--- title: "Set up Azure AD Admin Center" slug: "set-up-azure-ad-admin-center" tags: ["IT Pro", "Azure"] updated: 2024-02-21T13:08:20Z published: 2024-02-21T13:08:20Z canonical: "help.lanteria.com/set-up-azure-ad-admin-center" --- > ## Documentation Index > Fetch the complete documentation index at: https://help.lanteria.com/llms.txt > Use this file to discover all available pages before exploring further. # Create application for integration When [setting up the Exchange integration in Lanteria HR](/v1/docs/exchange-integration-setup-in-lanteria-hr), the authentication method is to be selected. The users can choose between the **Basic** (login and password) and **Modern** (OAuth) authentication. Microsoft announced deprecation of basic authentication to connect to their services including Exchange Web Service. Thus, it is recommended to choose **Modern** and configure the OAuth authentication method. The OAuth configuration steps in the Microsoft Entra ID (previously known as Azure Active Directory) admin center are as follows: 1. Sign in to the Azure portal, browse to **Microsoft Entra ID** > **App registrations**, and then click **New registration** to create a new application registration. ![](https://cdn.document360.io/c315c68d-2799-4fcc-9a39-084315b58f14/Images/Documentation/image-1699870087326.png) 2. In the **Register an application** window, in the **Name** field, specify the name of the application. 3. Under the **Supported Account Types** field, select **Accounts in this organizational directory only (Default Directory only - Single tenant)**. 4. Under **Redirect URI**, select **Public client (mobile & desktop)** and set the value to **https://login.microsoftonline.com/common/oauth2/nativeclient**. ![](https://cdn.document360.io/c315c68d-2799-4fcc-9a39-084315b58f14/Images/Documentation/image-1699870360338.png) 5. Click **Register**. From the page that opens, copy the values of the **Application (client) ID** and **Directory (tenant) ID** and save them. These will be used when [setting up the Lanteria HR](/v1/docs/exchange-integration-setup-in-lanteria-hr) part of integration. ![](https://cdn.document360.io/c315c68d-2799-4fcc-9a39-084315b58f14/Images/Documentation/image-1699870537242.png) 6. Under **Manage**, click **Manifest**. 7. Locate the **requiredResourceAccess** property in the manifest (use Ctrl+F to find a key), and set - "resourceAppId" to "00000002-0000-0ff1-ce00-000000000000 - Under **resourceAccess**, change "id" to "dc890d15-9560-4a4c-9b7f-a736ec74ec40" and "type" to "Role". After the changes, the manifest must look as follows: ![](https://cdn.document360.io/c315c68d-2799-4fcc-9a39-084315b58f14/Images/Documentation/image-1699870734354.png) 8. Click **Save**. 9. Under **Manage**, click **API permissions**. 10. Make sure that the **full_access_as_app** permission is listed. ![](https://cdn.document360.io/c315c68d-2799-4fcc-9a39-084315b58f14/Images/Documentation/image-1699870816343.png) 11. Select **Grant admin consent for app** and provide confirmation. 12. Under **Manage**, click **Certificates and Secrets**, and then add a new client secret, which will be used when you fill in the **Azure AD Connection Settings** field while configuring [Exchange Integration Settings in Lanteria HR](/v1/docs/exchange-integration-setup-in-lanteria-hr). 13. In the **Description** field, type the secret description. 14. Set **Expires to 730 days (24 months)**. 15. Click **Add**. **![](https://cdn.document360.io/c315c68d-2799-4fcc-9a39-084315b58f14/Images/Documentation/image-1699871201043.png)** 16. Once a new client secret is created, please copy its value and save somewhere, it will be used when [configuring Lanteria HR](/v1/docs/exchange-integration-setup-in-lanteria-hr). ![](https://cdn.document360.io/c315c68d-2799-4fcc-9a39-084315b58f14/Images/Documentation/image-1699871239881.png) *Note* *The portal* ***Never Expire*** *option for the* ***Client Secret Expiry*** *was removed in April 2021.* *Please set up a reminder to create a new client secret and update Lanteria HR settings before it expires.* Alternatively, you can create a client secret which almost never expires. ## **Create a Never Expiring Client Secret with PowerShell** After creating an app registration, you can create a client secret with PowerShell and set the unlimited expiration date. 1. Open Windows PowerShell (Terminal) as administrator and run the following command to install the Microsoft Graph PowerShell module. ```powershell Install-Module Microsoft.Graph.Applications -Scope CurrentUser ``` 2. Copy the following script and paste it into any text editor. Don’t forget to replace the **Object ID** you copied earlier (when creating an app registration at step 5 of the current article). ```powershell # Connect to Microsoft Graph Connect-MgGraph -Scopes 'Application.ReadWrite.All' # Parameters $AppObjectId = "xxxxxxxx-xxxxxx-xxxx-xxxx-xxxxxxxxx" $AppSecretDescription = "Never expired client secret" $AppYears = "50" $PasswordCred = @{    displayName = $AppSecretDescription    endDateTime = (Get-Date).AddYears($AppYears) } # Add App Client Secret - Valid for 50 years (change to 999 for unlimited years) $Secret = Add-MgApplicationPassword -ApplicationId $AppObjectId -PasswordCredential $PasswordCred # Write Client Secret value $Secret | Format-List ``` 3. Your code is ready, copy and paste it into the PowerShell windows, then sign in with your global administrator credentials. 4. Select **Consent on behalf of your organization** and click **Accept**. 5. The PowerShell output shows the **SecretText** (сlient secret value). Copy the **SecretText** (client secret value) and save it. ```powershell PS C:\> $Secret | Format-List CustomKeyIdentifier  : DisplayName          : Never expired client secret EndDateTime          : 1/19/2074 3:00:18 AM Hint                 : tFs KeyId                : 9fffb36d-788d-437f-b10b-f986e5fd0a47 SecretText           : tFs8Q~VJBO8Yrgq6gFxexUfyLRWuIfAXin7jYbKl StartDateTime        : 1/19/2024 3:00:20 AM AdditionalProperties : {[@odata.context,                       https://graph.microsoft.com/v1.0/$metadata#microsoft.graph....]} ``` > [!NOTE] > *Note* > > *Client secret values cannot be viewed except immediately after creation. Remember to save the secret before you close the PowerShell window.* 6. Go to the Microsoft Entra ID admin center to verify the secret has been created. You can see that your new сlient secret has been added and expires after 50 years. You successfully configured a client secret for an application in Microsoft Entra ID that never expires.