Azure Active Directory
You can sync Azure Active Directory with Infraon to enable synchronization of user/requester accounts. Follow the below steps to configure Azure Active Directory.
Pre-requisites
An active Azure account
The Process
Follow the below steps on your Azure portal.
Step 1: Register your app
1. Log in to your Azure account and click 'App Registrations.'

2. Select 'New registration.'

3. Add a display name for your application, select the account type, and click 'Register.'

4. The application is created, and the details are displayed per the reference screenshot. Copy the Application and Tenant ID.

Step 2: Enable API Permissions
1. Navigate to ' API Permissions' and click 'Add a permission.'

2. A slider appears. Click on the 'APIs my organization uses' tab.

3. Select 'Microsoft Graph' from the list of APIs displayed.

4. Scroll down and look for 'User' related APIs. Expand and select 'User. Read.All' to enable.

5. Once the permissions are added, details are displayed per the reference.

6. Click on 'Grand Admin Consent' and confirm your selection.


Step 3: Create a client secret
1. Navigate to 'Certificates and secrets' -> Client Secrets.

2. Add a new client secret. Provide a description and an expiration date. The client secret is valid only for the selected period. A new client must be created on the expiry of this. Click 'Add' once done.

3. The client secret is generated. Copy the value to the clipboard. Please note that this value will be hidden on page refresh.

Step 4: Register your app on Infraon.
1. Navigate to Infraon -> Market Place -> Azure Active Directory (Azure AD). Click 'Install'. Add the 'Talent ID, Client ID, and Secret Key. Click 'Verify.'

2. Per the reference screenshot, you will be redirected to the field mapping screen upon successful verification. In the tabs below on Infraon, select column names to the respective field names.
Requester
Work
Address

