Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...


Rw ui textbox macro
typenote

The MCA feature included in 3.24.0 Release. Check Give your Consent to interworks.cloud platform for more details.


Microsoft is introducing a new security framework to give CSP Partners and Control Panel Vendors (CPVs) a more secure application model through multi-tenant application authentication capability. This model helps to further secure partner credentials and reduce many potential financial risks caused by unauthorized access.

With this improvement, we will comply and take all actions so as to enhance the security of our platform application. What will change is that you will no longer need to setup in your BSS the credentials of your global CSP admin user. There will be a different approach where we (the control panel) we will ask from you (the CSP) your consent for calling MS API on your behalf without asking you to share with us your credentials. We have registered interworks.cloud platform as a Vendor application in Microsoft systems and we will ask from all our customers to give to our application the consent to call Microsoft APIs on their behalf. 


rw-ui-tabs-macro
ui

rw-tab
titleFAQ

Q: What preparation is required from my part for giving my consent?
A: In order to give your consent to interworks.cloud platform, you will need to have a global admin user with MFA enabled. You have already setup a global admin user since it is required from our current implementation. So, the only preparation from your part is to enable for your global admin user the MFA option.

For enabling the MFA for your admin user, you should:

  1. Login to https://portal.azure.com and navigate to "Azure Active Directory > Users"
  2. Select the option "Multi-Factor Authentication"
    Image Added

  3. Define the service settings
  4. Select
you
  1. your admin user and press "Enable"
    Image Added

Check please this page https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-mfa-getstarted for more details.


Q: How can I give my consent to interworks.cloud platform?
A: We will introduce in Microsoft Cloud Services settings a new field called "Status" that will include the consent functionality:

  1. For giving your consent you should press the button "Authenticate Instance"

    Image Added
  2. This button will redirect you to Microsoft login page. You must
login
  1. log in using a global admin user with the MFA option enabled.
  2. A pop-up will be displayed which will ask you to give access to interworks.cloud platform

    Image Added
  3. After giving your consent, you will be directed back to BSS. The status will turn to "Instance is authenticated" and the consent process will be completed
    Image Added

Q: How much time do I have for giving my consent?
A
: You should have completed the consent process until 3rd of February 2019. From 4th of February, Microsoft will enforce the new security model and you will no longer be able to provision any Microsoft services from our platform if you haven't given your consent to our platform. Our platform will support both functionalities until 3rd of February, meaning that if you haven't given your consent we will

continueusing

continue using the credentials of your global admin user for authentication purposes.

Q: Do I need to keep the Web App I had registered for interworks.cloud platform?
A:
Yes, you need to keep it because we are using this web app to call Microsoft APIs that do not require consent. Such APIs are for example the ones we are calling to receive the list of the available offerings during the "Get Services Definitions" action.

Q: What will happen with the credentials of the CSP global admin user I have registered in interworks.cloud platform?
A: These credentials will be removed from our platform after 4th of February 2019. With the release of the consent process, the fields "Native App ID", "Username" and "Password" will no longer be compulsory and later on, will be removed (we will make sure to purge their values too) from our system.