Sync Azure AD with Oomnitza to surface and gain visibility of user data.
Contents
Before you start
Before you create the integration, you must complete the following steps:
The Active Directory User integration uses the List Users API, which requires User.Read.All permissions. See Microsoft Graph API Documentation: List users.
You can, depending on the integrations that you have added to your Oomnitza instance, add:
- Azure AD User Load
- Azure AD User Load with filtering
ImportantWhen you add the Azure AD User Load with filtering integration, you can retrieve all the data by selecting Default as the filtering expression or you can create a filter to retrieve the data you need. See Use the $filter query parameter. The pattern for adding a filter is as follows:
<field> <operator> (<'value1'>, <'value2'>, <'value3'>). Example: employeeType in ('Admin', 'Staff', 'Faculty', 'Contingent Workers', 'EmpStudent').
Creating the user integration
- In Oomnitza, click Configuration > Integrations > Overview.
- Click Block view
.
- On the Integrations page, scroll down to the Extended section for user integrations.
- Click NEW INTEGRATION.
- In the sidebar, search for the integration.
- Click ADD.
Integration details overview
More information is provided about the following fields to help you complete the integration:
- User only. Add user records.
- User plus SaaS user. Add user and SaaS user records.
The benefit of adding SaaS user records is that you can run a workflow to validate the status and activity of SaaS users and retrieve information such as the role of the SaaS user. The information that can be retrieved depends on whether SaaS user workflows are available for the integration.
Installation types
- Cloud. Store credentials in the Oomnitza cloud.
- Local. Store credentials locally. If you want to sync Oomnitza with vendor applications that require AWS or OAUTH authentication, select cloud as the type of installation. Local installations don't support AWS and OAuth authentication.
Integration preferences
- Create & Update. Add and update records.
- Create only. Add records.
- Update only. Update records.
Editing the integration details
When you edit the Integration details section, you can select the name or names of integration contacts. Integration contacts will receive an in-app notification and an email, when the integration fails, when the integration fails to complete within 24 hours, or when the scheduled integration fails to run.
- Click Edit
.
- Make your changes.
Editing the credential details
If you selected Cloud as the installation type, choose one of the following options:
- Select the credentials that were created for the integration.
- Edit the credentials that were created for the integration.
- Create new credentials
Scheduling the integration
By default, data is synced once every day. Change the interval or the time so that the data is streamed when your system isn't busy.
- Click Edit
.
- Make and save your changes.
Mapping fields to Oomnitza
To map the fields to Oomnitza, click Edit .
Select Edit integration to add rules for syncing data.
Filtering integration results.
You can add new fields to your integration by selecting Add new field on the mapping page.
Creating custom API fields.
Standard Mappings
Map the Microsoft Azure Active Directory fields to Oomnitza fields and create custom mappings to get the user information that you need.
Complete these actions:
- Click Smart Mapping to automatically detect appropriate mapping fields. Values from the integration can also be dragged to the appropriate field on the Oomnitza side, or selected from the integration field dropdown.
- Map the Mail or User Principal Name to the Email field on the Oomnitza side (required for integration).
- Map the Mail or User Principal Name to the Username field on the Oomnitza side (required for integration).
- Select the Role field on the Oomnitza mapping side.
- Choose a suitable role from the list (a defined role is necessary for the integration)
- Assign a sync key to a unique field, such as the Email.
- Click UPDATE.
Tracking information for user loads
When the integration is run, you can track the name of the credentials that were used and the source of the data. To do this, you map the following fields to Oomnitza:
- Connect: Credentials
Standard Azure Active Directory to Oomnitza User Load mappings
Age Group
City
Company Name
Consent Provider For Minor
Country
Creation Date
Creation Type
Department
Display Name
Employee ID
Employee Hire Date
Employee Type
Fax number
Given Name
ID
Is Account Enabled
Is Resource Account
Job Title
Last Password Change Date
Legal Age Group
Mail
Mail Nickname
Mobile Phone
Office Location
Password Policies
Postal Code
Preferred Language
State
Street
Surname
Usage Location
User Principal Name*
User Type
*Mandatory field.
Launching the integration
Your integration is in Draft mode until the required mandatory fields are added. When added, click Launch to activate your integration.
If you selected Cloud as the installation type when creating the integration, see Running an extended integration
If you selected Local as the installation type when creating the integration, see Running an extended integration locally.
Viewing data ingested by Oomnitza
Viewing ingested asset data
For asset integrations, click Hardware. If the asset integration also ingests software data, click Software.
Viewing ingested user data
For user integrations, click People. If you chose the option to ingest User and SaaS user data, click Software > SaaS, click the SaaS app, and then click the Users tab.
Related Links
Unleash the power of Oomnitza
To get valuable actionable insights that help you manage your assets, learn how to:
- Configure dashboards for your users and software
- Configure custom reports about your users and software
- Create workflows to automate tasks
See Getting started for more information.
Comments
0 comments
Please sign in to leave a comment.