warnungsbox}} 37 +You only need to assign the application permissions, not the delegated permissions! 38 +{{/aagon.warnungsbox}} 39 + 40 +[[Assigning application permissions>>image:67_Microsof 365_Anwendungen verteilen_Umrandung_3822.png||alt="67_Microsof 365_Anwendungen verteilen_3822.png"]] 41 + 42 +Once you have selected both permissions, click //Add Permissions//. You will see the entries in the overview. 43 + 44 +[[Assigned privileges (without consent)>>image:67_Microsoft 365_Verteilte Berechtigungen (ohne Einwilligung)_2818.png]] 45 + 46 +You may need to grant permissions if you have not already done so. To do this, click on the //'Grant administrator consent for %your company%//' field. This will change the status and provide user consent. 47 + 48 +[[Approved permissions>>image:67_Microsoft 365_Verteilte Berechtigungen (ohne Einwilligung)_2818.png]] 49 + 50 += Upload private client keys or certificates = 51 + 52 +When you first set up Microsoft 365, you need to specify authentication types. You can choose from two methods supported by the Microsoft Client Credentials Provider: //certificates// or //secret client keys//. 53 + 54 +{{aagon.infobox}} 55 +The procedure is different depending on the authentication type you choose. Read below to find out what to do for each method. 56 +{{/aagon.infobox}} 57 + 58 +== Upload a certificate == 59 + 60 +{{aagon.infobox}} 61 +Because of the higher level of security, Microsoft recommends that you use a certificate as your credential. 62 +{{/aagon.infobox}} 63 + 64 +Certificates can be used as an authentication method to log in to Microsoft Entra ID. A certificate always consists of a public and a private part, where the public key is loaded directly into the Microsoft Entra ID. Both parts will be needed later when you can add the certificate to the connection information to create a new portal. This certificate pair must be created beforehand. Read on to find out how to create a certificate using [[Microsoft>>url:https://learn.microsoft.com/en-us/azure/app-service/configure-ssl-certificate?tabs=apex%2Cportal]] or [[Open SSL>>url:https://stackoverflow.com/questions/6307886/how-to-create-pfx-file-from-certificate-and-private-key]]. 65 + 66 +{{aagon.infobox}} 67 +The PKCS#12 or PFX/P12 format is often used for certificates. This is not supported by ACMP because the certificate and key file are combined in one file. However, you can use the OpenSSL commands openssl pkcs12 -in path.p12 -out newfile.crt -clcerts –nokeys to generate two files from the file for the certificate and openssl pkcs12 -in path.p12 -out newfile.pem -nocerts –nodes for the private key. 68 +For more information, see the [[Managing certificates>>doc:ACMP.67.ACMP-Solutions.System.Einstellungen.ACMP Server.WebHome||anchor="HEnde-zu-Ende-VerschlFCsselung"]] section. 69 +{{/aagon.infobox}} 70 + 71 +Within the previously registered application, navigate to //Certificates & Secrets//. In the details section, click the //Certificates// tab and upload the certificate you created earlier. 72 + 73 +[[Upload certificates>>image:67_Microsoft 365_Zertifikat hochladen_3356.png]] 74 + 75 +A field will open on the right-hand side for you to upload the certificate. Browse to the appropriate directory and upload the file, then enter an optional description for the certificate. Click //Add// and the certificate will be saved for the application. 76 + 77 +{{aagon.infobox}} 78 +Please note that only .cer, .pem and .crt file types are supported when uploading a certificate. 