OAuth2 Setup

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • Slammers
    Trusted Tech

    100+ Posts
    • Feb 2019
    • 187

    #1

    [Misc] OAuth2 Setup

    Hi.

    Has anyone configured a 4series or new MZ series device to scan to O365 with OAuth2?
    There is not much documentation on how it is done and I have done some testing of my own and I have successfully managed to make it work using a O365 account that has MFA enabled.

    Steps I have carried out:

    Logged in to Entra ID as Domain Admin.
    Created a new Application called "OAuth2 Scan to Email" and copied down of the Application (Client) ID and the Directory (Tenant) ID - These are not required from what I have seen during the setup on a MZ2501ci

    image.png


    I then created API permissons to allow SMTP Send and applied admin consent via Graph.

    image.png

    Generated client secret for the App and noted this down. - Again, I did not have to use these details during the copier configuration.

    image.png

    I then copied down the Application Endpoint URL: - We need this later to enter into Command Centre.

    image.png

    With these details ready I then logged into the copiers Command Centre and entered the follwing info:

    Auth Protocvol: OAuth 2

    Proxy Auth: Enter in the email account detail that will be performing the send. it must be part of the Entra Organization that the application was configured for.

    Once the saved, click the button that says "Authorize"

    image.png

    Copy the code shown, then click the link.

    image.png
    Paste the code in the box in the new browser window that has opened and follow the instructions to authenticate your Kyocera Device with your Exchnage account.

    image.png

    Once that is complete, head back to the copier interface - One final step is needed. You must update the OAuth 2 - Microsoft Exchange settings to point to the Application Endpoint URL we generated inside Entra at the start:

    image.png

    Enter the URL in the box - We copied this from Entra earlier on:
    image.png

    image.png

    Save and test.

    If anyone has other steps or pitfalls they have experienced, please let me know.
    Last edited by Slammers; 2 days ago.
  • ThisPete
    Snr/troubleshoot/network

    Site Contributor
    250+ Posts
    • Jun 2014
    • 279

    #2
    Cracking write up Slammers!!

    Thanks for taking the time, and for sharing it.

    Comment

    • Slammers
      Trusted Tech

      100+ Posts
      • Feb 2019
      • 187

      #3
      Quick update,

      You may not even need to create the Entra App mentioned in the first parts and I have may have overcomplicated the setup.
      I have noticed that it will automatically create an application in Entra under the user ID that you use called Exchange Online Client for Device:

      image.png


      If you click in on this it should be auto filled out with the Kyocera Homepage etc like this:

      image.png

      Do with this information what you wish.
      Attached Files

      Comment

      • Larhal
        Retired

        Site Contributor
        VIP Subscriber
        500+ Posts
        • May 2013
        • 654

        #4
        Thank you for your diligence in wanting to help fellow techs.
        Larhal

        Retired

        If all else fails read the Service Manual!

        If that fails, meet me at the pub and we will discuss it.

        Comment

        • Slammers
          Trusted Tech

          100+ Posts
          • Feb 2019
          • 187

          #5
          Originally posted by ThisPete
          Cracking write up Slammers!!

          Thanks for taking the time, and for sharing it.
          No problem! I was making my own SOP as we had some clients require this setup this week, looks like the rollout by Microsoft has begun. Thought I would share what I experienced as there was no detail for the Kyoceras.

          I did have to edit my post, turns out you don't need to mess about making your own connector app, the copier creates an app and registers itself under the scanner user in Entra for you. I left all the info in though as it may help in other situations.

          Comment

          • tmaged
            Owner/Service Manager

            Site Contributor
            VIP Subscriber
            1,000+ Posts
            • Oct 2008
            • 1902

            #6
            Thanks for posting. It will save some time for us !
            Hope that helps !
            -Tony
            www.dtios.com
            Become a fan on Facebook

            Comment

            • ThisPete
              Snr/troubleshoot/network

              Site Contributor
              250+ Posts
              • Jun 2014
              • 279

              #7
              Originally posted by Slammers

              No problem! I was making my own SOP....
              Whoa, Whoa, Whoa buddy, please don't get technical.. it's 18.58 here now, well past work time now.. 😁


              And as I didn't get home until 18.24, I'm still trying to sort out my 'too much blood in my alcohol ' emergency.... 😉

              Comment

              Working...