For the complete documentation index, see llms.txt. This page is also available as Markdown.

Azure Active Directory

You can sync Azure Active Directory with Infraon to enable synchronization of user/requester accounts. Follow the below steps to configure Azure Active Directory.

Pre-requisites

  • An active Azure account

The Process

Follow the below steps on your Azure portal.

Step 1: Register your app

1. Log in to your Azure account and click 'App Registrations.'

2. Select 'New registration.'

3. Add a display name for your application, select the account type, and click 'Register.'

4. The application is created, and the details are displayed per the reference screenshot. Copy the Application and Tenant ID.

Step 2: Enable API Permissions

1. Navigate to ' API Permissions' and click 'Add a permission.'

2. A slider appears. Click on the 'APIs my organization uses' tab.

3. Select 'Microsoft Graph' from the list of APIs displayed.

4. Scroll down and look for 'User' related APIs. Expand and select 'User. Read.All' to enable.

5. Once the permissions are added, details are displayed per the reference.

6. Click on 'Grand Admin Consent' and confirm your selection.

Step 3: Create a client secret

1. Navigate to 'Certificates and secrets' -> Client Secrets.

2. Add a new client secret. Provide a description and an expiration date. The client secret is valid only for the selected period. A new client must be created on the expiry of this. Click 'Add' once done.

etCache\Content.MSO\84ABFF3F.tmp

3. The client secret is generated. Copy the value to the clipboard. Please note that this value will be hidden on page refresh.

Step 4: Register your app on Infraon.

1. Navigate to Infraon -> Market Place -> Azure Active Directory (Azure AD). Click 'Install'. Add the 'Talent ID, Client ID, and Secret Key. Click 'Verify.'

2. Per the reference screenshot, you will be redirected to the field mapping screen upon successful verification. In the tabs below on Infraon, select column names to the respective field names.

  • Requester

  • Work

  • Address

3. Click 'Submit' when you are done. Infraon might take a few minutes to complete the synchronization. Once complete, all your Azure users are added as requesters on Infraon.

How to Install

Step 1: Go to the Marketplace tab from the left navigation panel. Under the available integrations, locate and select the Azure AD card to open the integration details page.

Step 2: On the Azure AD plugin details page, click Install to add the integration to your Infraon environment.

After successful installation, the Azure AD configuration page becomes available for further setup and verification.

Step 3: Enter the required Azure AD configuration details to establish communication between Infraon Infinity and Microsoft Azure Active Directory.

These details are used to authenticate the integration, synchronize requester information, and enable requester login through Azure AD Single Sign-On (SSO).

Label
Action
Description / Example

Config Name

Enter configuration name

Specify a unique name for the Azure AD integration configuration.Example: Infraon - Azure AD Directory

Tenant ID

Enter Azure AD Tenant ID

Specify the Tenant ID generated from the Microsoft Azure portal for the registered application. This is used to identify the Azure AD directory instance.

Client ID

Enter Client/Application ID

Provide the Client ID associated with the registered Azure AD application created for Infraon integration.

Secret Key

Enter client secret value

Specify the Secret Key generated for the Azure AD application. This key is used for secure authentication between Infraon Infinity and Azure AD services.

SSO Unique Key

Select a unique requester attribute

Select the unique attribute used to identify and authenticate synchronized users during SSO login.Example: Email

Sync

Select synchronization type

Choose the object type to synchronize from Azure AD into Infraon Infinity. Example: Requester

Allow Requester Login

Enable requester SSO login

Enable this option to allow synchronized requesters to log in to the Infraon Self-Service Portal using Azure AD credentials.

Verify

Validate Azure AD configuration

Verifies the entered Tenant ID, Client ID, and Secret Key by testing the connection with Azure AD before proceeding with synchronization.

Once the configuration details are added, use Verify to validate the Azure AD connection and continue with the integration setup.

Step 4: After verifying the Azure AD connection, navigate to the Login Settings tab to configure the user attribute used for requester authentication and login mapping.

The Login Settings section allows administrators to define the Azure AD attribute that Infraon Infinity should use as the requester's username during authentication and synchronization.

Label
Action
Description / Example

Username

Select the Azure AD user attribute

Select the Azure AD attribute that should be mapped as the requester login username in Infraon Infinity. Commonly used attributes include mail, userPrincipalName, or other Azure AD user properties. Example: mail

Attribute Search

Search and select attribute

Use the dropdown search to browse and select available Azure AD attributes retrieved from the connected directory instance.

