Conga Product Documentation

Welcome to the new doc site. Some of your old bookmarks will no longer work. Please use the search bar to find your desired topic.

Show Page Sections

Entra ID Authentication

The authentication mode between CPQ and MSCRM is managed via Entra ID. If one instance of Entra ID supports the MSCRM instance associated with CPQ, CPQ can be declared as an app in this Entra ID. By doing so, Entra ID will provide a security token when requested to guarantee the safety of every sync process between CPQ and MSCRM.

Workflow

The following diagrams show the protocol involving CPQ, MSCRM and Entra ID and managing the authentication between the two environments:

QUOTE CREATION



SYNC BACK TO THE CRM



Integrating your Identity Provider with Application Portal

The authentication with Dynamics 365 relies on standard S2S OAuth2.0. It is made possible via an integration with the PROS Application Portal.

The following page details the different ways PROS currently provides to connect to the PROS Application Portal: Integrating with PROS Application Portal.

The PROS Application Portal supports integration with external identity providers such as Entra ID, or any SAML-Based Identity Provider.

Entra ID Authentication

The architecture supporting the integration of CPQ with MSCRM leverages Entra ID to manage the authentication between the two systems.

If one instance of Entra ID supports the MSCRM instance associated with CPQ, CPQ can be declared as an app in this Entra ID. By doing so, Entra ID will provide a security token when requested to guarantee the safety of every sync process between CPQ and MSCRM.

The setup of the authentication requires actions both in the Entra ID and in CPQ managed solution for MSCRM.

PROS Home Documentation

The documentation on the PROS Home specific to the Entra ID integration is available on Connect: Integrate PROS Home and Entra ID

Microsoft Documentation

The step-by-step procedure below highly depends on Microsoft Entra ID, which is outside of PROS control. It may thus happen that the MS Entra ID interface evolves without noticing PROS and that it differs form the below screenshots. If that occur, please contact you Microsoft Premier Support Engineer for assistance in the corresponding actions or steps.

REGISTER SMART CPQ APP IN ENTRA ID

To start the AAD setup, first go on the Entra ID portal and access Entra ID:



In the left menu, click on "App Registration" and then on "New Registration":



Name the new registration "Smart CPQ" and choose the option "Account in any organizational directory":



The outcome of the operation are the Application ID and Tenant ID that you may reuse for the overall setup.



GRANT API PERMISSION

In the left menu, access the "API Permissions" section



Click on "Add a permission" and choose "Dynamics CRM"



Choose "user_impersonation" and click on "Add permissions"



Click on "Grant Admin consent for PROS"



The user of your organization now have permissions on CRM APIs.

Error

If you forget this step , you will most likely face the following error:

ADAL error occurred: AADSTS65001: The user or administrator has not consented to use the application with ID 'XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX' named 'PROS SmartCPQ'. Send an interactive authorization request for this user and resource.

REPLY URI

Click on "Manifest" in the left menu



Scroll down to find the tag "replyUrlwithType" and update it as follows,

{"url":"https://yourinstance.crm.dynamics.com/WebResources/pros_/HTML/connectFram e.html,"type":"Web"}

As an alternative, you can include a wildcard '*'

{"url":"https://yourinstance.crm.dynamics.com/*,"type":"Web"}



Click on Save.

Click on "Token Configuration" in the left menu. The reply URI is displayed:



Scroll down to the section "Implicit Grant" and select both options "Access tokens" and "ID Tokens"



Click on Save.

MIGRATE FROM ADAL TO MSAL

Microsoft has deprecated the ADAL library and recommends to migrate to the new MSAL library for the authentication management. This new configuration works with the library ADAL (managed package 2.7.0.2) and MSAL (managed package 3.0.0 and after).

Based on the setup described in this page, follow these steps to do the migration:

  1. In App Registration, open your App:

  2. Click on Redirect Uris:

  3. Click on the link “This app has been ..”:

  4. Select the Redirect URIs for the Single Page Application, click on Configure:

  5. It’s now defined for a Single Page Application:

  6. Check that the authentication is working fine and then delete the Web Redirect URIs:

PROS CPQ Managed Solution

Setup PROS Custom Settings in MSCRM and run the workflow

  • Store the application Client ID and Tenant ID in the CRM PROS Custom Setting entity
  • When a call to CPQ is made
    • These settings are sent to AAD requesting for a security token
    • A token is returned by AAD and stored in MSCRM for future calls
    • The token is sent as part of each call to CPQ
  • When CPQ sync back with the CRM
    • This token is used to authenticate
      • Either an exchange of data (XML+PDFs) or a use of the Web API is leveraged to fire the MSCRM custom workflow responsible for the CRM update

        Entra ID Token Timeout

        By default, Entra ID associates an inactivity timeout to the authentication token used by CPQ. Which means that CPQ must interact with Entra ID, at least periodically, to prevent hitting the token timeout.

        As soon as the user is authenticated in Entra ID when opening CPQ, the timer starts. While in CPQ, no end-user action can reset this timeout, except when syncing back to the CRM. For the end user, this implies that:

        • a sync back must be performed at least every X minutes (check the limit defined in your Entra ID instance)
        • that the sync back will not work after those X minutes timeout. Note that no data will be lost in CPQ in that scenario but the end user will have to open CPQ again from the CRM to reset the timeout prior to being able to perform a sync back.

Double Authentication

The PROS Managed solution for MS Dynamics supports the double authentication via Entra ID.