Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

  1. Dynamics 365 On-premise base URL.

  2. ADFS base URL.

  3. ADFS oAuth2 client id.

...

(Connector is using Authorization code grant flow for connection)

Create oAuth2 client in ADFS using PowerShell commands

1. Register new client application(s) to use with Connector

To register a new oAuth2 client You need to create separate clients for Connector G-Suite add-on, run the following from the Administrative PowerShell prompt -

...

languagepowershell

...

and Automatic sync, depends on what you are using. Use the following re-direct URI for each clients.

...

To register a new oAuth2 client for Automatic Sync, run the following from the Administrative PowerShell prompt -

Code Block
languagepowershell
Add-ADFSClient -Name "oAuth2 Client forname iSynchere" -ClientId "some- uid here" -RedirectUri "https://isync.ienterprises.com/oauth2client/mscrm.phpre-direct uri here"

** Replace “some - uid“ with a client id. Use this client id in connection settings.

...

https://docs.microsoft.com/en-us/powershell/module/adfs/add-adfsclient

2. Grant Application permission to

...

CRM

For Windows Server 2016 and later :-

Grant Application permission to ADFS clients with the required scope(s), by running the following from Administrative PowerShell prompt -

Code Block
languagepowershell
Grant-AdfsApplicationPermission -ClientRoleIdentifier "clientid" -ServerRoleIdentifier "Dynamics URLURI" -ScopeNames openid, user_impersonation

Microsoft doc link :

https://docs.microsoft.com/en-us/powershell/module/adfs/grant-adfsapplicationpermission

For ADFS 3.0 on Windows Server 2012 R2 :-

  1. Goto ADFS Management

  2. Expand ADFS > Trust Relationships > Relying Party Trusts

  3. Use the Add Relying Party Trust Wizard

  4. Create a Relying party manually and Permit all users to access this relying party

Obtaining refresh tokens from ADFS

Refresh tokens are needed from ADFS to keep the login active. To set them you’d run the following from an Administrative PowerShell prompt -

...