How to configure SESAR with Azure Active Directory?

How do I configure SESAR with Azure Active Directory?

This procedure explains how to connect SESAR to your Azure Active Directory so that Secure Exchanges can read your groups and automatically assign licences to your users. You first create an application in Azure, note its identifiers, then enter them in the configuration of your SESAR instance.

Step 1: Create the application in Azure Active Directory

  1. Go to Azure Active Directory.
  2. In the left-hand bar, click "App registration", then "New registration".


  3. Enter a name, then, under "Supported account types", select the first option, "Single tenant".


  4. Click the "Register" button at the bottom left of the screen.

The application allows Secure Exchanges to connect to your Active Directory in order to access its various groups.

Step 2: Create the secret and note the application identifiers

  1. Go back to "App registration" and click the new application with the name you entered earlier.
  2. Click the link to the right of "Add a certificate or secret", then "New client secret".




  3. Enter a short description of the secret, for example "Secret for Secure Exchanges", and select the expiry date that suits you.
  4. Click the "Add" button to create the secret.
  5. Note the "value" of this secret, as it will no longer be accessible afterwards.
  6. Return to your application and note the client identifier (Application (client) ID) and the tenant identifier (Directory (tenant) ID).

Note: You must renew the secret each time it expires. We recommend selecting 12 months.
Note: Do not worry, if you ever lose the value of this secret, you can create another one.

You now have all the information Secure Exchanges needs to connect to your Azure Active Directory (ClientId, tenantId and the secret).

Step 3: Assign the Microsoft Graph permissions

To allow Secure Exchanges to connect to your Azure Active Directory, the permissions must be changed.

  1. In the left-hand tab, click "API permissions", then "Add a permission".
  2. In the right-hand tab, select the first option, "Microsoft Graph".


  3. Click the "Application permissions" button on the right.
  4. Add these four permissions: "Group.Read.All", "GroupMember.Read.All", "MailboxSettings.Read" and "User.Read.All". You can find them easily using the search tab.
  5. Once all the permissions are selected, click "Add permissions" at the bottom left.

Warning: You must obtain administrator consent (admin consent) for all these permissions, as they are application permissions.

You should obtain the following result:


Step 4: Create the licence groups

The last thing left to do on the Azure side is to create the groups that will be used to manage users.

  1. In the left-hand tab, click "Groups", then "New group".
  2. We suggest using "SecureExchanges_Licences" as the group name.


  3. Then create the following 7 subgroups inside the parent group (SecureExchanges_Licences): "Advanced", "Eco", "No_Licence", "Pro", "DEBASE-P", "COMPLET-P" and "COMPLET2100-P".
Note: You can use whatever parent group name you want, you only need to enter the same group name in the SESAR configuration.
Warning: It is important that the subgroups have exactly these names.

You should obtain the following result in the "SecureExchanges_Licences" group:


Step 5: Configure SESAR

With the information noted earlier, that is the Application (client) ID, the Directory (tenant) ID and the Secret, you can now modify the configuration of your SESAR to support AAD (Azure Active Directory).

  1. Add the following three new fields in your SESAR instance: AzureAD_Client, AzureAD_Tenant and AzureAD_Secret, then associate the values with the right fields (AzureAD_Client="Your Application (client) ID", etc.).


  2. In the AppSettings section, add the AzureAD_GroupName key and enter the name of the parent group you created in step 4.

Warning: If you have to update SESAR and delete your existing SESAR.config file, you will need to enter your API keys, your Serial, your User and all the other instance information again.
Note: The name you enter must be exactly the name you gave your parent group in Azure AD.

You have now configured your SESAR to support AAD.

Step 6: Manage users and their licences

Once your SESAR is configured, you can manage the users of your organization in Azure. To do so, you only need to place the users in one of the following four subgroups:

  • Eco
  • Advanced
  • Pro
  • No_Licence

For shared licences, you must create the following groups:

  • DEBASE-P (shared Eco)
  • COMPLET-P (shared Advanced)
  • COMPLET2100-P (shared Pro)

Example: if you place a user in the Pro group, that user is assigned a Pro licence at the next synchronization. The same applies to the Eco and Advanced groups.

Example 2: a user holding a Pro licence who is moved to the Eco group will have their licence changed.

Note: Synchronization with Azure takes place every 5 minutes.
Warning: For licences to be assigned to users, they must have been purchased and provisioned in Secure Exchanges beforehand.

If you want to remove a licence from a user, you must place that user in the No_Licence group.

Warning: If you place a user in "No_Licence", their event logs are permanently deleted.
Warning: If you want to permanently delete a user, you must delete them directly in the Secure Exchanges web portal.

Step 7: Grant the user management rights

As a last step, you must give a user the rights to add and modify users.

  1. Log in to the Secure Exchanges online portal. If you need help, see Log in to the Secure Exchanges online portal.
  2. In the left-hand menu, under the Organization section, click Roles and permissions.


  3. Click Add a new group role.
  4. Give the group the name "Azure-AD", then click "Save".


  5. Locate the group concerned in the table.
  6. Click the Edit button, at the bottom right of the group card.


  7. Turn on the "User management" switch.

  8. In the role group card, click the button showing "(x) users".


  9. Select the user of the SESAR licence.
  10. Save your changes.

Troubleshooting

If an error occurs with the SESAR synchronization, an email is sent to the administrator of your organization.

Example: if you do not have enough licences, or if a user has a domain name that is not validated in your organization, you receive an email to that effect.

Need help?

Our team is available to assist you. Write to us at support@secure-exchanges.com