OIDC with state, nonce, PKCE, and RS256 signature validation
Qisutu AddOn
Entra ID – Agents
Secure agent sign-in through Microsoft Entra ID with automatic creation and updating of Qisutu accounts.
Module overview
Entra ID – Agents
The key use cases and capabilities at a glance.
Optional agent import and scheduled synchronization through Microsoft Graph
Encrypted storage and renewal of personal Microsoft 365 tokens
Configure OIDC login, automatic agent provisioning and Microsoft Graph synchronization.
These addresses are generated from the HTTP type, FQDN and web path in system settings. Microsoft Entra ID requires the HTTP type to be HTTPS.
The client secret is encrypted at rest and is never displayed again.
Synchronization is performed by the Qisutu daemon; a separate cron job is not required.
Capabilities in detail
Capabilities in detail
The following capabilities are part of this independent Qisutu module.
- Register this complete address exactly as shown as a web redirect URI.
- This single URI is used for agent login and delegated Microsoft 365 permissions. The Microsoft 365 module needs no second app registration and no additional redirect URI.
- The delegated scopes required for calendar, Teams, and SharePoint are completed when saving and requested on every Entra sign-in.
- Select multiple groups directly using the checkboxes. They are assigned only when an agent is first created.
- Optional. Only direct or transitive members of this Entra group may sign in.
- Optional. Without a group ID, all users in the tenant are read.
- These actions use only the already saved configuration.
- Synchronization is performed by the Qisutu daemon; a separate cron job is not required.
- This address only skips automatic Entra redirection. It does not work when local agent login is disabled.
How the module works
How the module works
The typical workflow is integrated directly into day-to-day work in Qisutu.
- 01
OIDC with state, nonce, PKCE, and RS256 signature validation
- 02
Optional agent import and scheduled synchronization through Microsoft Graph
- 03
Encrypted storage and renewal of personal Microsoft 365 tokens
- 04
Register this complete address exactly as shown as a web redirect URI.
- 05
This single URI is used for agent login and delegated Microsoft 365 permissions. The Microsoft 365 module needs no second app registration and no additional redirect URI.
- 06
The delegated scopes required for calendar, Teams, and SharePoint are completed when saving and requested on every Entra sign-in.
Requirements
Requirements
These technical and organizational requirements are relevant for deployment.
- Qisutu 1.0.1+
- HTTPS
- Microsoft Entra app registration
- Client secret
- OpenSSL
- Qisutu daemon
Administration and operation
Administration and operation
Configuration, background processing, and control remain centralized in Qisutu.
- The client secret is encrypted at rest and is never displayed again.
- Tenant GUID or a domain such as company.onmicrosoft.com; common, organizations and consumers are rejected.
- Client ID of the Microsoft Entra application registration.
- Generated from the tenant. For security, only the Microsoft endpoint belonging to this tenant is accepted.
- Select multiple groups directly using the checkboxes. They are assigned only when an agent is first created.
- Optional. Only direct or transitive members of this Entra group may sign in.
- Optional. Without a group ID, all users in the tenant are read.
- Synchronization is performed by the Qisutu daemon; a separate cron job is not required.
Security and control
Security and control
Credentials, permissions, and automated decisions are handled transparently and securely.
- A secret is stored. Leave this field empty to keep it unchanged.
- Generated from the tenant. For security, only the Microsoft endpoint belonging to this tenant is accepted.
- The delegated scopes required for calendar, Teams, and SharePoint are completed when saving and requested on every Entra sign-in.
- Register this complete address exactly as shown as a web redirect URI.
- This address only skips automatic Entra redirection. It does not work when local agent login is disabled.
Scope and boundaries
Scope and boundaries
The module extends Qisutu for a defined purpose while remaining separate from the Qisutu core.
- Installation through Administration → AddOns
- Independent ZIP module with no changes to Qisutu core files
- 11 fully supported interface languages
- AGPL-3.0-or-later
Questions about this AddOn?