Skip to main content
Version: 11.x

Entra ID/Azure DA Planning

Rebranding

Azure AD has been rebranded by Microsoft to "Entra ID". This has no effect on the integration. (https://www.microsoft.com/en-us/security/business/identity-access/microsoft-entra-id)

Basic principles

To sign in using Entra ID (Entra) at least two different Entra-groups are required.

  • The first group determines the right to login and which site the user belongs to.
  • The second group determines the user profile to use.

To be able to login, an Entra user must match the following requirements

  • The user must be explicitly linked to at least one site in Smartsign (member of Entra group linked to site)
  • The user must be explicitly linked to a single user profile in Smartsign

There is no need to import or sync users to Smartsign. Users will be automatically created at sign in if authenticated by Entra.

Additional groups can be used to differentiate between different sites and different user profiles within Smartsign.

Access to resources such as screens, layers and media folders are controlled using groups within Smartsign.

Optional

If you wish to manage access to resources, such as screens, folders and layers, from the Entra. Additional groups should be created for that purpose.

Example:
Smartsign_Resources_Finance
Smartsign_Resources_Marketing 

Suggested Entra ID groups

For clarity and readability, we suggest naming your ad groups similar to the below examples.

One Entra group for each site (minimum one)

Example:
Smartsign_Site_MySiteName

The site group should only be linked to site(s) in Smartsign. It should not be linked to any user profile.

One Entra group for each user profile (minimum one, at least two normally)

Example:
Smartsign_Userprofile_Publisher  Smartsign_Userprofile_SiteAdmin
Smartsign_Userprofile_Admin 

Each user profile group must be linked to a single user profile.