

Test with a small set of users and groups before rolling out to everyone. If the only role available on the application is the default access role, you can update the application manifest to add additional roles. Users with the Default Access role are excluded from provisioning and will be marked as not effectively entitled in the provisioning logs. When assigning users and groups to TeamViewer, you must select a role other than Default Access. If you choose to scope who will be provisioned based solely on attributes of the user or group, you can use a scoping filter as described here. If you choose to scope who will be provisioned to your app based on assignment, you can use the following steps to assign users and groups to the application. The Azure AD provisioning service allows you to scope who will be provisioned based on assignment to the application and or based on attributes of the user / group.

Define who will be in scope for provisioning Learn more about adding an application from the gallery here. However it is recommended that you create a separate app when testing out the integration initially. If you have previously setup TeamViewer for SSO you can use the same application. Add TeamViewer from the Azure AD application galleryĪdd TeamViewer from the Azure AD application gallery to start managing provisioning to TeamViewer. This value will be entered in the Secret Token field of your TeamViewer application in the Azure portal. Click on the Save button.Ĭopy the Token and click OK. Configure TeamViewer to support provisioning with Azure AD

Application Administrator, Cloud Application administrator, Application Owner, or Global Administrator).

