Before you begin
            There are two prerequisites to complete before configuring the Identity Provider in
                    
ExtremeCloud
                Universal ZTNA.
                    - Create ClientID,
                            Client
                            Secret, and Discovery URL
                        in Entra ID under App Registration. Save a copy of each to use in this
                        procedure. 
- Your organization's AD-synced
                        users must have administrative privileges in Entra ID so Microsoft can
                        authorize the user during log in. To set the permission, navigate to
                            .
About this task
 Follow this procedure to configure
            a Microsoft Active Directory - OpenID Connect Identity Provider.
            
        
        Procedure
- 
                Select Onboarding.
                The welcome window
                    displays. 
- 
                Select Secure Hybrid
                        Access [Secure Application
                        Access or Secure Network
                        Access].
                The Identity Provider
                    window displays with ExtremeCloud
                    Universal ZTNAselected. 
- 
                Select Microsoft Active
                        Directory and Continue.
                Microsoft Active
                        Directory window displays. 
- 
                [Default] Confirm that OpenID Connect is
                    selected for the Single
                        Sign-on Method.
            
- 
                Follow the Setup Redirect
                        URIs instructions.
            
- 
                Enter the data you created in
                    Entra ID into the following fields: 
                
                    - 
                        Enter the Client
                            ID.
                    
- 
                        Enter the Client
                                Secret.
                    
- 
                        Enter the Discovery
                                URL.
                    
 
- Optional: 
                Select All Domains or Custom  and enter the
                    domain.
                If you select Custom, fill in the
                    approved domains. Applicable for network and application access. 
- 
                Select Secure Network
                    Access.
                
                     Note    Specify the  Client ID, Client
                            Secret and  Discovery URL. 
 
- 
                Select Validate
                        Information.
                 A message in the upper
                    right corner confirms the validation test passed. 
- 
                Select Update.
                
                    Update Identity
                        Provider
                    pop-up window displays. This message cautions you that the
                    Identity Provider change logs out current users. 
- 
                If you decide to continue,
                    select Confirm.
            
- 
                Select Next.
                The Onboarding - Access
                        Groups window displays. 
- 
                Configure Access Groups.
            
- 
                Configure Resources.
            
- 
                Configure Applications and Application Groups.
                 You can skip this step if you
                    are using Secure Network Access. 
- 
                Configure Policies.
            
Results
            Your onboarding is complete. Your users, applications, and devices can now access the
                network securely.