hi human interface®
English

Configure Microsoft Entra ID Sign-In

Configure Microsoft Entra ID Sign-In

Overview

Register an application in Microsoft Entra ID (formerly Azure Active Directory), then enter its identifiers in the hi system. Users can then sign in to the hi web interface with their Entra ID work accounts.

Part of this procedure is performed in the Microsoft Azure Portal by the organization's IT administrator. Microsoft can change Azure Portal labels. See the Microsoft Entra documentation for the current Azure Portal layout.

Information

The Azure Portal screenshots show the portal as of 2024. Host names, organization names, and application and directory IDs in the screenshots are examples.

Prerequisites

  • Use a local hi account that can change System > System Settings. See Manage System Settings.

  • Confirm that the installed license enables Entra ID authentication. See Entra ID Authentication.

  • Confirm that the hi web interface has a registered DNS name. Add the name to the company DNS server, or create a public DNS entry.

  • Confirm that users reach the hi web interface through HTTPS. Entra ID authentication requires HTTPS.

  • Install a certificate from a trusted Certificate Authority. The default self-signed certificate works, but browsers report the site as not secure.

  • Use an Entra ID account that can register applications and grant administrator consent for the tenant.

Register the Application

  1. In the Azure Portal, open the Microsoft Entra ID instance.

  2. Select App registrations, then select New registration.

  3. Enter a name for the application, for example hi - Human Interface.

  4. Under Supported account types, select Accounts in this organizational directory only (Single tenant).

  5. Build the redirect URI. Add /redirect to the HTTPS address of the hi web interface, for example https://hi.example.com/redirect.

  6. Under Redirect URI, select Single-page application (SPA) and enter the redirect URI.

  7. Select Register.

  8. On the Overview page, record the Application (client) ID and the Directory (tenant) ID.

Microsoft Entra ID Register an Application Form with Single Tenant and SPA Redirect URI

  1. Enter a name for the hi application.

  2. Select Accounts in this organizational directory only (Single tenant).

  3. Select Single-page application (SPA) and enter the HTTPS redirect URI ending in /redirect.

  4. Select Register.

Microsoft Entra ID Application Overview with Application and Directory IDs

  1. Record the Application (client) ID.

  2. Record the Directory (tenant) ID.

Configure Authentication

hi uses the authorization-code flow with PKCE. See Microsoft's guidance on implicit grant settings.

  1. In the registered application, select Authentication.

  2. For an application registration dedicated to hi, leave Access tokens (used for implicit flows) and ID tokens (used for implicit and hybrid flows) unselected.

  3. Select Save.

Information

If the registration is shared with an older application, coordinate changes to its implicit grant settings with your IT administrator. Disabling these settings affects all applications that share the registration.

Microsoft Entra ID Authentication Page with Implicit Grant Tokens Unselected

  1. Select Authentication.

  2. Leave Access tokens (used for implicit flows) and ID tokens (used for implicit and hybrid flows) unselected.

  3. Select Save.

Grant API Permissions

The application must read the signed-in user and list the groups of the directory.

  1. Select API permissions. The User.Read permission is already present.

  2. Select Add a permission, then select Microsoft Graph.

  3. Select Delegated permissions.

  4. Enter group in the permission filter and expand Group.

  5. Select Group.Read.All, then select Add permissions.

  6. Select Grant admin consent for your organization, then select Yes.

  7. Confirm that the status of both permissions is green.

Microsoft Entra ID API Permissions Page with Microsoft Graph Selected

  1. Select API permissions.

  2. Select Add a permission.

  3. Select Microsoft Graph.

Microsoft Entra ID Request API Permissions Dialog with Group.Read.All Selected

  1. Select Delegated permissions.

  2. Enter group in the permission filter.

  3. Select Group.Read.All.

  4. Select Add permissions.

Microsoft Entra ID Configured Permissions with Grant Admin Consent

  1. Select Grant admin consent for your organization.

  2. The status column shows that consent has not yet been granted. After granting consent, confirm that both permissions show a green status.

Configure the Group Claim

  1. Select Token configuration.

  2. Select Add groups claim.

  3. In the Edit groups claim dialog, select All groups.

  4. Confirm that Group ID is selected for each token type.

  5. Select Add.

Microsoft Entra ID Token Configuration with Add Groups Claim

  1. Select Token configuration.

  2. Select Add groups claim.

Microsoft Entra ID Edit Groups Claim Dialog with All Groups and Group ID

  1. Select All groups.

  2. Confirm that Group ID is selected for the ID token.

  3. Confirm that Group ID is selected for the Access token.

  4. Confirm that Group ID is selected for the SAML token.

  5. Select Add.

Enable Entra ID in hi

  1. Sign in to hi with a local administrator account.

  2. Select System > System Settings.

  3. In the Entra ID (Active Directory) Authentication section, turn on Enabled.

  4. Enter the Tenant ID and the Application (client) ID that you recorded.

  5. Select Save.

See Entra ID Authentication for all settings, including Hide local user login.

Import Groups and Assign Roles

Caution

An Entra ID user can sign in to hi only as a member of at least one Entra ID group that is imported into hi. Import at least one group and assign its roles before users sign in. Use a local administrator account for this task. Users without an imported group cannot sign in.

  1. Sign in with the local administrator account, not an Entra ID account.

  2. Import one or more groups. See Import Microsoft Entra ID User Groups. When prompted, select Confirm and sign in to Entra ID with an account that can read the groups of the tenant. You stay signed in to hi as the local administrator.

  3. Assign roles and Tags to each imported group. See Assign Roles to a Microsoft Entra ID User Group.

Verify the Result

Sign out of hi. The login page shows an option to sign in with the Entra ID work account. Sign in with an account that belongs to an imported group. Confirm that the account receives the roles of that group.

Next Steps

Use Assign Tags to a Microsoft Entra ID User Group to control which Ports the imported groups can access.