79 +{{/aagon.infobox}} 80 + 81 + 82 +[[Uploaded certificate in Microsoft Entra>>image:67_Microsoft 365_Hochgeladenes Zertifikat in Entra_3052.png]] 83 + 84 +== Adding a secret client key == 85 + 86 +The secret client key is a string of characters used by the enterprise application as an authentication key or proof of identity when requesting the token. To do this, go to the //Certificates & Secrets// section of the registered application. In the details, click on the //Secret Client Keys// tab and create a new key. 87 + 88 +[[Adding a news client key>>image:67_Microsoft 365_Neuen Clientschlüssel hinterlegen_3052.png]] 89 + 90 +When creating a new secret client key, you will be given the option to configure the validity period. Please note that when the validity period expires, a new key must be created and saved. 91 + 92 +[[Adding a secret client key>>image:67_Microsoft 365_Geheimen Clientschlüssel hinzufügen_3052.png]] 93 + 94 +{{aagon.infobox}} 95 +You will need the created secret client key when setting up Microsoft 365 to create new portals in the ACMP console. Therefore, save the secret client key so that you can access it later. 96 +{{/aagon.infobox}} 97 + 8 8 = Settings for Microsoft 365 = 9 9 10 10 The //Microsoft 365// section provides an overview of the portals you have saved and from which you want to import information. ... ... @@ -13,7 +13,7 @@ 13 13 14 14 To manage the portals, in the open ACMP console, navigate to //System// > //Settings// > //Licence// //Management// > //Microsoft// //365//. The view is split into two parts. On the left, you will see the action fields where you can add ([[image:1731318667592-246.png]]), edit ([[image:1731318667592-758.png]]) or delete ([[image:1731318667592-156.png]]) the Microsoft 365 portals. At the bottom is a list of all the existing portals that you have previously created. On the right, you can see the details of the portal you selected. 15 15 16 -[[Microsoft 365 portals overview>>image:6 8_M365_Hinzugefügtes Portal_1361.png||alt="67_M365_Hinzugefügtes Portal_1361.png"]]106 +[[Microsoft 365 portals overview>>image:67_M365_Hinzugefügtes Portal_1361.png]] 17 17 18 18 == Add a Microsoft 365 portal == 19 19 ... ... @@ -57,7 +57,7 @@ 57 57 58 58 Finish the wizard by clicking //Done//. You will return to the overview page within the ACMP settings, where the new portal has been added to the list. 59 59 60 -[[Added portal in the Microsoft 365 settings>>image:6 8_M365_Hinzugefügtes Portal_1361.png||alt="67_M365_Hinzugefügtes Portal_1361.png"]]150 +[[Added portal in the Microsoft 365 settings>>image:67_M365_Hinzugefügtes Portal_1361.png]] 61 61 62 62 == Editing or deleting Microsoft 365 portals == 63 63 ... ... @@ -79,7 +79,7 @@ 79 79 80 80 = Licenses, products and compliance = 81 81 82 -The execution of two [[server tasks>>doc:ACMP.6 8.ACMP-Solutions.System.Einstellungen.ACMP Server.WebHome||anchor="HGeplanteServeraufgaben"]] is required to import licenses and products and to calculate the status:172 +The execution of two [[server tasks>>doc:ACMP.67.ACMP-Solutions.System.Einstellungen.ACMP Server.WebHome||anchor="HGeplanteServeraufgaben"]] is required to import licenses and products and to calculate the status: 83 83 84 84 |**Server task**|**Description** 85 85 |1. Import Microsoft 365 licence data|The server task imports the Microsoft 365 licence and product data for License Management and creates the licences and products. ... ... @@ -86,13 +86,13 @@ 86 86 |2. Recalculation of the data for the compliance view|The compliance data is recalculated to determine the consumers and the status of the licence. 