Bentley Communities
Bentley Communities
  • Site
  • User
  • Site
  • Search
  • User
Licensing, Cloud and Web Services
  • Welcome to Bentley Communities
  • Bentley's Communities
  • Licensing, Cloud and Web Services
  • More
  • Cancel
Licensing, Cloud and Web Services
Licensing, Cloud and Web Services Wiki Microsoft Azure AD configuration for OIDC
    • Sign in
    • Eastern Europe Continuity Plan
    • Guest Accounts - Review Access
    • +Web Services
    • +SES Activation
    • +CONNECTION Client
    • +CONNECT Advisor
    • -Federated Identity
      • Microsoft Azure AD configuration for OIDC
      • Open ID Connect / OAuth Federation Specifications
      • Microsoft Azure AD configuration for SAML 2.0
      • Microsoft ADFS Configuration for SAML 2.0
      • SAML 2.0 Configuration Specifications
      • +Microsoft Azure AD Automatic User Provisioning Configuration
      • +IMS Help and Troubleshooting
    • +SELECTserver based Activation
    • +Pre-SELECTserver Based Activation
    • +Product-Specific Licensing
    • Understanding why you received a TL Invoice
    • Working from Home using Bentley Licensing
    • +Licensing Workflow
    • How to leave a Product Review
    • +Serviços ProjectWise 365
    • About Bentley Trust Licensing
    • How to delete Bentley account and all related data
    • Support for non-Bentley technologies utilized by Bentley products
    • Support for V8i SELECTseries 10 applications after December 31st, 2021
    • +Support Homepage - Localized

    You are currently reviewing an older revision of this page.

    • History View current version

    Microsoft Azure AD configuration for OIDC

    Introduction

    This guide provides instructions for setting up Single Sign-on between Microsoft Azure AD and Bentley's Identity Management System (IMS), for your corporate users.

    This guide assumes that your Azure AD tenant is properly set up on a SSL /TLS endpoint using HTTPS, and that the authentication address is accessible by your corporate users.

     

     

    Create the Application in Azure AD

    Note: The interface for Azure changed in early 2019, so your Azure interface may look different than the screenshots depicted below. 

    • Open your Azure AD portal (https://portal.azure.com/) and login with administrative privileges
    • Select “Azure Active Directory” from the left navigation, if not already selected.
    • Choose “App Registrations”

    • Click on “New Registration”

    • Name it “Bentley IMS”, select “Accounts in this organizational directory only”, and no Redirect URI for now, click register –

    Setting up your ID Token 

    • Click “Token Configuration” on the left-hand side –

    • From here, we’re going to hit “Add Optional Claim” –

    • Select the “ID” Token Type –

    • A list of claims to add will pop up. Select: ctry, email, family_name, given_name, and upn. Then hit Add –

    • A warning box will pop asking if you should turn on the Microsoft Graph, hit the checkbox and hit Add again –

    Setting up your Client Secret

    • Select the “Certificates & Secrets” option on the left-hand menu

    • Select “New Client Secret”

    • Name it “Bentley Secret” and select an expiration length, hit add –

    Communities
    • Home
    • Getting Started
    • Community Central
    • Products
    • Support
    • Secure File Upload
    • Feedback
    Support and Services
    • Home
    • Product Support
    • Downloads
    • Subscription Services Portal
    Training and Learning
    • Home
    • About Bentley Institute
    • My Learning History
    • Reference Books
    Social Media
    •    LinkedIn
    •    Facebook
    •    Twitter
    •    YouTube
    •    RSS Feed
    •    Email

    © 2021 Bentley Systems, Incorporated  |  Contact Us  |  Privacy |  Terms of Use  |  Cookies