Adding Microsoft Entra ID Directory Service Connection

Before you begin

This process requires:

  • A Microsoft Azure account
  • Access to Microsoft Azure Portal
  • Authentication of SOTI MobiControl with your Microsoft Azure account.See Microsoft Azure documentation for more information.
  • Azure AD Join Cloud Enrollment listed in default applications

About this task

Follow this procedure to add a Microsoft Entra ID directory service connection in SOTI MobiControl.

Procedure

To begin, you must collect configuration information from Microsoft Azure Portal.
  1. Open the Microsoft Azure Portal (https://portal.azure.com).
  2. Select Microsoft Entra ID.
  3. In the Overview tab, copy the following details for later use:
    • Tenant ID
    • Primary Domain
  4. In the left-hand menu, select App Registrations.
    The App Registrations view opens.
  5. Select Endpoints.
    The Endpoints window opens.
  6. Copy the Federation Metadata Document URL.
Next, add the Azure tenant.
  1. From the SOTI MobiControl main menu, select Global Settings > Services > Directory.
    The Directory view opens.
    Directory View
  2. In the Microsoft Entra ID panel, select Add to add a tenant.
    The Microsoft Entra ID Connection window opens.
    Microsoft Entra ID Connection View
  3. Enter a short descriptive name for the connection.
  4. Enter Microsoft Graph API Address URL.
  5. In Microsoft Entra Tenant, select Add.
    The Microsoft Entra ID > Connection Details view appears.
    Microsoft Entra ID Connection Options
  6. Enter values for the following fields:
    Name A short descriptive name for the tenant.
    Primary Domain The primary domain copied from the Azure Portal.
    Microsoft Entra Tenant ID The tenant ID copied from the Azure Portal.
    Metadata Endpoint Address The federation metadata document URL copied from the Azure Portal.
    OIDC Metadata Endpoint Address (Optional) The OpenID Connect metadata endpoint in Azure, provided by Microsoft when you sign up for Azure AD.
  7. Select Save.
    The tenant is available for selection to complete the connection.
Complete the connection details.
  1. From Microsoft Entra Tenant, select the tenant name you just added.
  2. From Application Name, select Azure AD Join Cloud Enrollment.
  3. Select Save.
    The Microsoft Sign In dialog displays.
  4. Select Continue.

Results

The Microsoft Entra ID directory connection is now available in SOTI MobiControl.

What to do next

Proceed with the steps in Creating an Enrollment Policy for an Azure AD Join (Cloud) Enrollment Type.