Step by Step Guide to Configure Azure AD as an OAuth/OpenId Connect Server for Drupal

Step 1: Steps to configure Azure B2C as oauth provider

  • Go to https://portal.azure.com and sign up/login in your Azure portal.
  • Create a new tenant: You can do so by following the below given steps:
    1.  Click on Create a resource.
    2. Search for Azure Active Directory B2C.
    3. Select and scroll down unti you find an option to Create a new B2C Tenant without     Subscription.
    4. Click on it to create a new tenant.
  • Select Create a new Azure AD B2C Tenant and enter the following data in their respective text fields:
    1. Organization name
    2. Initial Domain name
    3. Select your Country or Region
  • Click on the Save button to create a new tenant.
  • Click on the following message to manage your directory: “Click here, to manage your new directory”
  • Click on Applications and then on Add option to add a new application.
  • Enter a name for your application under the Name text field.
  • Select Yes from the options in front of Web APP/Web API and Yes from options in front of Allow Implicit Flow. Also, copy the Redirect/Callback URL from the miniOrange OAuth Client plugin and save it under the Reply URL textbox.
  • Click on the Create button to create your application. (Refer to the image below)
  • Please Note: Your Callback/ Redirect URl should be https only and not http .

  • Click on the Applications option under the Manage Menu in the left navigation bar and you will find your application listed there. Click on your application
  • Copy your Application ID and save it under your Client ID textbox in your miniOrange OAuth Client plugin. Then, click on the Keys option to generate a key
  • Click on the Generate Key option and save it with a name. Click on the Save option and it will generate a random string which you will store as Client secret in your miniOrange OAuth Client plugin.
  • Now, go to your dashboard and go to Azure Active Directory Properties. Copy the Directory ID and substitute this value whenever you need to enter Tenant ID in endpoint URLs in the miniOrange OAuth Client(given below).
  • Authorize Endpoint : https://login.microsoftonline.com/[tenant-id]/oauth2/v2.0/authorize
    Access Token Endpoint : https://login.microsoftonline.com/[tenant-id]/oauth2/token
    Get User Info Endpoint : https://graph.microsoft.com/v1.0/me
  • You have successfully completed your Azure AD B2C OAuth Server side configurations.

Step 2: Configure Drupal as OAuth Client

  • Click on the link here to install the miniOrange OAuth Client module.
  • Scroll down and download plugin by clicking in the zip option under Downloads.
  • Login in your Drupal site’s admin console and click onModules from the top navigation bar.
  • Select the Instal new module option to install a new module/plugin on your Drupal site.
  • Upload the downloaded zip file of the plugin and click on the Install button to continue.
  • Click on Modules from the top navigation bar again and scroll down till you find miniOrange OAuth 2.0 Client. Click on the checkbox next to it and click on the Save Configuration button to enable the module.
  • Now next to the miniOrange OAuth 2.0 Client, you will find an option to configure the plugin. Click on it to continue to the configuration page of the module.
  • Register/ Login to your miniOrange account.
  • Click on the Configure OAuth tab and select your OAuth Provider from the Select Application dropdown. In case you do not find your OAuth Provider listed in the dropdown, please select Custom OAuth Provider and continue.
  • Enter your OAuth provider information in their respective fields and click on the Save button to continue. Also, copy the Callback/Redirect URL and save it on your OAuth Provider.
  • Now click on the Test Configuration option. This Test Configuration link will give you the list of the attributes that are coming from your OAuth Provider.
  • Copy the email and the name attributes and save them under the Attribute & Role Mapping tab in the Email Attribute and Name Attribute text field respectively. Please note that this step is mandatory for your login to work. Click on the Save button on the bottom of the page to save your attribute configurations.
  • Now logout and go to your Drupal site’s login page, you will automatically find a Login withyour OAuth Provider link there. If you want to add your login link to other pages as well, please follow the steps given in the below image:
  • If you want to check out our complete list of features and our various licensing plans, you can go to the Licensing Plan tab in the plugin.
  • In case you are facing an issue or if you have any questions in mind, you can reach out to us but submitting a query in the Support tab or by sending us a mail at info@xecurify.com .
  • Congratulations, you have successfully configured the miniOrange Drupal OAuth CLient module.