Skip to content

Connecting Your Own IDP (Microsoft Entra)

This article describes how to connect your own identity provider (IDP) to the noris Enterprise Cloud (nEC), using Microsoft Entra as an example.

The following steps are covered:

  • Creating and configuring an enterprise app in Microsoft Entra
  • nEC (VMware Cloud Director) SAML configuration
  • Importing metadata (Entra enterprise app & VMware Cloud Director)
  • Assigning users/groups to roles in VMware Cloud Director (nEC)
  • Role: at least Cloud Application Administrator or Application Administrator.
  • License: assigning groups to an enterprise app requires one of the following licenses:
    • Microsoft Entra Suite
    • Microsoft Entra ID Governance
    • Microsoft Entra ID P2
  • Multi-factor authentication (MFA): to use MFA, it must be enabled in Microsoft Entra, this is strongly recommended. This can generally be configured in two different ways:
    • Security defaults: Security defaults are a feature for paid Microsoft 365 and Office 365 or trial subscriptions created after October 21, 2019. These subscriptions have default security settings enabled. Starting with the first sign-in after security defaults are enabled, users have 14 days to register with the Microsoft Authenticator app for MFA. After this period, the user can only sign in once MFA registration is complete. For tenants created earlier, security defaults must be enabled manually.

      Enabling security defaults in Microsoft Entra

    • Conditional access policies: Granular configuration is possible via conditional access policies, which let you define different policies based on various criteria. Documentation: learn.microsoft.com

Link to VMware’s vendor documentation: docs.vmware.com

Creating and configuring an enterprise app in Microsoft Entra

Section titled “Creating and configuring an enterprise app in Microsoft Entra”
  • Sign in to the Entra ID admin center.
  • Create an enterprise app.

Creating an enterprise app in the Entra ID admin center

  • Create your own application.
  • Assign a name.

Naming the custom application

  • Add users or groups to the app.

Adding users or groups to the enterprise app

  • Configure Single Sign-On.
  • Select SAML.

Selecting SAML as the Single Sign-On method

SAML configuration in the enterprise app, step 1

SAML configuration in the enterprise app, step 2

  • Adjust or add attributes & claims: “Add new Claim”.

Adding a new claim to the attributes

  • For “group” only: “Add a group claim”.

Adding a group claim

nEC (VMware Cloud Director) SAML configuration

Section titled “nEC (VMware Cloud Director) SAML configuration”
  • Basic IDP configuration in VMware Cloud Director.

Basic IDP configuration in VMware Cloud Director

  • Add the entity ID.

Adding the entity ID in VMware Cloud Director

Importing metadata (Entra enterprise app & VMware Cloud Director)

Section titled “Importing metadata (Entra enterprise app & VMware Cloud Director)”
  • Download the metadata from the Entra enterprise app.

Downloading metadata from the Entra enterprise app

  • Upload the downloaded metadata from the Entra enterprise app into VMware Cloud Director.

Uploading metadata into VMware Cloud Director

Confirming the metadata upload in VMware Cloud Director

  • Download the metadata from VMware Cloud Director.

Downloading metadata from VMware Cloud Director

  • Upload the downloaded metadata from VMware Cloud Director into the Entra enterprise app.

Uploading metadata into the Entra enterprise app

Confirming the metadata upload in the Entra enterprise app

Assigning users/groups to roles in VMware Cloud Director (nEC)

Section titled “Assigning users/groups to roles in VMware Cloud Director (nEC)”

Option 1: Assigning individual Microsoft Entra users in VMware Cloud Director

Section titled “Option 1: Assigning individual Microsoft Entra users in VMware Cloud Director”
  • Enter the Microsoft Entra user’s name under “new user”.

Entering a Microsoft Entra user in VMware Cloud Director

Option 2: Assigning Microsoft Entra groups in VMware Cloud Director

Section titled “Option 2: Assigning Microsoft Entra groups in VMware Cloud Director”
  • Copy the object ID of the Entra group.

Copying the object ID of the Entra group

  • In VMware Cloud Director, use “Import Groups” and enter the object ID from Microsoft Entra.

Importing groups in VMware Cloud Director

  • Afterwards, the group name can also be entered in the description.

Entering the group name in the description