Zum Inhalt springen
Bpanda-Hilfe
English
Esc
navigierenöffnen⌘Jvorschau
Auf dieser Seite

Microsoft Entra ID

To use Microsoft Azure Entra ID as your identity provider, you first have to add our Bpanda Enterprise App in your Azure tenant and then configure it.

Setting up Microsoft Entra ID as an identity provider

To use Microsoft Azure Entra ID as your identity provider, you first have to add our Bpanda Enterprise App in your Azure tenant and then configure it.

[!IMPORTANT] Prerequisite: You need Global Administrator rights in your Azure tenant to add the app.

Proceed as follows:

1. Add the Bpanda Enterprise App

📷 [Insert screenshot: Adding the Bpanda Enterprise App in the Azure tenant]

⚠️ Important: Only an Azure tenant administrator can add the app. After clicking “Sign up for Bpanda”, this admin must confirm or grant admin consent for Bpanda. In doing so, you confirm to MID GmbH and Microsoft that they may receive and process the user data from Microsoft.

Note: Once the app has been added successfully, you are redirected straight to the Bpanda page – at this point, you CANNOT log in yet!

For this to work, users and groups first have to be synchronized to us. To do so, you need to set up provisioning for the Bpanda Enterprise Azure App.

2. Set up provisioning

📷 [Insert screenshot: Provisioning the app]

  1. In the app’s provisioning settings, switch to “Automatic” and, in the next step, enter the Tenant URL and the Secret Token.
  2. Then click “Test Connection”.

📷 [Insert screenshot: Tenant URL, Secret Token and Test Connection]

3. Select users and groups

Once the connection is working, you can select the users and groups to be synchronized under “Users and Groups”.

You are welcome to create and provide the following groups in your AD:

Group name in Entra ID Function in Bpanda
Bpanda-Account-Manager Manages the users and groups in the CAMP account management
Bpanda-BPM-Manager The manager of the Process Space; can adjust all settings relating to the Process Space, manage processes, set process maps and process hierarchies, and manage organizational structures and applications. Has access to all levels and processes.
Bpanda-User A participant in the Process Space; can access processes, take part in reviews and use collaboration features such as Q&A.
Bpanda-Process-Designer In addition to the rights of a Bpanda user, can create processes, initiate reviews and change process content.
Bpanda-Consumer A participant in the Process Space with read-only rights

4. Start provisioning and assign licenses

✅ Afterwards, please make sure that provisioning has actually been started.

Once the users have been synchronized to us successfully, we have to take action once more to assign the licenses in Bpanda’s CAMP before logging in to the product will work.

Synchronization sequence: Entra ID → every 40 minutes → Keycloak → once per night → CAMP

Since synchronization from Entra ID to us in Keycloak only happens every 40 minutes, and from Keycloak to CAMP only once per night, please let us know so that we can trigger the latter manually.
After that, it is possible at any time.

War diese Seite hilfreich?