Configure service principal connection account in Microsoft 365 extension
Notes and limitations
Starting Cayosoft Administrator v13.2.1, new installations allow only the service principal connection account.
Adding new platforms in the Microsoft 365 extension may require additional permissions. When you enable additional platforms, a message is prompted to rerun the service principal configuration and grant additional permissions. To learn more about the required permissions, refer to the following article: Entra ID application permissions required by Cayosoft Administrator Service.
-
Review the list of known limitations of using a service principal connection account:
Creation of Family Groups is not supported.
The New User | Office 365 OneDrive post creation tasks web action does not support the service principal connection account.
-
In the Archive web action for Teams, the Set permissions for team members to read-only on the SharePoint Online checkbox is not supported by the service principal connection account. If you select the checkbox, the following error is prompted:
Operation 'Archive' did not complete in time.
Please refresh your view and try again later. The Clone Cloud Group web action does not support groups that have an
assignedLabelsattribute. If a group has the attribute assigned, attempting to clone it will fail. You can exclude the attribute from the list of copied Graph attributes in the Additional Graph attributes setting of the web action.
Prerequisites
Cayosoft Administrator v13.2.1 or newer.
A Global Administrator user to register the enterprise app.
-
Optional: A certificate issued by a trusted authority.
IMPORTANT: It is not recommended to use self-signed certificates in production environments.
Paths
New installation
Starting v13.2.1, new installations of Cayosoft Administrator only allow the use of service principal app-based connection accounts. Follow the setup steps listed below to set up your Microsoft 365 extension.
Upgrade
When you upgrade to Cayosoft Administrator v13.2.1 or later, there are two options proceed with in your installation:
Keep the user-based account.
Migrate to the service principal app-based connection account.
If you decide to migrate, the migration process follows the setup process for new installations and does not require additional steps. Review the setup steps for the app-based connection account in new installations.
IMPORTANT: Migrating to the service principal connection account does not remove or disable the prior user-based connection account. The user account and its credentials remain active in your tenant. Review your organization's security policies and, if the account is no longer needed, manage it manually (e.g., reset the password, remove assigned licenses and roles, or delete the account).
Set up service principal authentication and connection account
Depending on your scenario, navigate to the Microsoft 365 extension settings.
In the initial configuration wizard, enable the Microsoft 365 extension and navigate to the extension configuration page.
After the initial setup, navigate to Configuration > Connected system extensions > Microsoft 365 in the Cayosoft Administrator Console.
To start the configuration wizard, click Configure service principal.
-
In the first window, select a certificate to authenticate Cayosoft Administrator in your tenant.
To generate a self-signed certificate, select Self-signed certificate and click Generate. A thumbprint value will be prompted in the corresponding box.
To use a certificate issued by a trusted authority, select Custom certificate and click Select to choose a custom certificate.
IMPORTANT: It is not recommended to use self-signed certificates in production environments.
Click Next to proceed. Review the window; click Next to prompt a sign-in pop-up.
-
Specify credentials of the Global Administrator account to grant consent and create a Cayosoft Administrator enterprise app. After you enter the credentials, click Accept to complete the wizard.
IMPORTANT: It is required to grant consent on behalf of your account, not the organization the account belongs to.
Cayosoft Administrator may take some time to connect to the tenant and configure the app. When the wizard completes, the thumbprint value will be specified in the Certificate for Microsoft 365 applications field; the Service principal field will switch to Configured.
NOTE: By default, only Microsoft Graph and Exchange Online applications are included in the scope. To expand the scope, navigate to the Microsoft 365 extension settings and enable settings Connect to Microsoft Teams and Connect to SharePoint Online. Newly added platforms may request you to grant additional permissions to manage data; refer to the list of required permissions in the following article: Entra ID application permissions required by Cayosoft Administrator Service.
Comments
0 comments
Please sign in to leave a comment.