How to Configure the Profile Application in Microsoft Entra ID Tenant
4 min
article overview the following article is intended for system administrators or technical users of profile it will cover the process for configuring your organization’s microsoft entra id instance to prepare for setting up single sign on (sso) with profile as you complete these steps, you will gather certain settings that will be required for configuring profile disclaimer the instructions provided for configuring microsoft entra id are based on our findings and industry best practices they are intended as general guidance and may not cover all unique configurations or specific requirements of your organization before implementing these configurations, we strongly recommend consulting with your organization’s security, compliance, and it teams to ensure that the assigned privileges and settings align with your internal security policies and compliance requirements intrahealth assumes no responsibility for any misconfigurations, security vulnerabilities, or compliance issues that may arise from applying these configurations a thorough review and approval by your internal teams are essential to ensure that the integration between profile and microsoft entra id aligns with your organization’s operational, security, and compliance standards configure the profile application in microsoft entra id login to https //entra microsoft com https //entra microsoft com go to applications / app registrations click the new registration tab application setup enter application name (example profile emr application) select the " single tenant" option select web option from dropdown for redirect url section add url https // server path /idp/signin oidc note the url above is an example please replace "server path" with your own server found on the profile server login screen click the register button after clicking register , the screen should look like this collect \[application (client) id] & \[authority url] values you will copy the application (client) id and authority url from your microsoft entra id configuration these identifiers are crucial for establishing a secure connection between profile and microsoft entra id, allowing profile to authenticate and interact with entra id correctly make sure to store these details securely, as they will be required during the setup process within profile click on the application name that was created in the next screen you will see the overview page for the selected application and the application (client) id is visible copy and save the value of application (client) id as it will be needed later to configure profile click on the endpoints tab copy and save the value of the field name authority url (accounts in this organizational directory only) as it will be needed later to configure profile client secret setup the client secret acts as a password that allows profile to authenticate security with microsoft entra id once generated, this secret must be copied and stored safely, as it will be used in the configuration process to ensure a secure connection between the two systems go to certificates & secrets and click +new client secret when creating an application secret, you will be prompted to choose an expiration period please ensure the selected expiry aligns with your organization’s security and credential rotation policies common durations include 6 months, 12 months, or 24 months, depending on internal compliance requirements note once the secret expires, authentication to profile with microsoft entra id will fail unless a new secret is generated be sure to create a new secret before the current one expires, and update the corresponding secret settings in profile to avoid any service disruption copy and save the client secret value, because it is visible one time only when the secret is added ensure you copy this value at this time as it will be needed later to configure profile once you copy this value, it will become your application client secret platform configuration setup we need to setup platform configurations for the new application to ensure proper integration with microsoft entra id these configurations define how the application communicates with the identity provider, including supported authentication protocols, redirect uris, and other essential settings go to authentication click +add a platform select web verify the url is https // server path /idp/signin oidc where the profile server will connect to this would be the same url as in step 4 token configuration for user authentication to enable the profile system to securely identify and authenticate users logging in via microsoft entra id, we need to configure token generation and include the necessary 'claims' these claims, such as user attributes provide critical information that the profile system uses for authentication and authorisation purposes go to token configuration page click on +add optional claim select id for token type and check the following email fwd preferred username click add this ensures all tokens generated from microsoft entra id will include the user's microsoft entra id email address, fwd (ip address) and their preferred username a pop up add optional claim appears select the turn on the microsoft graph email permission (required for claims to appear in token) checkbox and click add conditional access policies we recommend considering implementing conditional access policies tailored to your organization's needs conditional access helps control how and when users access the profile application, adding layers of protection based on factors like user risk, device compliance, and location for guidance on setting up conditional access policies refer to microsoft's documentation https //learn microsoft com/en us/entra/identity/conditional access/overview https //learn microsoft com/en us/entra/identity/conditional access/overview assigning users and groups in microsoft entra id for profile access after creating the profile application in microsoft entra id, you can assign access through the "users and groups" section this step controls which users or groups within your organization can access profile to ensure the newly added profile application is governed by these user and group policies go to applications / enterprise applications select your profile application click on properties for assignment required? if you’re deploying the profile application and want only selected clinicians or staff to access it initially, set assignment required? to yes and assign those users/groups if it's meant to be broadly accessible to all users in your organization, leave it as no lastly, assigning access in entra id alone does not grant a user access to profile to enable access, a corresponding user account must exist and be linked in profile to establish a one to one link with the entra id user 11 conclusion with all steps completed above, you should have recorded authority url (used for ms entra id org site (root) in profile settings) see step 5b application (client) id (used for client id in profile settings) see step 5a application client secret (used for client secret in profile settings) see step 6 all three values will be used in configuring microsoft entra id settings within profile learn more for more information on microsoft entra id in profile please click on the article links below for microsoft entra id in profile docid 7vbbydxhicv4cig1vbcwdmicrosoft entra id in profile faq docid\ bcqmjgnoca mmuinnxwjqhow to add single sign on ms entra id license in profile docid\ wikaaadvi80fasetqmukvhow to configure single sign on (sso) for microsoft entra id in profile docid 1zwbi7njedkcjkbfmnpyzhow to configure existing users for single sign on (sso) with microsoft entra id in profile docid\ dx0y5tybx qkq2rohi0z how to add new users to profile for single sign on (sso) with microsoft entra id in profile docid\ infkwtp01gthumhdrkb2nhow to prevent users from using microsoft entra id single sign on (sso) as a login method docid\ z9bjonex05g1ui4jolqbkhow to enforce users to only use single sign on (sso) microsoft entra id as a login method docid\ dvj52aqrmntx m09ucstuhow to configure a profile user's application shortcut to use single sign on (sso) (microsoft entra id) login method docid\ s0 sfcmduo3b2oqe2f9jf