Integrate Entra ID
Introduction
These instructions describe the steps necessary to integrate the Application Portal with your instance of Microsoft's Entra ID using OAuth 2.0 and OpenID Connect protocols. This guide is for the integration with Entra ID via the Microsoft Identity Platform 2.0. Refer to Evolution of Microsoft Identity Platfor for further details from Microsoft.
Please note that Entra ID exists only within the Microsoft cloud; it is compatible with on-premise Active Directory instances, but these are separate software deployments.
Prerequisites
ENTRA ID
This document assumes that your Entra ID instance is already generally available, able to service logins for your users, and that it simply needs additional configuration to integrate with the Application Portal. It is important to note that the Application Portal only supports SP-Initiated single sign-on.
Creating an Entra ID instance and configuring it to synchronize with or federate to your on-premise identity management systems (e.g. traditional Active Directory) is not within the scope of this document. See Microsoft's site for general information on Entra ID.
The Free tier is supported but not recommended since it does not provide any SLA guarantees (see Microsoft Entra Plans and Pricing). Basic and Premium tiers are recommended.
ENTRA ID ADMINISTRATOR ACCESS
The integration procedure requires involvement from an existing, authorized user within your Entra ID instance that has the necessary administrative permissions to add and configure applications within the directory.
CONGA LOGIN ADMINISTRATOR SECURITY GROUP
As a part of setting up the Application Portal to integrate with your Entra ID instance, the portal requires at least one AD security group to represent those users who shall be granted administrative rights to the Application Portal. The selected security group(s) may already exist and need not be specific to Conga, if for instance you have an existing group that represents its security/domain administrators; however, some organizations may wish to create a separate security group specific to the Conga integration.
This document does not cover how to create a new group or how to add a user to such a group. These actions are performed either directly in Entra ID or in your on-premise Active Directory instance (or other back-end user management system).
To ensure that the user performing the initial configuration has and retains access to administrative functions within the portal, the user must select the administrative group(s) from one or more of his/her own group memberships. This means that the initial configuration user must already be an existing member of at least one of the desired administrator security groups.
Register the Application Portal in the Entra ID
DIRECTORY DOMAIN NAME
All Entra ID directories come with a default domain, specified at the time that the directory was created. This domain is globally unique. You also have the option of adding custom domains to their directory, for Internet domain names that they control. For example, Conga has the option to configure its own directory with the custom pros.com domain. Custom domains are supported when their status shows up as verified in Entra ID, but a custom domain is not required; either kind will work with the Application Portal.
Choose a custom domain if one has already been configured for the directory, or use the default domain. To locate the default domain name, navigate to the Entra ID configuration screen within the Entra ID portal and click on the Custom domain names tab. Please record the fully qualified domain name as shown, with all parts of the domain including the period separators; however, do not include a period at the very end.
ADD AN APPLICATION
At this time, a private integration will be configured between Entra ID and the Application Portal rather than causing the Conga portal to display in the Entra ID Marketplace for all Entra ID users.
- Navigate to the Entra ID tab within the Entra ID portal, then select the App registrations.
- Click the New registration button in the top toolbar.
- Enter a name for the application, for example: Conga Cloud Production
- Click Register to create the new application.
Instead of naming the domain application based on the product purchased from Conga, or an internal project or code name, consider using a more general name such as the example above. the Application Portal integration only needs to be performed once per deployment realm even if additional products are purchased later, so choose a name that will make sense long into the future.
This process may be repeated if integrating with multiple deployment realms; for example: the US1 production realm and the US1 preview realm for user acceptance or other testing. For security reasons, each realm has a separate and independent application portal.
The remainder of these instructions will refer to the Application Portal URLs from the table below. Substitute or adjust the values for the appropriate realm. Please contact Conga if you do not know your assigned the Application Portal and realm.
| CONGA CLOUD REALM | APPLICATION PORTAL URL |
|---|---|
| AU REALM 1 | https://login.au1s1.congacloud.com |
| EU1 | https://login.eu1s1.congacloud.com |
| EU Preview | https://login.eu0s1.congacloud.com |
| US REALM 1 | https://login.us1s1.congacloud.com |
| US Preview | https://login.us0s1.congacloud.com |
| E1 EU1 | https://login.eu1s2.congacloud.com |
| US REALM 2 | https://login.us1s2.congacloud.com |
CONFIGURE THE NEW APPLICATION
Once the application has been created, perform the following configuration steps within the application in the Entra ID portal:
- Under Manage, click Authentication.
- In the section labeled Platform configurations, click Add a platform.
- Click Web to create a web application.