87 87 88 88 {{aagon.infobox}} 89 -The execution interval of the Scheduled Server Tasks depends on the configured start condition. You can view the status of the server jobs using the [[Server Monitor>>doc:ACMP.6 8.Arbeiten mit der ACMP Console.Aufbau der Console.Ribbonleiste.Monitore.WebHome||anchor="HServermonitor"]].179 +The execution interval of the Scheduled Server Tasks depends on the configured start condition. You can view the status of the server jobs using the [[Server Monitor>>doc:ACMP.67.Arbeiten mit der ACMP Console.Aufbau der Console.Ribbonleiste.Monitore.WebHome||anchor="HServermonitor"]]. 90 90 {{/aagon.infobox}} 91 91 92 92 The licences, products and required contacts are created when the data is imported. The compliance recalculation is used to calculate the status. 93 93 94 94 {{aagon.infobox}} 95 -The new contacts can be accessed from the [[Master Data>>doc:ACMP.6 8.Arbeiten mit der ACMP Console.Aufbau der Console.Ribbonleiste.Stammdaten.WebHome]] (//Master Data //> //Contacts//). The contacts are required to complete the compliance calculation at the end and to record them as licence users and link them to the appropriate licences and products.185 +The new contacts can be accessed from the [[Master Data>>doc:ACMP.67.Arbeiten mit der ACMP Console.Aufbau der Console.Ribbonleiste.Stammdaten.WebHome]] (//Master Data //> //Contacts//). The contacts are required to complete the compliance calculation at the end and to record them as licence users and link them to the appropriate licences and products. 96 96 {{/aagon.infobox}} 97 97 98 98 For more detailed information on products and licences, navigate to Licence Management. ... ... @@ -101,13 +101,13 @@ 101 101 All licence and product data from the portal is read-only and cannot be edited. The Microsoft 365 portal is the leading system and cannot be changed by the administrator. 102 102 {{/aagon.infobox}} 103 103 104 -[[Read linked product from licence>>image:6 8_M365_Lizenzen Verknüpfte Produkte_1831.png||alt="67_M365_Lizenzen Verknüpfte Produkte_1831.png"]]194 +[[Read linked product from licence>>image:67_M365_Lizenzen Verknüpfte Produkte_1831.png]] 105 105 106 106 == Products == 107 107 108 108 Products are created on initial creation in the following output directory //Microsoft 365// > //Portal name// (here: Microsoft 365 Portal). Products can be dragged and dropped into other directories as required. The product name is made up of the portal name (prefix) and the licence title. 109 109 110 -[[Reading Microsoft 365 portal products>>image:6 8_M365_Produkte markiert_1280.png||alt="67_M365_Produkte markiert_1280.png"]]200 +[[Reading Microsoft 365 portal products>>image:67_M365_Produkte markiert_1280.png]] 111 111 112 112 {{aagon.infobox}} 113 113 There is a new automatic consumer (type: Microsoft 365) to correctly identify consumers. This is only used for Microsoft 365 imports and is not available for selection when manually creating a product ... ... @@ -135,69 +135,68 @@ 135 135 |The portal has been deleted.|The complete portal has been deleted from the settings and no longer exists.|If you have deleted the portal in the ACMP settings, you must manually delete the already imported products and licenses from the License Management. 136 136 137 137 {{aagon.infobox}} 138 -You can find out more about the different statuses of the licenses [[here>>doc:ACMP.6 8.ACMP-Solutions.Lizenzmanagement.Compliance.WebHome||anchor="HStatusderLizenzen"]].228 +You can find out more about the different statuses of the licenses [[here>>doc:ACMP.67.ACMP-Solutions.Lizenzmanagement.Compliance.WebHome||anchor="HStatusderLizenzen"]]. 