Quick-start - Elevated Entra ID access
In this guide we will set up Elevated Access to Entra ID for MSPs. Technicians can request just-in-time admin accounts for customer Entra ID tenants and access them from idemeum portal.
Sign up for idemeum MSP tenant
If you have not created your idemeum cloud tenant yet, please follow the steps below to create a trial tenant for your organization.
Enable cloud directory for your MSP tenant
To manage identities of your MSP technicians we will leverage idemeum local directory. To enable local directory:
- Navigate to
https://<your-msp-domain>.idemeum.com/adminportal
- Access
Users
→User source
and chooseLocal
Save
the configuration
Onboard other MSP technicians
Now you can add your technicians to your MSP tenant local directory. Once onboarded they will be able to login to your MSP tenant and also customer tenants with a mobile device.
- Navigate to your MSP tenant admin portal at
https://<your-msp-domain>.idemeum.com/adminportal
- Access
Users
→User management
and clickAdd user
- Enter the following details to create a technician:
First name
andLast name
Corporate email address
Username
will be automatically generated. This username will be used to create unique admin account for each technician on the workstations that they access. You can change this username if you want.- Optionally specify
personal email address
Create a customer tenant that you will manage
Idemeum offers Multi-Tenant MSP Portal to manage all your customer tenants from a single dashboard. To create a tenant for your customer:
- Navigate to your MSP tenant admin portal at
https://your-domain.idemeum.com/adminportal
- Access
Customers
on the left and clickCreate customer
- Enter
Name
(will be used to create a subdomain for your MSP tenant, for examplecustomer-<your MSP domain>.idemeum.com
) andDisplay name
(will be used as a display name / title for your customer tenant)
Once the customer tenant is created, click on the name of the customer tenant, and you will be automatically logged in there. More about the MSP portal below.
Delegate technician access to customer tenant
You have two options:
- You can make every technician an
Admin
in your MSP tenant and as a result, technicians will have access to all created customers tenants by default. - You do not assign an
Admin
role to a technician, but delegate access to each customer tenant directly.
To assign an Admin
role to a technician, please follow these steps.
- Navigate to your MSP tenant admin portal at
https://<your-msp-domain>.idemeum.com/adminportal
- Access
Users
- Find the user record, click on
...
and then chooseMake admin
To delegate access to each customer tenant directly, please follow these steps.
Configure customer tenant
Now access the customer tenant you created with a mobile device. You can directly navigate to a customer tenant URL at customer-<your msp domain>.idemeum.com
or navigate to your MSP postal, Customers
section and click on the link from there.
Enable cloud directory for customer tenant
- Navigate to your customer tenant admin dashboard and enable cloud directory
- Access
Users
→User source
and chooseLocal
Save
the configuration
Connect Entra ID tenant
We will now connect customer Entra ID tenant with this customer idemeum tenant. Connection is cloud-to-cloud and is done over oAuth protocol. You will need an admin account for customer Entra ID tenant to authenticate and then authorize idemeum cloud to access Entra ID APIs. Detailed steps to connect Entra ID cloud tenant are below.
Create entitlement rule for Entra ID application
After the Entra ID is connected, make sure you create entitlement rule so that technicians can access the Entra ID application. Instructions are below.
Install idemeum browser extension
Idemeum browser extension offers the convenience of automatically filling credentials when accessing Entra ID customer tenants. Technicians can download the extension from the store and install for their browsers.
Test technician Entra ID access flow
Now you can test the Entra ID access flow. We documented how the technician access flow looks like step by step. Please check the document below.
Questions?
If you have any questions please join our Discord chat, and we will help.