User Provisioning

Prerequisite for Azure User Provisioning


This feature will help administrators register their user's security key on their account on their behalf, so the user can immediately use the security key to access their account without any registration efforts.To use this feature, the following conditions should be met:

1

Temporary access pass should be enabled for your Azure AD workspace for all users or at least for the ones you want to register on their behalf. You can find more details on this here.

2

The target user should be imported from Azure AD, using Import from Azure AD option in Users & Security Keys, or be synced with Azure AD, so that there is an equivalent user in your Azure AD.

3

When an IDmelon administrator tries to import users from Azure AD for the first time, they will be asked to log in to Azure to grant necessary permissions. The admin who is doing so cannot provision themself in IDmelon, as Azure prevents this action. For example, if [email protected] is used to import users from Azure AD, this user can't be provisioned from IDmelon Panel.

4

The target user should be assigned a passkey security key, but it is not necessary to be activated in IDmelon Admin Panel.

Azure User Provisioning Steps


1

Choose a user you have imported from Azure AD >> Click Action >> User Provisioning.

2

A wizard will ask you to select a service and say that OBR will be enabled, and as long as it is so, any credential registration will take place on the selected user's security key. Select Microsoft Azure AD and follow the instructions.

3

The admin may want to register security key on behalf of a user in some circumstances. To do this, the admin can use the OBR procedure which can be done starting from pairing tool by doing the following steps:

Prerequisite for OBR


User must install IDmelon Authenticator app on their smartphone.

User security key status must be active in administration panel (Admin must add the user to the panel via invitation email and user must accept the invitation).

OBR steps


1

Choose a user you have imported from Azure AD >> Click Action >> User Provisioning.

2

Select Other Devices to start OBR by other kinds of devices and click on Start OBR.

3

IDmelon Pairing Tool will open and has to be Ready for on behalf registration.

3

Now administrators can register account for their specific user.

Note: If a user's security key type is local, administrator must contact the user to approve the permissions that will be shown on the user's smartphone to complete the OBR steps.