Skip to content
Bpanda
English
Esc
↑↓navigate↵open⌘Jpreview
On this page

Set up Microsoft Entra ID

Set up Bpanda as an enterprise app in Microsoft Entra ID and provision users — with a pointer to Microsoft's own instructions.

With Microsoft Entra ID as your identity provider, your users sign in to Bpanda with their company account; users and groups reach us from your tenant via provisioning. Microsoft itself describes the steps on the Entra side — this article tells you which groups to create for it and what happens afterwards on the Bpanda side.

Prerequisites

You have the Global Administrator role in your tenant. Only with that role can the Bpanda Enterprise App be added.

Important: When you add the app, you confirm the admin consent for Bpanda. In doing so, you agree that MID GmbH and Microsoft may receive and process the user data.

How to proceed

  1. Add the Bpanda Enterprise App in your tenant and set up provisioning: mode Automatic, plus the Tenant URL and the Secret Token, verified with Test Connection. Microsoft describes both steps in Configure Bpanda for automatic user provisioning with Microsoft Entra ID.
  2. Under Users and Groups, select the users and groups to be synchronized. The next section covers which groups lend themselves to this.
  3. Start provisioning and check that it is actually running.
  4. Let us know so that we can trigger the transfer into the account management (internally: CAMP) right away. We then assign the licenses.

Note: Immediately after you add the app, you are redirected to the Bpanda page. You cannot log in there yet — first the users have to be synchronized and their licenses assigned.

Groups in Entra ID and roles in Bpanda

Create these groups in Entra ID and provide them. The permissions behind the Bpanda roles are described in Roles and permissions.

Group name in Entra ID Role in Bpanda
Bpanda-Account-Manager Manages users and groups in the account management
Bpanda-BPM-Manager BPM Manager of the Process Space
Bpanda-Process-Designer Designer
Bpanda-User Participant in the Process Space
Bpanda-Consumer Participant with read-only rights

How long synchronization takes

Entra ID → every 40 minutes → Keycloak → once per night → account management

Synchronization from Entra ID to Keycloak happens every 40 minutes, from Keycloak into the account management only once per night. Hence the last step above: the first time, we trigger the run manually once you let us know. After that, as an Account Manager you can trigger it yourself at any time, with Update Users and Groups in the ⋮ menu of the user list, see Creating and Managing Account Users.

If the two states have drifted apart nonetheless — for example because the Secret Token had expired for a while — then Check user synchronization with Entra ID will help.

Was this page helpful?