Versions Compared
Key
- This line was added.
- This line was removed.
- Formatting was changed.
| Table of Contents |
|---|
This page describes how to install
EG Worksense to your
organization’s Microsoft 365 account as
an Entra ID Enterprise Application.
| Table of Contents |
|---|
General
Microsoft Entra ID Enterprise Applications
Microsoft allows 3rd party developers to create applications that can be easily integrated to their own solutions and use Microsoft identity platform to provide secure sign-in and authorization. These 3rd party applications are registered in Microsoft’s platform. Optimaze Worksense application
is registered under
our Entra ID tenant (Developer’s tenant).
You can read more information about
Microsoft 365 Integrated Apps from Microsoft’s
Entra ID Enterprise Application?
When Worksense is installed as an
Entra ID Enterprise Application your organization’s employees can:
Sign in to Worksense with their personal Microsoft work accounts
Use the booking feature to quickly find and book meeting spaces
Global
administrator
Why a Global
administrator is needed in the installation?
In
Microsoft 365 only
a Global administrator can install
Entra ID Enterprise
Applications. This prevents any user from granting apps access to sensitive parts of your configuration. You can read more from Microsoft documentation about installing an Integrated App, here.
EG Worksense does not need to
work Global administrator privileges, it is only required in the installation. Also, Worksense does not gain the abilities of
a Global administrator, similar to how creating a new user mailbox as
the Global administrator does not transfer power to the user account simply because an admin is needed to complete the set up step.
Required
permissions by Worksense
Technically EG Worksense is split into two separate Entra ID Enterprise Applications, Optimaze Worksense and Optimaze Worksense Calendar Integration. The first one handles only the Single Sign-On and second one only reading and writing calendars in mailbox. If you use only the integration for Single Sign-On, you do not need to install the Optimaze Worksense Calendar Integration app.
Permissions required for using Single Sign-On
Permission | Type | Description | Worksense feature using permission |
|---|---|---|---|
Sign in and read user profile | Delegated | Allows users to sign-in to the app, and allows the app to read the profile of signed-in users. It also allows the app to read basic company information of signed-in users. User’s name and email are saved into |
EG Worksense. These are always read when the user signs in and will be updated to EG Worksense if they change. | Sign in with Microsoft |
(the permission is not used if you do not enable the feature |
) |
Permissions required for integrating Microsoft 365 bookable resources with EG Worksense
Permission | Type | Description | Worksense feature using permission |
|---|---|---|---|
Read and write calendars in all mailboxes | Application | Allows the app to create, read, update, and delete events of all calendars without a signed-in user. EG Worksense needs read and write permissions to all calendars in order to use the booking features from lobby screens as lobby screen is not an actual user. | Booking features |
(the permission is not used if you do not enable the feature |
) |
| Note |
|---|
EG Worksense has access to all calendars in your organization’s |
Microsoft 365 account with |
the Read and write calendars in all |
mailboxes application level permission. More information regarding the permissions can be found on |
Microsoft Graph documentation, here. |
We cannot restrict the access from |
the Worksense end |
. It has to be |
done from the Microsoft |
365 side. If you |
need to restrict |
usage of certain calendars, you can |
scope the application permissions to specific |
Exchange Online mailboxes. See Microsoft instructions here. |
| Info |
|---|
Through |
EG Worksense, users can access only those calendars that have been entered into the system. |
See |
instruction here how the calendars are added. Also the booking feature has to |
be enabled |
. |
Installing
EG Worksense as an Enterprise Application
| Info |
|---|
An EG Worksense account can be linked to only one |
Entra ID tenant at a time. |
| Info |
|---|
You can install EG Worksense manually |
in |
Entra ID. This requires |
assistance from our support and must be agreed separately. When setting up EG Worksense the redirect |
URI is: https://worksense.optimaze.net/signin-oidc and you need to provide us your |
Entra ID tenant ID. |
You must have
a Global adminrole in
Microsoft 365 to continue
and Administrator
role in
EG Worksense.
If you do not have an account with the
Global admin role you need to contact your organization’s IT department.1.
- Log in
- to EG Worksense on your web browser
- Click Administration
- If the
- navigation bar option is not visible
- , contact your organization’s
- EG Worksense main user or Submit a
- support request to find out who in your organization to contact
3. Click the ‘Connect’ button
- Click Microsoft 365
- Click the Connect button. This will start Microsoft’s Oauth flow to install the app.
- Enter
- your Global admin
- account credentials
- If you get “Need admin approval”, it means the account you used is not
- a Global Admin in Microsoft 365. You need to log in using a different account or have
- your IT department temporarily change your user permissions in
- Microsoft 365.
- EG Worksense will ask for permissions to access your organization’s
- Microsoft 365 data.
- Take your time to
- fully understand them
- what permissions are required
- . Why does
- EG Worksense need the permissions? For certain features to work
- , EG Worksense requires
- these permissions. You can see for more details
- above under the ‘Required Permissions by Worksense’ section.
- Click Accept to proceed
- You are good to go!
| Info |
|---|
You can check that Optimaze Worksense is visible from your M365 account’s app overview, here |
- Now you can:
Image Removed
Image Removed