Back to all AddOnsEntra ID – Customer Users

Qisutu AddOn

Entra ID – Customer Users

Customer users sign in to the customer portal through Entra ID and can be imported and updated automatically.

Version1.0.1
CompatibilityQisutu 1.0.1 or newer
Languages11
LicenseAGPL-3.0-or-later

Module overview

Entra ID – Customer Users

The key use cases and capabilities at a glance.

01

Optional restriction to a defined Entra group

02

Individual and bulk assignment of imported users to Qisutu customers

03

No portal access without exactly one active customer assignment

04

Configure OIDC login, automatic contact provisioning, customer assignment and Microsoft Graph synchronization.

05

This address is generated from the HTTP type, FQDN and web path in system settings. Microsoft Entra ID requires HTTPS.

06

Newly imported contacts initially have no customer assignment. Customer portal login is allowed only after exactly one active customer has been assigned.

07

At most 50 contacts are loaded per page. Customer assignments can be saved for one or several selected contacts together.

Capabilities in detail

Capabilities in detail

The following capabilities are part of this independent Qisutu module.

  • Register this complete address exactly as shown as a web redirect URI.
  • This URI belongs to contact login. The OAuth2 redirect URI of a Microsoft 365 mailbox is a different endpoint and must not be used here. A separate app registration for contacts is recommended.
  • Default: openid profile email. The module adds the required scopes when login group enforcement is enabled.
  • Newly imported contacts initially have no customer assignment. Customer portal login is allowed only after exactly one active customer has been assigned.
  • Optional. Only direct or transitive members of this Entra group may sign in.
  • Optional. Without a group ID, all users in the tenant are read.
  • At most 50 contacts are loaded per page. Customer assignments can be saved for one or several selected contacts together.
  • Synchronization is performed by the Qisutu daemon; a separate cron job is not required.

How the module works

How the module works

The typical workflow is integrated directly into day-to-day work in Qisutu.

  1. 01

    Optional restriction to a defined Entra group

  2. 02

    Individual and bulk assignment of imported users to Qisutu customers

  3. 03

    No portal access without exactly one active customer assignment

  4. 04

    Register this complete address exactly as shown as a web redirect URI.

  5. 05

    This URI belongs to contact login. The OAuth2 redirect URI of a Microsoft 365 mailbox is a different endpoint and must not be used here. A separate app registration for contacts is recommended.

  6. 06

    Default: openid profile email. The module adds the required scopes when login group enforcement is enabled.

Requirements

Requirements

These technical and organizational requirements are relevant for deployment.

  • Qisutu 1.0.1+
  • HTTPS
  • Microsoft Entra app registration
  • Client secret
  • OpenSSL
  • Qisutu daemon

Administration and operation

Administration and operation

Configuration, background processing, and control remain centralized in Qisutu.

  • The client secret is stored encrypted and is never displayed again.
  • Tenant GUID or a domain such as company.onmicrosoft.com; common, organizations and consumers are rejected.
  • Client ID of the Microsoft Entra application registration.
  • Generated from the tenant. For security, only the Microsoft endpoint belonging to this tenant is accepted.
  • Optional. Only direct or transitive members of this Entra group may sign in.
  • Optional. Without a group ID, all users in the tenant are read.
  • At most 50 contacts are loaded per page. Customer assignments can be saved for one or several selected contacts together.
  • Synchronization is performed by the Qisutu daemon; a separate cron job is not required.

Security and control

Security and control

Credentials, permissions, and automated decisions are handled transparently and securely.

  • A secret is stored. Leave this field empty to keep it unchanged.
  • Generated from the tenant. For security, only the Microsoft endpoint belonging to this tenant is accepted.
  • Newly imported contacts initially have no customer assignment. Customer portal login is allowed only after exactly one active customer has been assigned.
  • This URI belongs to contact login. The OAuth2 redirect URI of a Microsoft 365 mailbox is a different endpoint and must not be used here. A separate app registration for contacts is recommended.

Scope and boundaries

Scope and boundaries

The module extends Qisutu for a defined purpose while remaining separate from the Qisutu core.

  • Installation through Administration → AddOns
  • Independent ZIP module with no changes to Qisutu core files
  • 11 fully supported interface languages
  • AGPL-3.0-or-later

Questions about this AddOn?

We can help with selection, setup, and productive use.