Skip to main content
Biamp Cornerstone

Register oAuth with EWS for Microsoft 365 and Evoko Home

This article is for new installs of Evoko Home only. If you have an existing install that is using Microsoft 365 with basic authentication and want to change to modern authentication, please see this article instead

To use oAuth with EWS for Office 365, you have to register a custom application in the Azure Active Directory for the Office 365 tenant.  When installing Evoko Home you will need both the Tenant ID and Application ID from Azure to complete the configuration with O365. 

Please follow the guide below to gather/create that information.

 

1: Preparations

Make sure you run the latest version of Evoko Home.  You must be running v2.6 or newer of Evoko Home in order to successfully connect to O365 using oAuth.  All supported Evoko Home versions can be found here: https://download-liso.evoko.se/ 

If you haven't done so already, please visit the Booking system preparation guide for Office 365 to create your service account and get the Application Impersonation management scope applied to it.  When you have done that, please continue below.

 

 

2: Configure the Azure App and collect Tenant/Application ID.

Find the tenant name or ID for your Office 365 Tenant in Azure Active Directory

You can use either tenant name or ID in the Evoko Home configuration wizard. Note this down for use in the Evoko Home configuration wizard.

Alternative 1: Use the tenant ID

  1. Navigate to the Azure Active Directory Admin Center by going here and logging in with your Admin Account: https://aad.portal.azure.com/ 

  2. Navigate to Azure Active Directory in left panel and click Properties under Manage section.

  3. Open notepad/text edit on your computer and write down the Tennant ID for your organization. We will need this ID in a later step when we connect Evoko Home to O365.   It is shown here in this screenshot:

clipboard_e4d51f77bddfbe29e6f32a1936738e7b5.png

 

 

3: Register App for use with oAuth in EWS

1. Navigate to App Registrations to open the App registrations page.

clipboard_ed32ece39d07258c0fe92f8281cc83080.png

2. Click the New Registration button.

clipboard_ec55d3e7577d462663c44eafe6ebc6849.png

3. Fill in the Name add a Web Redirect URL for https://localhost  We recommend the naming scheme to identify it is for the Evoko Home Application so it can easily be referenced in the future.  Once complete - click Register

clipboard_ea2644ff629a897ab01cd152efaa33fe1.png

4. Once the application is created, you can see the details page. Add this Application (client) ID to your notepad as we will need this too during the Evoko Home configuration wizard that will be needed in a later step.

clipboard_e5a13fea996326ed7bc104ed0d8cbd22d.png

5. Navigate to Authentication.

clipboard_e1673bdda4a5d9e56b1bcb9e6031259ce.png

6Scroll down and enable Allow Public Client Flows by selecting Yes. 

clipboard_edcb286976a68aebea2ef911e17760166.png

7. Press Save

8Navigate to API Permissions 

clipboard_ee1046161a2d593477e253f273709d142.png

9. Click Add a permission button.

clipboard_e8f6d877cb23ba42f8115357c2c849c48.png

10. Click on APIs my organization uses. Search for "Office" and Press "Office 365 Exchange Online

clipboard_edc624d056690db4520940390f7c6ea6e.png

11. In the permission selection page, select “Delegated Permission”, which will open the list of permissions for Delegated access. Expand “EWS” and select “EWS.AccessAsUser.All”. Click the Add permission button.

clipboard_e73587dd0bb28bb7d878fbae73f414bd3.png

12. You should now see the application permissions.

clipboard_efb5f7244f498b9ee17c95f34e47f4a57.png

13. The last step is to Grant Admin Consent for your Organization.

clipboard_ecfc427d0553723cff596a35c3841eb57.png

14. Press Yes

clipboard_e6c22c4b23b583053ba3d57d7bb772f10.png

15. You should now see the permissions granted.

clipboard_e4a9647a87ba135b2ab33898159c83507.png

 

 

4: Login using OAuth in the Evoko Home Configuration Wizard

 

Note: If you are already using Evoko Home with Basic authentication, please log on to Evoko Home, go to Global Settings, and click the Change button under your booking system credentials in the top right corner of the global settings. Then, continue from here.
  1. Select “Modern (OAuth)” from the drop down on the credentials page.
  2. Copy and Paste the Tenant ID and Application ID from the previous steps for the appropriate fields and click “Login”

clipboard_e26a97ed6434cb25140d17ad51b099e23.png

3. The wizard will now wait for you to log in using the provided URL (https://microsoft.com/devicelogin) and provided code.

clipboard_ea272b1b084802e6e0821f2f0a974ef9d.png

4. On the provided URL, enter the code from the wizard and click Next

clipboard_ea77b1761609747cef00ca37bbf78957a.png

Notice the application name you configured for this and log in with your service account and password.

clipboard_ebd40f41cd74e899ab139e82586013fff.png

5. Once you sign in using service account credential, it will prompt for the consent dialog. This happens only for first login to this application, subsequent login remembers the consent.  Review the dialog and click "Accept".

clipboard_ea756ce39f05f0485ab031eaa99a66e1e.png

6. You should now see the following screen which informs you to safely close this window.

clipboard_e2e45a7d14b71439926da467fe0a10523.png

7. Switch back to the Evoko Home Setup Wizard and continue to the next step.  Your screen should look like this:

clipboard_edc2233851cad389fef4da1f33e1f414e.png

8. The Default Port for Evoko Home is 3002 - if you do not wish to change that or upload any of your own certificates, press next.

9. Here you will prompted to enter an NTP Server Address for Evoko Home to use.  We recommend using 0.pool.ntp.org if your organization allows access to it.  Some larger organizations may have their own internal NTP server.  Press next when ready.

clipboard_ebb04870d5bf56af713bb6896642cae2c.png

10. Here you will be prompted to accept the Evoko Terms of Service.   Press Accept!

11. Here on the final page you will be presented with the Username and Password that will be used to log into Evoko Home as an Admin.  Its very important that you copy this information to notepad before hitting finish as the text will disappear!

clipboard_ef6a5c4663746efd2eecaab0644b01409.png

12. Once the information is copied to notepad Press Finish

13. If you did not upload your own Security Certificates during the wizard you may get a message indicating that your connection is not private.  If you do get this message press Proceed to Localhost.

clipboard_e526f22b6cfa4f5ca2e9e7e9a46de87b2.png

14. You will want to log in with the Username and Password that Evoko Home prompted you at the end of the wizard (this should be the information you copied to the notepad).

clipboard_e9f7936a62a33aa1947cf0efa856d4a75.png

15, Success! You have now completed the setup with Modern Auth and you can now move through Setting Up Your Global Organization in Evoko Home!  This will let you add locations, and room resource accounts from O365!

clipboard_eb9f1fb6251dbb5ddd78eb84420a10258.png

 

  • Was this article helpful?