139 139 {{/aagon.infobox}} 140 140 141 -= Errormessages whenaccessingthe Microsoft 365 GraphAPI =231 += Fehlermeldungen beim Zugriff auf die Microsoft 365 GraphAPI = 142 142 143 - An access tokenisrequiredtoaccessthe Microsoft 365 GraphAPI.Thistoken isgeneratedbythescheduledservertask whenimportingMicrosoft 365datafor eachconfiguredportal.If thereareproblemsgeneratingthetoken, this willbe displayedasanerrormessageinthe log.You canfind thecorresponding entryinthe [[ServerMonitor>>doc:ACMP.68.Arbeiten mit der ACMP Console.Aufbau der Console.Ribbonleiste.Monitore.WebHome||anchor="HServermonitor"]].233 +Beim Zugriff auf die Microsoft 365 GraphAPI wird ein sogenannter Access Token benötigt. Dieser Token wird von der geplanten Serveraufgabe beim Import der Microsoft 365 Daten für jedes konfigurierte Portal generiert. Sollte es beim Generieren des Tokens zu Problemen kommen, wird Ihnen dies als Fehlermeldung im Log angezeigt. Den Eintrag dazu finden Sie im [[Servermonitor>>doc:ACMP.67.Arbeiten mit der ACMP Console.Aufbau der Console.Ribbonleiste.Monitore.WebHome||anchor="HServermonitor"]]. 144 144 145 -Gener ally,therearetwobasic errorsthatcan occur:235 +Generell gibt es zwei grundsätzliche Fehler, die auftreten können: 146 146 147 -1. Anerrorreportedby theGraphAPIwasgeneratedby thecorrespondingwebserver.148 -1. An erroroccurredduringtheconnectionfromtheACMP ServertotheGraphAPI or duringtheevaluation ofthe GraphAPI response.237 +1. Ein von der GraphAPI gemeldeter Fehler wurde vom entsprechenden Webserver generiert. 238 +1. Es ist zu einem Fehler gekommen, der bei der Verbindung vom ACMP Server zur GraphAPI oder bei der Auswertung der Antwort der GraphAPI aufgetreten ist. 149 149 150 - Thefollowingaresomedetailederrormessagesthatmay appearonyoursystem:240 +Nachfolgend einige detaillierte Fehlermeldungen, die bei Ihnen erscheinen können: 151 151 152 - 153 153 |((( 154 -** Errormessage**243 +**Fehlermeldung ** 155 155 )))|((( 156 -** Error log**245 +**Fehlerbeschreibung ** 157 157 ))) 158 158 |((( 159 159 Die GraphAPI meldet einen Fehler und eine Fehlerbeschreibung. 160 160 )))|((( 161 - The ACMP Servercould reachthe Microsoft GraphAPIandreceived an error.250 +Der ACMP Server konnte die Microsoft GraphAPI erreichen und bekam einen Fehler gemeldet. 162 162 163 - The error descriptionscomefromMicrosoftandindicate thetypeoferrorreportedbythe Microsoft GraphAPI.252 +Die Fehlerbeschreibungen stammen von Microsoft und geben die Art des Fehlers wieder, die von der Microsoft GraphAPI gemeldet wurde. 164 164 ))) 165 165 |((( 166 166 „Could not connect to GraphAPI server.“ 167 167 )))|((( 168 - TheACMP Servercouldnot establish a connectiontotheMicrosoft GraphAPI.257 +Der ACMP Server konnte keine Verbindung zur Microsoft GraphAPI aufbauen. 169 169 170 -** Solution**:Checkifyouhavereleasedthe [[necessaryURLs>>doc:ACMP.68.ACMP installieren.Checkliste zur Installation.WebHome||anchor="HErforderlicheURLs"]] foryour environment.259 +**Lösung**: Überprüfen Sie, ob Sie die [[notwendigen URLs>>doc:ACMP.67.ACMP installieren.Checkliste zur Installation.WebHome||anchor="HErforderlicheURLs"]] für Ihre Umgebung freigegeben haben. 171 171 ))) 172 172 |((( 173 173 „GraphAPI webcall returned success but information could not be deserialized.“ 174 174 )))|((( 175 - The ACMP Serverwasabletoestablish a connectionandtheremotestationreporteda success(HTTPstatus 200),butthe deliveredresponsecouldnotbesuccessfullyevaluated.Itispossiblethattheformat isdifferentthanexpected.264 +Der ACMP Server konnte eine Verbindung aufbauen und die Gegenstelle meldete einen Erfolg (HTTP Status 200), allerdings konnte die gelieferte Antwort nicht erfolgreich ausgewertet werden. Hier kann es sein, dass das Format ein anderes ist, als erwartet. 