- In the section labeled Redirect URIs, append the following path the Application Portal URL from the table below exactly: /x/azure-ad/reply
Ex:
https://login.us1s1.congacloud.com/x/azure-ad/replyCONGA CLOUD REALM APPLICATION PORTAL URL AU REALM 1 https://login.au1s1.congacloud.com/x/azure-ad/reply EU1 https://login.eu1s1.congacloud.com/x/azure-ad/reply EU Preview https://login.eu0s1.congacloud.com/x/azure-ad/reply US REALM 1 https://login.us1s1.congacloud.com/x/azure-ad/reply US Preview https://login.us0s1.congacloud.com/x/azure-ad/reply E1 EU1 https://login.eu1s2.congacloud.com/x/azure-ad/reply US REALM 2 https://login.us1s2.congacloud.com/x/azure-ad/reply - In the section labeled Logout URL, append the following path to the Application Portal URL from the table below exactly: /x/azure-ad/signout
Ex:
https://login.us1s1.congacloud.com/x/azure-ad/signoutCONGA CLOUD REALM APPLICATION PORTAL URL AU REALM 1 https://login.au1s1.congacloud.com/x/azure-ad/signout EU1 https://login.eu1s1.congacloud.com/x/azure-ad/signout EU Preview https://login.eu0s1.congacloud.com/x/azure-ad/signout US REALM 1 https://login.us1s1.congacloud.com/x/azure-ad/signout US Preview https://login.us0s1.congacloud.com/x/azure-ad/signout E1 EU1 https://login.eu1s2.congacloud.com/x/azure-ad/signout US REALM 2 https://login.us1s2.congacloud.com/x/azure-ad/signout - Click the Save button in the top toolbar when finished.
The next step is to set some required API permissions for the application.
- Under Manage, click API permissions.
- Click the Add a permission button and select Microsoft Graph.
- Click Delegated permissions.
- Scroll and click on the User section. Make sure User.Read permission is checked.
- Scroll and click on the Group section. Make sure Group.Read.All permission is checked.
- Scroll and click on the OpenId permissions section. Make sure profile is checked.
- Click Application permissions.
- Scroll and click on the Group section. Make sure Group.Read.All permission is checked.
- Click the Add permissions button to set the permissions.
- Click the Grant admin consent button and click Yes to complete setting up the necessary permissions.
Allow the Application Portal to view each user's security group (and, optionally, distribution list) assignments, along with the signing in user's given name. the Application Portal supports assigning access and user roles based on groups already present within your directory; this allows directory administrators to manage user authorization through their existing, centralized processes. CONGA application roles can be assigned based on Active Directory security groups; group support can be expanded to also include email distribution lists as an option, depending on your organization's preferences. In the following steps, the "Security groups" setting limits the available groups to security groups only. To use both security groups and distribution lists, use the "All groups" setting. There is currently no option to use only distribution lists.
Follow the steps below to configure the necessary setting:
- Under Manage, click Token configuration.
- Click Add groups claim and then select Security groups.
- Click Add optional claim and select given_name under ID.
- Click Add optional claim and select email under ID. This will be used by certain CONGA applications to send out email alerts and notifications.
- Save your changes.
CAPTURE THE APPLICATION ID AND GENERATE A SECRET
In order for the Application Portal to securely communicate with your Entra ID instance, the portal requires an application ID and a secret key. You will configure these settings in the Application Portal later, but first the values must be retrieved from Entra ID. Perform the following configuration steps within the application in the Entra ID portal.
- Click Overview.
- Select the entire contents of the Application ID and record it somewhere safe.
- Under Manage, click Certificates & secrets.
- See the Client secrets section. By default, this section is empty. Otherwise, if you previously generated a secret and still have a copy of the key value, then it can be used as long as it is still valid according to its Expires date. If there are no secrets listed, or you do not have a copy of any existing secret values, then you will need to create a new secret; proceed to step 5.
- To create a new secret, click the New client secret button. Select a key validity duration from the options. Entra ID currently offers keys in one(1) - or two(2)-year duration or never expires; generated secrets will begin their validity from the current date. After selecting a duration, click the Add button to generate the secret.
- When the add operation completes, the page will update and display the new secret value. Select the entire secret value and record it somewhere safe along with the expiry date. It is important that the key be recorded exactly, as a single mistake will render the value unusable. As noted in the Entra ID portal interface, once you navigate away from this page or perform other operations, the key will be hidden and you will not be able to retrieve it again.
You're finished configuring the Application Portal on Entra ID. The next step is to set the application ID and secret in the Application Portal.
Configure the Application Portal
The next step is to setup the Application Portal with the details from your Identity Provider. You may have already received an e-mail invite that provides you access to the CONGA Platform, in which case you can refer back to the guide in order to complete the integration steps in the Application Portal.
If you've received a setup link from your CONGA implementation specialist, proceed to the steps documented in the following guide: Integrate the First Identity Provider.
If you're lacking an e-mail invite or setup link, contact Conga Support for assistance.
Test Integration
Please follow the steps documented in the following guide: Test IdP Integration
