Knowledge Base

Microsoft Tenant Authentication (5.0)

Overview

This document provides a step-by-step guide on Microsoft Tenant Authentication.

The instructions cover setting up tenant authentication to ensure secure access and management of Microsoft services. This guide is intended for administrators managing Microsoft tenants.

Tenant authentication is crucial for controlling access and ensuring security within Microsoft services.

Prerequisites

  1. An account on the Microsoft Partner Center as a Reseller.

  2. The user account for the Microsoft Partner Center must have at least Privileged Role Administrator permissions to authenticate the token correctly.

  3. The Privileged Role Administrator account should also be assigned the Admin Agent role in the Partner Center.

Use the eu.cloudmore.com address for EU customers, or the us.cloudmore.com address for US customers.

Steps to Authenticate Microsoft Tenant

  1. Navigate to Authentication - Go to Services > Microsoft 365 and open the Authentication tab.

  2. Enter Microsoft ID - Enter your Microsoft ID in the Microsoft authentication card. The ID connects this service to the vendor tenant used for provisioning and billing.

  3. Update consent - Click Update consent. You will be redirected to the Microsoft Partner Center. Sign in with a Privileged Role Administrator account and grant consent for the process.

  4. Automatic token refresh - The token will automatically refresh each night.

  5. Test the token - Run a Microsoft Billing Report to test the API connection to the Microsoft Partner Center.

You can find your Microsoft ID in the Microsoft Partner Center, under Home > My Profile (Account Settings) > Microsoft Entra ID profile > Microsoft ID.

As a Broker admin, you can enter the Microsoft ID only during the initial setup. Once it is set, you cannot change it. If the Microsoft ID needs to be changed later, contact Cloudmore, as only a Host admin can change it.

[SCREENSHOT] The Microsoft 365 service, Authentication tab selected.

Token status

The Microsoft authentication card shows the state of the token.

Field

What it shows

Microsoft ID

The vendor tenant this service is connected to. Set once during the initial setup.

Status

Whether the token is currently valid.

Expires

How long the token remains valid, with the expiry date.

[SCREENSHOT] The Microsoft authentication card, a valid token with its expiry date.

Cloudmore might require a manual token update in case of permission changes for accessing the Partner Center data on your behalf. This might happen when Microsoft changes the permission requirements for using the API endpoints or accessing customer data.

Buttons on this tab

  • Update consent button - Sends you to the Microsoft Partner Center to sign in and grant consent, and refreshes the token.

Authentication per service

Each Microsoft service is authenticated separately. Services > Microsoft 365 and Services > Microsoft Azure each have their own Authentication tab.

By following this guide, administrators can effectively set up and manage Microsoft Tenant Authentication within Cloudmore. Ensuring proper authentication is crucial for maintaining secure access and control over Microsoft services.

This step is essential for linking tenants, enabling them to access CSP services in Cloudmore.