176 176 177 - A possible sourceoferroris whenasystemretains information inthe cacheand returnsitasaresponse.For example,checkyourproxysettingsto seeifthe ACMP Serverhas storedthecorrectconfigurationsto resolvethe URL.Ifyouhave excludedthis,please contactour Support.266 +Mögliche Fehlerquelle ist, wenn ein System Informationen im Cache behält und diese als Antwort zurückliefert. Überprüfen Sie beispielsweise Ihre Proxyeinstellungen, ob der ACMP Server die richtigen Konfigurationen hinterlegt hat, um die URL auflösen zu können. Sollte das von Ihnen ausgeschlossen worden sein, wenden Sie sich bitte an unseren Support. 178 178 ))) 179 179 |((( 180 180 „GraphAPI webcall returned failure but error information could not be deserialized.“ 181 181 )))|((( 182 - The ACMP Serverwas abletoestablisha connectionsuccessfully,but theremote stationreports an error.Theresponsecouldnotbeevaluated271 +Der ACMP Server konnte erfolgreich eine Verbindung aufbauen, jedoch meldet die Gegenstelle einen Fehler. Die gelieferte Antwort konnte nicht ausgewertet werden. 183 183 184 -** Solution**:Check ifthe [[firewall/proxy settings>>doc:ACMP.68.ACMP installieren.Checkliste zur Installation.WebHome||anchor="HErforderlicheURLs"]]areconfigured correctlyorwhetheryouhave somethingelseinthe networkthat isinterceptingor blocking thecommunication.. If thishasbeenexcluded by you, pleasecontactourSupport.273 +**Lösung**: Überprüfen Sie, ob die[[ Firewall/Proxy Einstellungen>>doc:ACMP.67.ACMP installieren.Checkliste zur Installation.WebHome||anchor="HErforderlicheURLs"]] richtig konfiguriert sind. Sollte das von Ihnen ausgeschlossen worden sein, wenden Sie sich bitte an unseren Support. 185 185 ))) 186 186 |((( 187 187 „Thumbprint from public key could not be read.“ 188 188 )))|((( 189 - Thiserroronly occursifyouhave usedthecertificateasthe authenticationmethod.278 +Dieser Fehler tritt ausschließlich auf, wenn Sie als Authentifizierungsmethode das Zertifikat verwendet haben. 190 190 191 -In thiscase,the ACMP Servertries to generateaJSON Web Token forthe GraphAPI.Thefingerprintofthe certificate'spublic keymustbenoted.Anerroroccurred when readingthisvalue.280 +In diesem Fall versucht der ACMP Server einen JSON Web Token für die GraphAPI zu generieren. Hierbei muss der Fingerabdruck des öffentlichen Schlüssels des Zertifikats vermerkt werden. Beim Auslesen dieses Wertes trat ein Fehler auf. 192 192 193 -** Solution**:Whenthe erroroccurs, reinstallthecertificate.282 +**Lösung**: Spielen Sie beim Auftreten des Fehlers das Zertifikat neu ein. 194 194 ))) 195 195 |((( 196 196 „JSON Web Token generation for authentication with GraphAPI failed.“ 197 197 )))|((( 198 - Thiserroronly occursifyouhave usedthecertificateasthe authenticationmethod.287 +Dieser Fehler tritt ausschließlich auf, wenn Sie als Authentifizierungsmethode das Zertifikat verwendet haben. 199 199 200 - The ACMP ServertriestosignaJSON Web Token forthe GraphAPIwiththe certificate'sprivatekey.An erroroccurs.289 +Der ACMP Server versucht einen JSON Web Token für die GraphAPI mit dem privaten Schlüssel des Zertifikats zu signieren. Hierbei tritt ein Fehler auf. 201 201 202 -** Solution**:Thismaybeanexpiredcertificate.Eithercreateanewcertificateorre-importthecertificatewhenthe error occurs.291 +**Lösung**: Möglicherweise kann es sich um ein abgelaufenes Zertifikat handeln. Legen Sie entweder ein neues Zertifikat an oder spielen Sie beim Auftreten des Fehlers das Zertifikat erneut ein. 203 203 )))

