Integrate with Microsoft Azure

In this topic, you will learn how to integrate Portnox™ Cloud with Microsoft Azure Active Directory services.

  1. In the Cloud portal top menu, click on the Settings option.

  2. In the Cloud portal left-hand menu, click on the AUTHENTICATION REPOSITORIES tile.

  3. In the right-hand side pane, find and click on the AZURE ACTIVE DIRECTORY INTEGRATION SERVICE heading.

    More options appear under the AZURE ACTIVE DIRECTORY INTEGRATION SERVICE heading and description.

  4. Enable Microsoft Azure integration.
    1. Under the AZURE ACTIVE DIRECTORY INTEGRATION SERVICE heading and description, click on the Edit link.

    2. Click on the Disabled/Enabled switch to put it in the Enabled position.

    3. Click on the Save button.
  5. In the Azure Directory Applications provisioning mode step, you selected the Automatic option.

    Important: In this topic, you will integrate Portnox Cloud with Azure Active Directory using the automatic provisioning option. If you prefer to use the Manual option to have granular control over application privileges in your Azure environment, go to the following topic: Integrate with Azure Active Directory using manual provisioning.
  6. Grant Portnox Cloud permissions to deploy enterprise applications in your Azure Active Directory.
    1. In another browser tab, open your Azure portal dashboard.
    2. In the Azure Portal dashboard, click on the menu icon in the top left corner and select the Azure Active Directory option.

    3. In the right-hand side pane of the Azure Portal dashboard, you will see a Basic information section.

    4. Copy the value of the Tenant ID field from the Azure Portal dashboard and paste it into the Azure Directory ID field in Portnox Cloud.

    5. Click on the Sign In With Azure Account button.

      Your browser will display a Microsoft Azure prompt to select an account.

    6. Click on the admin account for your Azure tenant.

  7. Grant Portnox Cloud permissions to read directory data.
    1. Click on the Grant Permissions button.

      Your browser will display a Microsoft Azure prompt to select an account.

    2. Click on the admin account for your Azure tenant.

      Important: If the selected Azure account does not have administrative privileges, you may be unable to integrate or asked to contact your administrator.

      Your browser will display a Microsoft Azure prompt asking you to confirm the required permissions.

    3. Click on the Accept button to confirm permissions that the Portnox Cloud enterprise application will have to your Microsoft Azure Active Directory data.
  8. Grant Portnox Cloud permissions to validate user credentials.
    1. Click on the Grant Permissions button.

      Your browser will display a Microsoft Azure prompt to select an account.

    2. Click on the admin account for your Azure tenant.

      Important: If the selected Azure account does not have administrative privileges, you may be unable to integrate or asked to contact your administrator.

      Your browser will display a Microsoft Azure prompt asking you to confirm the required permissions.

    3. Click on the Accept button to confirm permissions that the Portnox Cloud enterprise application will have to your Microsoft Azure Active Directory data.
  9. Select the domains managed by Azure Active Directory that you want to associate with your Portnox Cloud organization.

    • If your Active Directory manages many domains you can use the search domains field to search for a string that matches a domain name. The list of domains below the search field will be updated as you type.
    • Click on the select all or unselect all link to select or deselect all domains in the list.
    • Click checkboxes next to domains to select or deselect them individually.
    1. After you select the domains, click on the Save Domains button to save your selection.
  10. Under the AZURE ACTIVE DIRECTORY INTEGRATION SERVICE section, click on the Force sync link.

    Portnox Cloud will start synchronizing immediately in the background with your Azure Active Directory. If you do not click Force sync, the synchronization process will be started automatically later.

    Note: If your Azure directory is very large, this process can take up to approximately an hour.
  11. Optional: If you want to edit the options of your Azure Active Directory integration or configure additional options, read the following topic: Edit your Azure Active Directory integration.

Result: Your Azure Active Directory integration is now active. You can authenticate devices on your network using Azure Active Directory.