Dynamics 365 (On-Premise)
This page explains how to configure a connection to an on-premise instance of Microsoft Dynamics 365 using Active Directory Federation Services and OAuth2 authentication.
These instructions apply specifically to internet-facing deployments (IFD), where both Dynamics 365 and ADFS are accessible externally. You’ll set up an OAuth client, grant the required permissions, and configure token settings to enable secure communication between the connector and your Dynamics environment.
This instruction is for internet facing installation. Your Dynamics and ADFS need to be publicly reachable, otherwise, the connector won’t work.
Prerequisites
To connect to Dynamics 365 On-premise installation, you will need to provide:
- Dynamics 365 On-premise base URL
- ADFS base URL
- ADFS oAuth2 client id
Create oAuth2 client in ADFS using PowerShell
1. Register new client application to use with Unaric Sidebar
You need to create separate clients for Unaric Sidebar add-on and Automatic sync, depends on what you are using.
To register a new oAuth2 client, run the following from the Administrative PowerShell prompt :
Add-ADFSClient -Name "oAuth2 Client name here" -ClientId "some uid here" -RedirectUri "re-direct uri here"Replace some uid with your client id. Use this client id in connection settings.
For more information on this process, see Microsoft documentation, Add-AdfsClient.
2. Grant application permission to CRM
Grant Application permission to ADFS clients with the required scope(s), by running the following from Administrative PowerShell prompt :
Grant-AdfsApplicationPermission -ClientRoleIdentifier "clientid" -ServerRoleIdentifier "Dynamics URI" -ScopeNames openid, user_impersonationFor more information on this process, see Microsoft documentation, Grant-AdfsApplicationPermission.
Obtain refresh tokens from ADFS
Refresh tokens are needed from ADFS to keep the login active. To set them, run the following from an Administrative PowerShell prompt:
Set-AdfsRelyingPartyTrust -TargetName "RPT Name" -IssueOAuthRefreshTokensTo AllDevices
Set-AdfsRelyingPartyTrust -TargetName "RPT Name" -TokenLifetime 10
Set-AdfsProperties -SSOLifetime 20160This would issue access tokens with a lifetime of 10 minutes and refresh tokens to all clients with a lifetime of 14 days.
For more information on this process, see Microsoft documentation, Set-AdfsRelyingPartyTrust and Set-AdfsRelyingPartyTrust.