Skip to main content

Set Up Microsoft Entra ID Integration

To sign in to BioStar Air with Microsoft Entra ID, an ID administrator creates an app registration in Entra ID. Then the administrator links it to the BioStar Air SSO settings.

Connect Entra ID SSO

BioStar Air: Prepare redirect URI

  1. Click SettingsSite in the left sidebar of BioStar Air.

  2. Click the SSO & SCIM tab.

  3. Under Identity Provider, select Microsoft Entra ID.

  4. Copy the URI value shown in the Redirect URI field.

Microsoft Entra admin center: Register app

  1. Sign in to the Microsoft Entra admin center.

  2. Go to Entra IDApp registrations.

  3. Click New registration.

  4. Enter 'BioStar Air' for the app name.

  5. Under Supported account types, select Single tenant only.

  6. In Redirect URI, select Web. Paste the URI from step #bsairRedirect into the field.

  7. Click Register.

  8. In the BioStar Air app Overview, copy the following values.

    • Application (client) ID

    • Directory (tenant) ID

  9. Under Certificates & secretsClient secrets, click New client secret.

  10. Enter a description and select an expiration period.

  11. Click Add.

  12. Copy the Value of the generated client secret.

Enter the copied Application (client) ID, Directory (tenant) ID, and Value in the next step.

Caution

Use Value, not Secret ID. The Value appears only once, so copy it now.

Microsoft Entra admin center: Assign users and groups

Create users and groups before assigning them.

  1. In Enterprise apps, click the app created earlier (BioStar Air).

  2. Click Assign users and groups.

  3. Click Add user/group to assign users and groups.

  4. After assigning users and groups, click Assign.

BioStar Air: Configure SSO

  1. Return to the BioStar Air Settings screen and enter the values copied in #appRegistration into each field.

    • Client ID: Application (client) ID

    • Client Secret: Value

    • Tenant ID: Directory (tenant) ID

  2. In the Email Domain field, enter your organization's email domain.

  3. Click Save & Validate.

After the system saves and verifies successfully, it automatically generates the value for Discovery URL.

Connect Entra ID SCIM provisioning

BioStar Air: Copy SCIM token

  1. Click SettingsSite in the left sidebar of BioStar Air.

  2. Click the SSO & SCIM tab.

  3. In the SCIM Provisioning section, copy the SCIM Endpoint URL value.

  4. Click Generate Token.

  5. In the Token Generation Complete dialog box, copy the token.

Info
  • Copy the generated token immediately. Copy the token only when you generate it. After you close the dialog box, you cannot copy the token again.

  • If you lose the token, click Rotate Token to generate a new token. Enter the new token in the identity provider again.

  • In the next step, enter the SCIM endpoint URL and token copied in this step.

Microsoft Entra admin center: Create a SCIM provisioning app

  1. In Enterprise apps, click New application.

  2. Click Create your own application.

  3. Enter the app name as 'BioStar Air SCIM'.

  4. Select Integrate any other application you don't find in the gallery (Non-gallery).

  5. Click Create.

  6. In the BioStar Air SCIM app, click ManageProvisioning.

Microsoft Entra admin center: Set admin credentials and start provisioning

  1. Click New Configuration.

  2. In Admin credentials, enter the SCIM endpoint URL and token copied in #copyToken into Tenant URL and Secret token.

  3. Click Test Connection to test synchronization.

  4. Click Create.

  5. In Users and groups, click Add user/group.

  6. Assign the users and security groups to provision.

  7. Click Assign.

  8. Go to ProvisioningMappings and confirm that user and group synchronization is enabled.

  9. Review the mappings before changing attributes.

  10. In the SCIM app Overview, click Start provisioning.

Info

It is recommended to start with a small test group. BioStar Air can take up to 40 minutes to reflect group membership changes.

BioStar Air: Check the connection

  1. Click SettingsSite in the left sidebar of BioStar Air.

  2. Click the SSO & SCIM tab.

  3. In the SCIM Provisioning section, check for the Connected indicator.

Group mapping

After connecting SSO and SCIM and pushing IdP groups, the site administrator must map them to BioStar Air groups.

Mapping rules

  • You can map multiple IdP groups to a single BioStar Air user group.

  • A BioStar Air user group must be empty before mapping.

  • BioStar Air groups with members cannot serve as mapping targets.

  • Only the site master administrator can manage IdP group mapping.

  • The system locks the role after mapping an IdP group to the master role.

Map administrator roles and user groups

  1. Click SettingsSite in the left sidebar of BioStar Air.

  2. Click the SSO & SCIM tab.

  3. Go to the Group Mapping section and click Add.

  4. From IdP Group, select an IdP group.

  5. In Mapping Target, select Admin Role or Local User Group based on the selected IdP group.

  6. Depending on the mapping target, assign an administrator role or select a user group.

  7. Click Save to save the mapping.

The Group Mapping section shows IdP groups and their mapped BioStar Air groups.

Info

Manage synchronized admins, users, and groups

With provisioning enabled, BioStar Air shows whether each admin, user, and group is local or synchronized from the identity provider.

  • In SettingsAdmins & Technicians, check the Identity Source column in the admin list.

  • In User ManagementUsers, check the Identity Source column in the user list.

  • In User ManagementUser Groups, check the Identity Source column in the user group list.

How SCIM-synced entries work

  • Manually created users and admins remain manually managed.

  • BioStar Air prevents manual deletion of SCIM-synced entries.

  • BioStar Air prevents manually adding or removing users from SCIM-synced groups.

  • Manually changing a synchronized entry locally sets the status to Override. Run Release Override to cancel local changes and return the entry to SCIM management.

Sign in with Entra ID

After completing Entra ID SSO connection, users sign in to BioStar Air with a Microsoft account on the sign-in screen.

  1. On the BioStar Air sign-in screen, click Login with Microsoft.

  2. Select Microsoft Entra ID.

    If your organization already uses Microsoft SSO, select Microsoft SSO to sign in without additional settings.

  3. Enter the organization's email address or domain in the Email Address or Domain field. (For example, user@company.com or company)

  4. Click Continue.

  5. On the Microsoft Entra ID sign-in screen, enter your organization's account email address and password.

  6. After authentication is complete, you are automatically redirected to BioStar Air, completing the sign-in process.

Info

If Entra ID SSO is not set up for the entered email domain, an error message appears. Contact the site administrator.

Was this page helpful?