3. Click 'Submit' when you are done. Infraon might take a few minutes to complete the synchronization. Once complete, all your Azure users are added as requesters on Infraon.
How to Install
Step 1: Go to the Marketplace tab from the left navigation panel. Under the available integrations, locate and select the Azure AD card to open the integration details page.
Step 2: On the Azure AD plugin details page, click Install to add the integration to your Infraon environment.
After successful installation, the Azure AD configuration page becomes available for further setup and verification.
Step 3: Enter the required Azure AD configuration details to establish communication between Infraon Infinity and Microsoft Azure Active Directory.
These details are used to authenticate the integration, synchronize requester information, and enable requester login through Azure AD Single Sign-On (SSO).
Config Name
Enter configuration name
Specify a unique name for the Azure AD integration configuration.Example: Infraon - Azure AD Directory
Tenant ID
Enter Azure AD Tenant ID
Specify the Tenant ID generated from the Microsoft Azure portal for the registered application. This is used to identify the Azure AD directory instance.
Client ID
Enter Client/Application ID
Provide the Client ID associated with the registered Azure AD application created for Infraon integration.
Secret Key
Enter client secret value
Specify the Secret Key generated for the Azure AD application. This key is used for secure authentication between Infraon Infinity and Azure AD services.
SSO Unique Key
Select a unique requester attribute
Select the unique attribute used to identify and authenticate synchronized users during SSO login.Example: Email
Sync
Select synchronization type
Choose the object type to synchronize from Azure AD into Infraon Infinity. Example: Requester
Allow Requester Login
Enable requester SSO login
Enable this option to allow synchronized requesters to log in to the Infraon Self-Service Portal using Azure AD credentials.
Verify
Validate Azure AD configuration
Verifies the entered Tenant ID, Client ID, and Secret Key by testing the connection with Azure AD before proceeding with synchronization.
Once the configuration details are added, use Verify to validate the Azure AD connection and continue with the integration setup.
Step 4: After verifying the Azure AD connection, navigate to the Login Settings tab to configure the user attribute used for requester authentication and login mapping.
The Login Settings section allows administrators to define the Azure AD attribute that Infraon Infinity should use as the requester's username during authentication and synchronization.
Username
Select the Azure AD user attribute
Select the Azure AD attribute that should be mapped as the requester login username in Infraon Infinity. Commonly used attributes include mail, userPrincipalName, or other Azure AD user properties. Example: mail
Attribute Search
Search and select attribute
Use the dropdown search to browse and select available Azure AD attributes retrieved from the connected directory instance.
Login Mapping
Configure requester authentication mapping
Maps the selected Azure AD attribute with Infraon requester accounts to support SSO authentication and requester identification during login.
Select Next to save the configured Login Settings and proceed to the next step of the Azure AD integration setup.
Step 5: After configuring the Login Settings, navigate to the Requester tab to map Azure AD user attributes with requester fields available in Infraon Infinity.
This section allows administrators to define how requester information from Azure AD should be synchronized into the Infraon platform. The selected Azure AD attributes are previewed automatically to help validate the mapping configuration before synchronization.
Full Name
Select Azure AD attribute
Maps the requester's full name field in Infraon Infinity with the corresponding Azure AD user attribute.
Select Azure AD attribute
Maps the requester email address from Azure AD. This field is commonly mapped using attributes such as mail or userPrincipalName.
Phone Number
Select Azure AD attribute
Maps the requester's mobile or contact number from Azure AD user details.
Landline
Select Azure AD attribute
Maps the requester's landline or office contact number from Azure AD.
Tags
Select Azure AD attribute
Maps Azure AD attributes that can be used as requester tags or classification values within Infraon Infinity.
Reporting Manager
Select Azure AD attribute
Maps the reporting manager or supervisor information from Azure AD user records.
Azure AD Details
View available Azure AD attributes
Displays the list of available Azure AD user attributes retrieved from the connected tenant for field mapping.
Preview Data
View synchronized sample data
Displays preview values from the selected Azure AD user attribute to validate mapping accuracy before synchronization.
Change User
Load another Azure AD user preview
Allows administrators to switch the preview user used to validate field mappings against a different Azure AD account.
The Work and Address sections follow the same field mapping process as the Requester configuration. Administrators can map Azure AD attributes to the corresponding Infraon Infinity work and location fields and use the preview data section to validate the synchronized values before proceeding.
Once the required mappings are completed, select Submit to save the configuration.
The Azure AD integration is now installed.
Settings
The Settings page allows administrators to manage the Azure AD integration, synchronize user data, update configuration settings, schedule automatic sync jobs, and export unsynchronized records for troubleshooting and validation.
Sync Data
Sync Now
Initiates an immediate synchronization between Azure AD and Infraon Infinity to fetch and update the latest requester and user details. The section also displays synchronization statistics, including Total Data Synced, Failed During Data Sync, and Last Synced Time, to monitor synchronization activity.
AD - Infraon Configuration
Configuration
Opens the Azure AD integration configuration settings page to modify or update mapped fields, authentication details, requester synchronization settings, login settings, and other Azure AD integration configurations.
Schedule Sync
Schedule
Configures automatic synchronization schedules between Azure AD and Infraon Infinity.
Export Unsync Data
Export
Downloads a CSV file containing records that were not synchronized successfully from Azure AD.
Requester Login via SSO
Azure AD–synced requesters can log in to the Infraon Self-Service Portal using Microsoft Single Sign-On (SSO). Authentication and access management for requesters occur when a ticket is created under any workflow configured with App Integration.
It includes scenarios such as:
Successful login via SSO
Invalid login attempts
Session management
Multi-device login
Error handling
Audit logging
How It Works
1. Navigate to Infraon Configuration → Infraon Automation → Workflow.
2. Select the required Ticket Workflow and click Edit.
3. In the Configure Workflow section, expand the left-side panel using the double arrow icon.

4. Under the Actions category, select App Integration.

5. Select the Azure AD app (installed from Infraon Marketplace Integration) from the dropdown.

6. Once selected, you will see three options to configure Azure AD account actions.

Azure AD Actions | Details
Label
Description
Scenario
Force Password Reset on Next Login
Triggers a temporary password reset and forces the requester to set a new password during their next login via SSO. An email with the temporary password is sent.
Use when the requester’s credentials may be compromised, or after IT security updates, ensuring the user resets their password before continuing access.
Unlock User Account
Unlocks a requester’s locked account due to multiple failed login attempts or admin restrictions. No email notification is sent.
Use it when a requester is unable to access the portal due to lockout errors. This ensures quick access restoration without requiring manual IT intervention.
Disable (Lock) User Account
Disables a requester’s account, preventing login until re-enabled. No email notification is sent.
Use when an account needs to be temporarily restricted—e.g., requester leaves the organization, suspicious activity is detected, or compliance rules require suspension.
This ensures IT admins can automate user account management actions within ticket workflows, integrating Azure AD SSO policies directly into Infraon Infinity Automation.
Last updated
Was this helpful?