Optional restriction to a defined Entra group
Qisutu AddOn
Entra ID – Customer Users
Customer users sign in to the customer portal through Entra ID and can be imported and updated automatically.
Module overview
Entra ID – Customer Users
The key use cases and capabilities at a glance.
Individual and bulk assignment of imported users to Qisutu customers
No portal access without exactly one active customer assignment
Configure OIDC login, automatic contact provisioning, customer assignment and Microsoft Graph synchronization.
This address is generated from the HTTP type, FQDN and web path in system settings. Microsoft Entra ID requires HTTPS.
Newly imported contacts initially have no customer assignment. Customer portal login is allowed only after exactly one active customer has been assigned.
At most 50 contacts are loaded per page. Customer assignments can be saved for one or several selected contacts together.
Capabilities in detail
Capabilities in detail
The following capabilities are part of this independent Qisutu module.
- Register this complete address exactly as shown as a web redirect URI.
- This URI belongs to contact login. The OAuth2 redirect URI of a Microsoft 365 mailbox is a different endpoint and must not be used here. A separate app registration for contacts is recommended.
- Default: openid profile email. The module adds the required scopes when login group enforcement is enabled.
- Newly imported contacts initially have no customer assignment. Customer portal login is allowed only after exactly one active customer has been assigned.
- Optional. Only direct or transitive members of this Entra group may sign in.
- Optional. Without a group ID, all users in the tenant are read.
- At most 50 contacts are loaded per page. Customer assignments can be saved for one or several selected contacts together.
- Synchronization is performed by the Qisutu daemon; a separate cron job is not required.
How the module works
How the module works
The typical workflow is integrated directly into day-to-day work in Qisutu.
- 01
Optional restriction to a defined Entra group
- 02
Individual and bulk assignment of imported users to Qisutu customers
- 03
No portal access without exactly one active customer assignment
- 04
Register this complete address exactly as shown as a web redirect URI.
- 05
This URI belongs to contact login. The OAuth2 redirect URI of a Microsoft 365 mailbox is a different endpoint and must not be used here. A separate app registration for contacts is recommended.
- 06
Default: openid profile email. The module adds the required scopes when login group enforcement is enabled.
Requirements
Requirements
These technical and organizational requirements are relevant for deployment.
- Qisutu 1.0.1+
- HTTPS
- Microsoft Entra app registration
- Client secret
- OpenSSL
- Qisutu daemon
Administration and operation
Administration and operation
Configuration, background processing, and control remain centralized in Qisutu.
- The client secret is stored encrypted and is never displayed again.
- Tenant GUID or a domain such as company.onmicrosoft.com; common, organizations and consumers are rejected.
- Client ID of the Microsoft Entra application registration.
- Generated from the tenant. For security, only the Microsoft endpoint belonging to this tenant is accepted.
- Optional. Only direct or transitive members of this Entra group may sign in.
- Optional. Without a group ID, all users in the tenant are read.
- At most 50 contacts are loaded per page. Customer assignments can be saved for one or several selected contacts together.
- Synchronization is performed by the Qisutu daemon; a separate cron job is not required.
Security and control
Security and control
Credentials, permissions, and automated decisions are handled transparently and securely.
- A secret is stored. Leave this field empty to keep it unchanged.
- Generated from the tenant. For security, only the Microsoft endpoint belonging to this tenant is accepted.
- Newly imported contacts initially have no customer assignment. Customer portal login is allowed only after exactly one active customer has been assigned.
- This URI belongs to contact login. The OAuth2 redirect URI of a Microsoft 365 mailbox is a different endpoint and must not be used here. A separate app registration for contacts is recommended.
Scope and boundaries
Scope and boundaries
The module extends Qisutu for a defined purpose while remaining separate from the Qisutu core.
- Installation through Administration → AddOns
- Independent ZIP module with no changes to Qisutu core files
- 11 fully supported interface languages
- AGPL-3.0-or-later
Questions about this AddOn?