Enterprise Application in Microsoft Entra ID
MyDesk is onboarded as an Enterprise Application in the customer's Microsoft Entra ID tenant. This gives full control over what rights MyDesk has and enables SSO, MFA and conditional access via the customer's existing identity policies.
App Registration and rights
During onboarding, an App Registration is created in the customer's Entra ID tenant with the specific Microsoft Graph rights needed to deliver the service. MyDesk applies the least privilege principle and only requests the rights that are strictly necessary.
Typical Graph entitlements include:
- User.Read - Reading user information
- Calendars.ReadWrite - Calendar integration for meeting room booking
- Place.Read.All - Reading room information
- Mail.Send - Sending notifications (optional)
Certificate-based integration
MyDesk supports certificate-based authentication for the Microsoft Graph API, eliminating the need for client secrets and increasing security. Certificates are regularly rotated and securely managed.
The onboarding process
The onboarding process is structured and documented:
- Technical kick-off with the customer's IT department
- Creating Enterprise Application in Entra ID
- Configuring SSO and MFA
- Integration and access management testing
- Approval and go-live
- Documentation and handover
Enterprise Setup
- Enterprise Application in Entra ID
- App Registration with least privilege
- Certificate-based integration
- SSO and MFA via Entra ID
- Documented onboarding process
- Technical support during onboarding