SC 300T00A ENU PowerPoint 04
SC 300T00A ENU PowerPoint 04
SC 300T00A ENU PowerPoint 04
• What is an app?
• Plan and design the integration of enterprise apps for single sign-on (SSO)
• Implement, and monitor the integration of enterprise apps
• Implement app registrations
3 Describe what happens and the primary settings when an app is registered.
Configure the scope permissions and API permissions available to the app.
Code running
In a virtual machine
Function, App Service,
or Logic App
Code running
In a virtual machine
Customer 1
Tenant Service
Principal
Service
Customer 1 Principal
Tenant
• App name
• What the user sees
• Account types that can log into the app
• Single or multitenant
• URI
• Where application is running after
authentication
A security tool placed between a cloud service (like Microsoft implementation of a CASB service to
an app) and the user to interject enterprise security protect data, services, and applications with
policies before the cloud-based resource is enterprise policies. It provides supplemental
accessed. reporting and analytics services.
Microsoft
Defender
for Cloud
Apps
• Cloud Discovery
Find apps
• Sanctioning
Allow/deny apps
• Connectors
Extend protection into
the app
with APIs
• Conditional Access –
Set access requirements
• Policy control – Define
user behavior with apps
© Copyright Microsoft Corporation. All rights reserved.
Set up Cloud Discovery with Microsoft Defender for Cloud
Apps
• Defender for Cloud Apps requests the user list. The first time the request is done, it may take some time
until the scan completes. After the user scan is over, Defender for Cloud Apps moves on to activities and
files. As soon as the scan starts, some activities will be available in Defender for Cloud Apps.
• After completion of the user request, Defender for Cloud Apps periodically scans users, groups, activities,
and files. All activities will be available after the first full scan.
• Data scan―scanning of unstructured data using two processes―periodically (every 12 hours) and in
real-time scan (triggered each time a change is detected).
• Data governance―ability to quarantine files, including files in trash, and overwrite files.
Add an app to
your Microsoft
Entra tenant:
Add an Enterprise
app and assign
your administrator
account
© Copyright Microsoft Corporation. All rights reserved. © Copyright Microsoft Corporation. All rights reserved.
Design and implement app
management roles
Includes the ability to manage all aspects of Includes the ability to manage most aspects of
enterprise applications; including registrations enterprise applications, but excludes the ability
and application proxy settings. to manage application proxy settings.
© Copyright Microsoft Corporation. All rights reserved. © Copyright Microsoft Corporation. All rights reserved.
Configure preintegrated
(gallery) SaaS apps
© Copyright Microsoft Corporation. All rights reserved. © Copyright Microsoft Corporation. All rights reserved.
Implement and monitor the
integration of enterprise
apps for SSO
• Before an application can access the organization’s data, a user must grant the application permissions to
do so
• All users can consent to applications for permissions that do not require administrator consent
• By allowing users to grant apps access to data, users can acquire useful applications and be productive
Disable user Users can consent Users can consent Custom app
consent to apps from to all apps consent policy
Users cannot grant verified publishers Users can consent to Users can consent to
permissions to Users can only consent any permission. custom app
applications. Requires to apps that were consent policies.
an admin to grant. published by a
verified publisher.
Application Proxy is a feature of Microsoft Entra ID that enables users to access on-
premises web applications from a remote client.
Interactive guide
Enable integrated
windows
authentication to on-
premises applications
with Microsoft Entra
application proxy.
Visit this
interactive guide
in Microsoft Learn
© Copyright Microsoft Corporation. All rights reserved. © Copyright Microsoft Corporation. All rights reserved.
Integrate custom SaaS apps
for SSO
Interactive guide
Integrate an
application in
Microsoft Entra ID
providing the single
sign-on experience
Visit this
interactive guide
© Copyright Microsoft Corporation. All rights reserved. © Copyright Microsoft Corporation. All rights reserved.
Implement application user
provisioning
© Copyright Microsoft Corporation. All rights reserved. © Copyright Microsoft Corporation. All rights reserved.
Implement app registrations
Accounts in this directory All user and guest accounts in your directory can use your
Single tenant
only application or API.
All users and guests with a work or school account from
Accounts in any Microsoft
Multi-tenant Microsoft can use your application or API. This includes
Entra directory
schools and businesses that use Microsoft 365.
All users with a work, school, or personal Microsoft account
Accounts in any Microsoft
can use your application or API. It includes schools and
Entra directory and personal
Multi-tenant businesses that use Microsoft 365, as well as personal
Microsoft accounts (such as
accounts that are used to sign into services like Xbox
Skype, Xbox, Outlook.com)
and Skype.
DEMO
3 Add credentials
6 Add a scope
There are two ways to declare app roles by using the Microsoft Entra admin center:
• App roles UI
– Found on the App Registration/App roles
DEMO
© Copyright Microsoft Corporation. All rights reserved. © Copyright Microsoft Corporation. All rights reserved.
Summary
© Copyright Microsoft Corporation. All rights reserved. © Copyright Microsoft Corporation. All rights reserved.
Labs
© Copyright Microsoft Corporation. All rights reserved. © Copyright Microsoft Corporation. All rights reserved.
Learning path recap
In this learning path, you learned how to: