Knowledge Base - Cloud Connect

STS

This topic provides information on the STS configuration required for setting up Cloud Connect. It includes the steps for registering the application in the Azure portal, App registration, authentication, Certificates & Secrets, API permissions, IIS setup, and Publishing Toolkit settings. After completing the STS configuration, the next step is to complete the Publisher Service Setup.

Register the application in Azure Portal

Registering your application establishes trust between your app and the Microsoft identity platform. Follow these steps to create the app registration

  1. Sign In to https://portal.azure.com.

  2. From the Portal menu at the upper-left corner of the screen, select Azure Active Directory.

  3. In the left menu, click App registration. The App registrations page displays.

  4. At the upper-left corner of the App registrations screen, click New Registration.

    AppRegistration.png
  5. In the Name field, enter a recognizable name. For example, Experlogix “Targetsite”.

  6. In the Supported Account Types section, select the Accounts in this organizational directory only (EXPERLOGIX only - Single tenant) option.

  7. In the Redirect URI section, in the Select a Platform dropdown list, select Web.

  8. In the URL path, enter name.experlogixonline.com/experlogix.sts/Authorize.aspx.

  9. Click the Register button. The Azure portal displays the app registration's Overview page.

AppOverviewPage.png

This completes the initial app registration. The Application (client) ID is displayed on the Overview page. Also called the client ID, this value uniquely identifies your application in the Microsoft identity platform.

Note down the Client ID for future use.

Authentication

Settings for each application type, including redirect URIs, are configured in Platform configurations in the Azure portal. To configure application settings and authentication, follow the below steps:

  1. In the left menu, under Manage, select Authentication.

    AuthenticationPage.png
  2. Under Platform configurations, click Add a platform.

    ConfigurePlatform.png
  3. Select Mobile and desktop applications.

  4. Under Redirect URIs, select the URI with nativeclient in its name.

    RedirectURI.png
  5. Click Configure. The Authentication page displays.

This completes the Platform configuration.

Certificates and Secrets

Credentials are used by confidential client applications that access a web API. A client secret is a string value your app can use in place of a certificate to identify itself. Update the following settings in the Certificates and Secrets section

  1. In the left menu, select Certificates & Secrets.

    CertificatesSecrets.png
  2. In the Client secrets tab, click New client Secret. The Add a client secret page displays.

  3. In the Description field, add a description for your client secret.

  4. In the Expires field, select 730 days (24 months).

    AddClientSecret.png
  5. Click Add.

    ClientSecretPage.png
  6. Record the client secret's value for use in your client application code.

Recording the Value (client secret value) is important as it is never displayed again after you leave this page.

This completes adding client secret in the Credentials & Secrets page.

API Permissions

Update the following settings in the API Permissions section.

  1. In the left menu, select API permissions.

    APIPermissionspage.png
  2. Click Add a permission.

    The Request API permissions page displays.

  3. Under the APIs my organization uses, search for and select Dynamics 365 Business Central.

    RequestAPIPermission.png
  4. Select Delegated Permissions and all the permissions below it.

    DelegatedPermission.png
  5. Click the Add permissions button. The API permission is added and listed on the API Permissions page.

  6. Click Grant Admin Consent. A confirmation dialog box displays.

  7. Click Yes. The API permission is added for the app.

IIS Setup

The IIS setup requires updating the web.config file.

  1. Create folder C:\inetpub\sitename\experlogix.sts and copy the site files.

  2. In the experlogix.sts folder, make the following updates to the web.config file:

    1. Delete all the authentications except AzureAD on lines 35 and 78

    2. Logpath on line 14

    3. Experlogixsite url on line 23

    4. Resource on line 29

    5. Client ID on line 31

    6. Secret value on Line 33

Create application

  1. From the Start menu, open the Internet Information Services (IIS) Manager.

  2. Create a separate application pool that runs as a Networkservice.

  3. Right-click on the Experlogix.sts folder and select Convert to Application.

    ConvertToApplication.png

This completes the creation of the experlogix.sts application.

Publishing Toolkit

Complete the following changes in the Design Center Toolkit:

  1. In Design Center, open the Publishing Toolkit.

  2. On the Publishing Toolkit toolbar, click the Open button. The Target Site Settings page displays.

  3. Click Website Settings. The Experlogix Config File Editor page displays.

    WebConfigAuthSettings.png
  4. In the Web Configurator Authorization Settings section, in the STS URL field, add https://created-dns-name.experlogixonline.com/experlogix.sts/Authorize.aspx

The STS URL is case-sensitive. It must be the same as in the Azure portal.

  1. Click the Save Config File button. This completes the Publishing Toolkit update for STS Configuration.

The next step is to complete the Publisher service setup. For more information, see Publisher Service Setup.