Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

  1. Define API App Role

    Before external systems can be granted access, an App Role must be defined in the API App Registration.

    Go to:

    • Microsoft Entra IDApp registrations

    • Open EGU.PartnerPortal.ApiService

    Navigate to App roles → Create app role.

    Configure the role:

    FieldValue
    Display nameExternal System Access
    Allowed member typesApplications
    ValueExternalSystem.Access
    DescriptionAllows external systems to access turnaround report data

    Save the role.

  2. Create External System App Registration

    • Create a separate application registration for each external company.

      Go to:

      • Microsoft Entra IDApp registrations

      • Select New registration

      Configuration:

      SettingValue
      Name{CompanyName}-PartnerPortal-Access
      Supported account typesAccounts in this organizational directory only
      Redirect URILeave blank
  3. Generate Client Secret

      1. Open the newly created PartnerPortal-External-{CompanyName} app-PartnerPortal-Access app.

      2. Navigate to Certificates & secrets.

      3. Click New client secret.

      4. Copy the secret value immediately and store it securely.

      ⚠️ The secret value cannot be viewed again after creation.

      Never commit secrets to source control.

  4. Assign Permissions

    • Add permission: EGU.PartnerPortal.ApiService
    • Select: ExternalSystem.Access
    • Grant admin consent

  5. Company Mapping (API side configuration)

    {
      "ExternalCompanies": {
        "Ravdex": {
          "AppId": "1f018c7511a51e47-2ea9cee5-4d464bb6-a4f1882b-a45d2d47d043a669dfaf1cb8",
          "CompanyNumber": "YOUR_COMPANY_NUMBER",
          "Name": "Ravdex"
        }
      }
    }