- Go to Entra ID App Registrations
- Click on New Registration.
- Fill in the following fields:
- Name: Enter a name for your app registration (e.g., "EasyChatbot")
- Supported account types: Select "Accounts in this organizational directory only (Single tenant)"
- Redirect URI: Select "Web" and enter the redirect URI for your web app (e.g.,
https://<your-web-app-name>.azurewebsites.net/.auth/login/aad/callback)
- Click on Register.
- After the registration is complete, you will be redirected to the app registration's overview page.
- Go to the Authentication tab in the left sidebar.
- Under Select the tokens you want to configure, just select
ID tokens (used for implicit and hybrid flows). - Disable the App Instance Proprty Lock
- Under Select the tokens you want to configure, just select
- Go to the API permissions tab in the left sidebar.
- Click on Add a permission.
- Select Microsoft Graph.
- Select Delegated permissions.
- Search for and select the following permissions:
openidprofileemail
- Click on Add permissions.
- Click on Grant admin consent for to grant the permissions.
- Go to the Expose an API tab in the left sidebar.
- Click on Add a scope.
- Enter the following details:
- Scope name:
user_impersonation - Who can consent?:
Admins and users - Admin consent display name:
Access EasyChatbot - Admin consent description:
Allows the app to access EasyChatbot on behalf of the signed-in user - State:
Enabled
- Scope name:
- Click on Add scope.
- Go to the Certificates & secrets tab in the left sidebar.
- Click on New client secret.
- Enter a description for the client secret (e.g., "EasyChatbot Secret").
- Select an expiration period (e.g., "In 6 months").
- Click on Add.
- Copy the generated client secret value and store it securely (you will need it later).