Login Mapping

Configure requester authentication mapping

Maps the selected Azure AD attribute with Infraon requester accounts to support SSO authentication and requester identification during login.

Select Next to save the configured Login Settings and proceed to the next step of the Azure AD integration setup.

Step 5: After configuring the Login Settings, navigate to the Requester tab to map Azure AD user attributes with requester fields available in Infraon Infinity.

This section allows administrators to define how requester information from Azure AD should be synchronized into the Infraon platform. The selected Azure AD attributes are previewed automatically to help validate the mapping configuration before synchronization.

Label
Action
Description / Example

Full Name

Select Azure AD attribute

Maps the requester's full name field in Infraon Infinity with the corresponding Azure AD user attribute.

Email

Select Azure AD attribute

Maps the requester email address from Azure AD. This field is commonly mapped using attributes such as mail or userPrincipalName.

Phone Number

Select Azure AD attribute

Maps the requester's mobile or contact number from Azure AD user details.

Landline

Select Azure AD attribute

Maps the requester's landline or office contact number from Azure AD.

Tags

Select Azure AD attribute

Maps Azure AD attributes that can be used as requester tags or classification values within Infraon Infinity.

Reporting Manager

Select Azure AD attribute

Maps the reporting manager or supervisor information from Azure AD user records.

Azure AD Details

View available Azure AD attributes

Displays the list of available Azure AD user attributes retrieved from the connected tenant for field mapping.

Preview Data

View synchronized sample data

Displays preview values from the selected Azure AD user attribute to validate mapping accuracy before synchronization.

Change User

Load another Azure AD user preview

Allows administrators to switch the preview user used to validate field mappings against a different Azure AD account.

The Work and Address sections follow the same field mapping process as the Requester configuration. Administrators can map Azure AD attributes to the corresponding Infraon Infinity work and location fields and use the preview data section to validate the synchronized values before proceeding.

Once the required mappings are completed, select Submit to save the configuration.

The Azure AD integration is now installed.

Settings

The Settings page allows administrators to manage the Azure AD integration, synchronize user data, update configuration settings, schedule automatic sync jobs, and export unsynchronized records for troubleshooting and validation.

Label
Action
Description / Example

Sync Data

Sync Now

Initiates an immediate synchronization between Azure AD and Infraon Infinity to fetch and update the latest requester and user details. The section also displays synchronization statistics, including Total Data Synced, Failed During Data Sync, and Last Synced Time, to monitor synchronization activity.

AD - Infraon Configuration

Configuration

Opens the Azure AD integration configuration settings page to modify or update mapped fields, authentication details, requester synchronization settings, login settings, and other Azure AD integration configurations.

Schedule Sync

Schedule

Configures automatic synchronization schedules between Azure AD and Infraon Infinity.

Export Unsync Data

Export

Downloads a CSV file containing records that were not synchronized successfully from Azure AD.

Requester Login via SSO

Azure AD–synced requesters can log in to the Infraon Self-Service Portal using Microsoft Single Sign-On (SSO). Authentication and access management for requesters occur when a ticket is created under any workflow configured with App Integration.

It includes scenarios such as:

  • Successful login via SSO

  • Invalid login attempts

  • Session management

  • Multi-device login

  • Error handling

  • Audit logging

How It Works

1. Navigate to Infraon Configuration → Infraon Automation → Workflow.

2. Select the required Ticket Workflow and click Edit.

3. In the Configure Workflow section, expand the left-side panel using the double arrow icon.

4. Under the Actions category, select App Integration.

5. Select the Azure AD app (installed from Infraon Marketplace Integration) from the dropdown.

6. Once selected, you will see three options to configure Azure AD account actions.

Azure AD Actions | Details

Label

Description

Scenario

Force Password Reset on Next Login

Triggers a temporary password reset and forces the requester to set a new password during their next login via SSO. An email with the temporary password is sent.

Use when the requester’s credentials may be compromised, or after IT security updates, ensuring the user resets their password before continuing access.

Unlock User Account

Unlocks a requester’s locked account due to multiple failed login attempts or admin restrictions. No email notification is sent.

Use it when a requester is unable to access the portal due to lockout errors. This ensures quick access restoration without requiring manual IT intervention.

Disable (Lock) User Account

Disables a requester’s account, preventing login until re-enabled. No email notification is sent.

Use when an account needs to be temporarily restricted—e.g., requester leaves the organization, suspicious activity is detected, or compliance rules require suspension.

This ensures IT admins can automate user account management actions within ticket workflows, integrating Azure AD SSO policies directly into Infraon Infinity Automation.

Last updated

Was this helpful?