Microsoft allows 3rd party developers to create applications that can be easily integrated to their own solutions and use Microsoft identity platform to provide secure sign-in and authorization. These 3rd party applications are registered in Microsoft’s platform. Optimaze Worksenseapplication
(App)
is registered under
Rapal’s Azure AD
our Entra ID tenant (Developer’s tenant).
You can read more information about Microsoft 365 Integrated Apps from Microsoft’s documentation here and about Microsoft identity platform here.
Why install Worksense as an
Azure
Entra ID Enterprise Application?
When
Optimaze
Worksense is installed as an
Azure
Entra ID Enterprise Application your organization’s employees can:
Sign in to Worksense with their personal Microsoft work accounts
Use the booking feature to quickly find and book meeting spaces
Global
Admin
administrator
Why a Global
Admin
administrator is needed in the installation?
In Microsoft 365 only
a ’Global admin’
a Global administratorcan install
‘Azure
Entra ID Enterprise
Applications’
Applications. This prevents any user from granting apps access to sensitive parts of your configuration. You can read more from Microsoft documentation about installing an Integrated App, here.
EG Worksense does not need to
work ’Global admin’
work Global administrator privileges, it is only required in the installation. Also, Worksense does not gain the abilities of
a ’Global admin’
a Global administrator, similar to how creating a new user mailbox as
the ‘Global admin’
the Global administrator does not transfer power to the user account simply because an admin is needed to complete the set up step.
Required
Permissions
permissions by Worksense
Technically
Optimaze
EG Worksenseis split into two separate
Azure
Entra ID Enterprise
applications
Applications,
‘Optimaze Worksense’
Optimaze Worksenseand
‘Optimaze
Optimaze Worksense Calendar
Intergration’
Integration. The first one handles only the Single Sign
in
-On and second
on
one only reading and writing calendars in mailbox. If you use only the integration for Single
Sing
Sign-On, you do not need to install the
‘Optimaze
Optimaze Worksense Calendar
Integration’ app
Integration app.
Permissions required for using Single Sign-On
Permission
Type
Description
Worksense feature using permission
Sign in and read user profile
Delegated
Allows users to sign-in to the app, and allows the app to read the profile of signed-in users. It also allows the app to read basic company information of signed-in users.
User’s name and email are saved into EG Worksense. These are always read when the user signs in and will be updated to EG Worksense if they change.
Sign in with Microsoft
,
The
(the permission is not used if you do not enable the feature
.
)
Permissions required for integrating Microsoft 365 bookable resources with EG Worksense
Permission
Type
Description
Worksense feature using permission
Read and write calendars in all mailboxes
Application
Allows the app to create, read, update, and delete events of all calendars without a signed-in user.
EG Worksense needs read and write permissions to all calendars in order to use the booking features from lobby screens as lobby screen is not an actual user.
Booking features
,
The
(the permission is not used if you do not enable the feature
.
)
Note
Optimaze
EG Worksense has access to all calendars in your organization’s
M365
Microsoft 365 account with
the ‘Read
the Read and write calendars in all
mailboxes’
mailboxesapplication level permission. More information regarding the permissions can be found on
the Worksense end. It has to be done from the Microsoft 365 side. If you need to restrict
use
usage of certain calendars, you can scope the application permissions to specific
exchange online
Exchange Online mailboxes. See Microsoft instructions here.
Info
Through
Optimaze
EG Worksense, users can access only those calendars that have been entered into the system. See instruction herehow the calendars are added. Also the booking feature has to be enabled.
Installing
Optimaze
EG Worksense as an Enterprise Application
Info
Optimaze
An EG Worksense account can be linked to only one
Azure AD
Entra ID tenant at a time.
Info
You can install EG Worksense manually
Optimaze Worksense
in
Azure AD
Entra ID. This requires
work by
assistance from our support and must be agreed separately.