Skip to content

Creating an Azure Application for SharePoint Online

A new Azure Active Directory application must be created and configured to support the Data Access Security SharePoint Online functionality.

This configuration can be performed either by running the automated PowerShell script supplied with the SailPoint distribution pack, or by creating and configuring the application through the Azure portal.

Creating and Configuring the Application Automatically

There is a PowerShell script named CreateSharePointOnlineAndOneDriveApp.ps1 provided in the Collectors.zip under the extracted scripts sub-folder. This script will perform all the Azure application creation and configuration steps required for OneDrive.

To run this script, the Azure AD PowerShell module must be installed.

  1. Open PowerShell as an Administrator.
  2. Install the Azure AD PowerShell module: Install-Module -Name AzureAD
  3. Open the CreateSharePointOnlineAndOneDriveApp.ps1 file in a text editor to review the default parameters. The parameters can be edited in the file or passed as parameters when running the script.
  4. Run the script:
    • To run the script with the default parameters from the directory where the script is located, run \CreateSharePointOnlineAndOneDriveApp.ps1
    • To run the script while overriding some of the default parameters, like DNS Name, years of certificate validity, or application name: .\CreateSharePointOnlineAndOneDriveApp.ps1 -AppName "SharePoint Online DAS App" -CertDnsName "contoso.com" -CertYearsValid 15
  5. When prompted, log in with administrator credentials to create and configure Azure applications.

The last step of the script will launch a URL to grant admin consent for the application. When you grant consent, you will be redirected to a missing localhost URL. The operation is successful if the URL for that page contains admin_consent=True.

Note

If you experience an access denied or other error in the web browser when granting admin consent, this might be a timing issue. This can be resolved by manually granting admin consent through the Azure portal. Alternatively you can copy and paste the consent URL into your browser. This is found in the script at: Consent URL:.

The following output should be gathered or noted when running the script. This information will be used to configure the SharePoint Online application in Data Access Security:

  1. The App ID value in the console output.
  2. The created certificate file <AppName>.pfx located in your working directory.
  3. The certificate password that was entered when prompted.

Creating and Configuring the Application Manually

The following steps will create and configure an Azure application for SharePoint Online authentication through the Azure portal.

These steps are adapted from the Microsoft SharePoint Online documentation.

Registering the Application in Azure AD

  1. Go to the the Azure AD portal.
  2. Under Manage Azure Active Directory, select View.
  3. On the Overview page that opens, under Manage, select App registrations.
  4. On the App registrations page that opens, select New registration.
  5. On the Register an application page that opens, configure the following settings:
  6. Name - Enter something descriptive, like "SharePoint Online DAS App"
  7. Supported account types - Verify that Accounts in this organizational directory only (<YourOrganizationName> only - Single tenant) is selected.
  8. Redirect URI (optional) - Leave empty.
  9. Select Register.

You will now assign API permissions to the application from this screen.

Assigning API Permissions to the Application

  1. On the app page under Manage, select Manifest.
  2. On the Manifest page, find the requiredResourceAccess entry.
  3. Replace the entire requiredResourceAccess entry with the following:

    "requiredResourceAccess": [
        {
            "resourceAppId": "c5393580-f805-4401-95e8-94b7a6ef2fc2",
            "resourceAccess": [
                {
                    "id": "594c1fb6-4f81-4475-ae41-0c394909246c",
                    "type": "Role"
                }
            ]
        },
        {
            "resourceAppId": "00000003-0000-0ff1-ce00-000000000000",
            "resourceAccess": [
                {
                    "id": "678536fe-1083-478a-9c59-b99265e6b0d3",
                    "type": "Role"
                }
            ]
        }
    ],
    
  4. Select Save.

  5. On the Manifest page, under Manage, select API permissions.
  6. On the API permissions page, verify that both Sites.FullControl.All and ActivityFeed.Read appear on the list.
  7. Select Grant admin consent for <Organization>. Read the confirmation dialog that opens.
  8. Select Yes in the confirmation dialog. The Status value should now be Granted for <Organization> on both entries.
  9. Close the API Permissions page (not the browser tab) to return to the App registrations page to generate a self-signed certificate.

Generating a Self-Signed Certificate

Create a self-signed x.509 certificate using the following PowerShell commands.

Edit parameters such as DnsName, Certificate expiration, and password as appropriate:

Create certificate

$mycert = New-SelfSignedCertificate -DnsName **"contoso.org"** -CertStoreLocation "cert:\LocalMachine\My" -NotAfter (Get-Date).AddYears(**15**) -KeySpec KeyExchange 

Export certificate to .pfx file

$mycert | Export-PfxCertificate -FilePath mycert.pfx -Password $(ConvertTo-SecureString -String "**P@ssw0Rd1234**" -AsPlainText -Force)

Export certificate to .cer file

$mycert | Export-Certificate -FilePath mycert.cer

Assigning the Certificate to the Azure Active Directory Application

After you register the certificate with your application, you can use the private key (.pfx file) for authentication.

  1. Go to the the Azure AD portal.
  2. Under Manage Azure Active Directory, select View.
  3. On the Overview page, under Manage, select App registrations.
  4. On the Apps registration page, select the application you registered.
  5. On the application page, under Manage, select Certificates & secrets.
  6. Select Upload Certificate.
  7. Browse to the self-signed certificate .cer file that you created when generating a self-signed certificate.
  8. Select Add.

The certificate is now shown in the Certificates section.

Comments