Important Note: nShift Entra Gallery Application requires the following Permissions: openid and profile. You may need to grant admin consent for them while performing the setup.
Steps in the setup:
- Step1: Getting an nShift Portal user
- Step 2: Configure SSO configuration in nShift Portal
- Step 3: Register nShift application
- Step 4: Configure Entra ID user access
- Step 5: Additional setup for nShift Portal users
Step 1: Getting an nShift Portal user
The customer’s EntraID Administrator (the user performing the nShift Application registration) will need an nShift Portal user.
Please contact nShift Support and ask for a user account to be created for your EntraID Administrator. You'll need to provide the Entra Administrator’s username and your Microsoft EntraID Tenant ID. nShift will then give you the nShift-Portal username, which will already have the necessary SSO setup. Make sure this user has the SSO Configuration functionality enabled.
This user will be used while performing Steps 2 and 3.
Step 2: Configure SSO configuration in nShift Portal
- Log into nShift Portal go to Settings > CompanyManagement > Single Sign-On (SSO).
- Select a nShiftMarketplace from the drop-down list and click Save.
- Fill in the Valid issuer field with your organization’s tenant id.
This must have the following structure:https://sts.windows.net/{TENANT_ID}/
Example:
- Click Save.
- Go to Settings > CompanyManagement > CustomerUsers.
- Edit your user by selecting from the SSO external provider dropdown nShiftGallery and click Save.
- Log out of the nShift Portal.
Step 3: Register nShift Application
- Go to Microsoft Azure -> Enterprise applications and click New application.
- You will be taken to the Microsoft Entra Gallery. Once there, search for nShift, and you should see nShift_IdentityProvider listed near the top. Click on Sign up for nShift_IdentityProvider to continue.
- You will be redirected to the nShift Portal login page. Enter the credentials (nShift Portal username) previously used for the nShift Portal configuration and sign in.
- After a successful login, the nShift Entra Gallery App should be added to your list of Enterprise Applications.
Step 4: Configure EntraID user access
Customer should configure their EntraID Users to have access to the EntraID nShift Application.
Make the necessary changes within Assign users and groups.
*)Important note: nShift does not support User Provisioning at this time. All of the customer’s users who wish to access nShift-Portal will have to be created within nShift-Portal.
Step 5: Additional setup for nShift-Portal users
If the nShift Portal user created for the registration in Step 1 is not the main user (owner) for the nShift-Portal customer’s account, nShift can provide support to make the necessary changes.