SaaS Security
Integrate with Azure Active Directory
Table of Contents
Expand All
|
Collapse All
SaaS Security Docs
Integrate with Azure Active Directory
Configure an app registration on Azure Active Directory to enable SaaS Security
to retrieve users and groups
Where Can I Use This? | What Do I Need? |
---|---|
|
Or any of the following licenses that include the SaaS Security Inline license:
|
If you performed an Azure Active Directory integration for Data Security, SaaS Security Inline uses that same integration framework, and you do not need
to repeat this integration.
SaaS Security integrates with Azure Active Directory (AD) to manage cloud-based
identity and access management service. After Azure AD connects to SaaS Security, the service retrieves your groups, which you can specify in
your SaaS policy rule recommendations. Creating policy rule recommendations based on
user group membership rather than individual users simplifies administration because
you don’t need to update the recommendation whenever group membership changes.
To integrate Azure AD, you need to:
- Configure an application registration on Azure AD.
- Connect Azure AD to SaaS Security.
- Select the AD groups you want to scan.
Configure an Application Registration on Azure AD
- Log in to Microsoft Azure and select Azure Active DirectoryApp registrationsNew registration.Enter a Name, select Accounts in this organizational directory only, and click Register.Copy the Application (client) ID.Copy the Directory (tenant) ID.Click API permissionsAdd a permissionMicrosoft GraphApplication permissionsSelect DirectoryDirectory.Read.All.Enable permissions to read directory data to allow SaaS Security to connect to the Azure AD application to read users, groups, and apps in the organization’s directory.Select GroupGroup.Read.All and Add permissions.Enable permissions to read all groups to allow Azure Active Directory to list groups, read their properties and membership, and enable SaaS Security to populate a list of groups to scan.Click Grant consent and click Yes to confirm permission change.Select Certificates & secretsNew client secret, enter a Description, select an expiration, and click Add.Copy the unique Client secret (Application Key).
Connect Azure Active Directory to SaaS Security
You need to connect Azure AD to SaaS Security so that SaaS Security Inline and Data Security can retrieve all your AD groups.After you connect Azure AD to SaaS Security Inline, you might need to wait up to 24 hours for all your AD groups to display in the SaaS Security Inline web interface.- Verify that you have an Azure AD account with administrator privileges.Log in to Strata Cloud Manager.Select ManageConfigurationSaaS SecuritySettingsDirectory ServicesConnect New .Select Azure Active Directory, then enter AD information.
- Directory ID
- Application ID
- Authentication Key
Save to authenticate Azure Active Directory.You can give your Azure AD instance a descriptive name other than the default name, which is Azure Active Directory n, to differentiate it from other instances.