Back to all AddOnsEntra ID – Agents

Qisutu AddOn

Entra ID – Agents

Secure agent sign-in through Microsoft Entra ID with automatic creation and updating of Qisutu accounts.

Version1.0.1
CompatibilityQisutu 1.0.1 or newer
Languages11
LicenseAGPL-3.0-or-later

Module overview

Entra ID – Agents

The key use cases and capabilities at a glance.

01

OIDC with state, nonce, PKCE, and RS256 signature validation

02

Optional agent import and scheduled synchronization through Microsoft Graph

03

Encrypted storage and renewal of personal Microsoft 365 tokens

04

Configure OIDC login, automatic agent provisioning and Microsoft Graph synchronization.

05

These addresses are generated from the HTTP type, FQDN and web path in system settings. Microsoft Entra ID requires the HTTP type to be HTTPS.

06

The client secret is encrypted at rest and is never displayed again.

07

Synchronization is performed by the Qisutu daemon; a separate cron job is not required.

Capabilities in detail

Capabilities in detail

The following capabilities are part of this independent Qisutu module.

  • Register this complete address exactly as shown as a web redirect URI.
  • This single URI is used for agent login and delegated Microsoft 365 permissions. The Microsoft 365 module needs no second app registration and no additional redirect URI.
  • The delegated scopes required for calendar, Teams, and SharePoint are completed when saving and requested on every Entra sign-in.
  • Select multiple groups directly using the checkboxes. They are assigned only when an agent is first created.
  • Optional. Only direct or transitive members of this Entra group may sign in.
  • Optional. Without a group ID, all users in the tenant are read.
  • These actions use only the already saved configuration.
  • Synchronization is performed by the Qisutu daemon; a separate cron job is not required.
  • This address only skips automatic Entra redirection. It does not work when local agent login is disabled.

How the module works

How the module works

The typical workflow is integrated directly into day-to-day work in Qisutu.

  1. 01

    OIDC with state, nonce, PKCE, and RS256 signature validation

  2. 02

    Optional agent import and scheduled synchronization through Microsoft Graph

  3. 03

    Encrypted storage and renewal of personal Microsoft 365 tokens

  4. 04

    Register this complete address exactly as shown as a web redirect URI.

  5. 05

    This single URI is used for agent login and delegated Microsoft 365 permissions. The Microsoft 365 module needs no second app registration and no additional redirect URI.

  6. 06

    The delegated scopes required for calendar, Teams, and SharePoint are completed when saving and requested on every Entra sign-in.

Requirements

Requirements

These technical and organizational requirements are relevant for deployment.

  • Qisutu 1.0.1+
  • HTTPS
  • Microsoft Entra app registration
  • Client secret
  • OpenSSL
  • Qisutu daemon

Administration and operation

Administration and operation

Configuration, background processing, and control remain centralized in Qisutu.

  • The client secret is encrypted at rest and is never displayed again.
  • Tenant GUID or a domain such as company.onmicrosoft.com; common, organizations and consumers are rejected.
  • Client ID of the Microsoft Entra application registration.
  • Generated from the tenant. For security, only the Microsoft endpoint belonging to this tenant is accepted.
  • Select multiple groups directly using the checkboxes. They are assigned only when an agent is first created.
  • Optional. Only direct or transitive members of this Entra group may sign in.
  • Optional. Without a group ID, all users in the tenant are read.
  • Synchronization is performed by the Qisutu daemon; a separate cron job is not required.

Security and control

Security and control

Credentials, permissions, and automated decisions are handled transparently and securely.

  • A secret is stored. Leave this field empty to keep it unchanged.
  • Generated from the tenant. For security, only the Microsoft endpoint belonging to this tenant is accepted.
  • The delegated scopes required for calendar, Teams, and SharePoint are completed when saving and requested on every Entra sign-in.
  • Register this complete address exactly as shown as a web redirect URI.
  • This address only skips automatic Entra redirection. It does not work when local agent login is disabled.

Scope and boundaries

Scope and boundaries

The module extends Qisutu for a defined purpose while remaining separate from the Qisutu core.

  • Installation through Administration → AddOns
  • Independent ZIP module with no changes to Qisutu core files
  • 11 fully supported interface languages
  • AGPL-3.0-or-later

Questions about this AddOn?

We can help with selection, setup, and productive use.