OAuth settings

Prerequisite: To configure the OAuth settings, you must have the OAUTH2ADM access code.

About WorkZone OAuth

OAuth is an open standard authorization framework that allows users to grant applications temporary and limited access to their user account information on other websites without distributing sensitive information such as passwords. The OAuth framework delegates user authentication to the service that hosts the user account, and authorizes third-party applications to access the user account and is used by large internet-based companies to enable users to share information with third party applications or websites.

OAuth and WorkZone

The OAuth framework can be used in WorkZone to improve security and facilitate delegation of authorization between the WorkZone Content Server and external components or systems such as mobile devices or the WorkZone ClientWorkZone Content Server web application without exposing passwords or using "on-behalf-of" features.

The OAuth settings page

The OAuth settings page has two tabs:

  • Clients: Here you can set up, maintain and delete OAuth settings for WorkZone integrated tools (clients), such as WorkZone Configuration Tool, WorkZone PDF Crawler and so on.
  • Integrations: Here you can configure access to WorkZone by the third-party apps registered in your Azure Tenant. By default, there are nine built-in integration accounts that you can configure for different third-party apps.

The Clients tab

Here you can view, create, edit and delete OAuth settings for WorkZone integrated tools.

Create, edit or delete OAuth settings

The Integrations tab

Use the Integrations tab to configure access to WorkZone by the third-party apps registered in your Azure Tenant. By default, there are nine built-in integration accounts that you can configure for different third-party apps.

Set up a new third-party integration account

  1. In WorkZone Configurator, click GlobalOAuth Settings > Integrations.
  2. On the OAuth settings page, hover the mouse over the integration account you want to edit, and click in the menu.
  3. In the [%account_name] - OAuth Integration settings form, fill in and edit the needed settings:
    • Account ID: This field is read-only.
    • Object ID: Enter the object ID of your Enterprise app registration in Azure.
    • Security code: From the dropdown, select the security code.
    • Department: Select a department from the dropdown, if this integration should only apply to a specific department within your organization.
    • Allow to act on behalf of other users: Turn on to allow this account to act on behalf of other users.
    • Departmental access: Turn on to give the integration account full access to any items within the selected Authority.
    • Global access: Enable to give the integration account full access to any items in the whole organization.
  4. Click Save.