Deployment

Automatic App Registration

MyQ can automatically create and configure the Microsoft Entra enterprise application required by the following integrations:

  • Microsoft Entra ID and Microsoft Graph

  • OneDrive for Business

  • SharePoint Online

Automatic authorization is the recommended setup method when the administrator has the required Microsoft Entra permissions. MyQ creates the enterprise application, configures its credentials and permissions, and obtains administrator consent through a guided authorization process.

Exchange Online and Universal Print require manual application registration. For these and other manual setup scenarios, see Microsoft Entra Application Reference for MyQ Integrations.

Before You Begin

To complete automatic authorization, you need:

  • a Microsoft Entra tenant

  • access to the relevant integration settings in MyQ

  • a Microsoft Entra account with the required administrator role

Required Administrator Roles

  • Application Administrator or Cloud Application Administrator can create the service principal in the tenant.

  • Global Administrator is required to grant administrator consent.

  • Therefore, a Global Administrator can complete the entire authorization process without involving another administrator.

The administrator permissions used during setup are separate from the permissions that the resulting enterprise application uses at runtime.

How Automatic Authorization Works

Automatic authorization consists of three stages:

  1. The administrator signs in to Microsoft Entra ID, and MyQ creates the service principal in the customer’s tenant.

  2. The administrator authorizes MyQ to configure the application.

  3. MyQ assigns the runtime permissions required by the selected integration, and the administrator grants consent.

The service principal is displayed under Enterprise applications in the Microsoft Entra admin center.

The exact runtime permissions depend on the integrations enabled for the connection. For a complete list, see Microsoft Entra Application Reference for MyQ Integrations.

Application Credentials

Client secrets created by MyQ during automatic authorization are valid for two years.

When a secret is within 30 days of expiration, MyQ reports a Health Check warning. Use Re-authorize before the secret expires to create a new secret for the existing connection.

Credentials created directly for service principals are not displayed in the Microsoft Entra admin center. They can be managed through Microsoft Graph or PowerShell.

Re-authorize a Connection

Use Re-authorize in MyQ to repeat the Microsoft authorization process for an existing connection.

Reauthorization can:

  • complete administrator consent that was not granted during the initial setup

  • create a new client secret

  • recreate a deleted enterprise application

  • change the connection between automatic and manual configuration

Reauthorization updates the existing enterprise application when it is still present. It does not normally create a duplicate.

Recreate a Deleted Enterprise Application

If the enterprise application has been deleted from Microsoft Entra ID, use Re-authorize in MyQ. The authorization process creates the service principal again and restores the connection.

Revoke Access

To revoke access for an automatically configured connection, delete its enterprise application in Microsoft Entra ID.

This removes the service principal and its credentials from the tenant. If the connection is later reauthorized in MyQ, MyQ creates the service principal again.