This guide is for IT Administrators and Tenant Admins. It explains how to connect your organization's Azure Active Directory (Azure AD) to the Future Ordering Navigator platform for Single Sign-On (SSO) and how to manage ongoing user access requests.
Initial Setup (Enrolling a New Azure AD)
Perform these steps only once to establish the connection between your organization and Future Ordering.
-
Submit a Configuration Request:
Send an email to support@futureordering.com.
Subject: "Request to Connect Azure AD to Navigator - [Your Company Name]"
-
Required Details:
-
Tenant ID: Your Azure AD Tenant ID.
Tenant ID can be collected using this web-tool: https://gettenantpartitionweb.azurewebsites.net/
Admin Username: The email address of the specific user who will act as the first "Tenant Admin" in Navigator (responsible for approving other users) and Approving connection between the Azure AD and Navigator.
-
-
Initial Login & Consent:
Once Support confirms the configuration, the designated Admin must log in to Navigator.
Consent: You will see a Microsoft prompt asking for permission. You must check "Consent on behalf of your organization".
Result: This registers the "Future Ordering Authentication" app in your Active Directory and allows your users to attempt to log in.
How Users Request Access
Navigator operates on an "Ask and Approve" model. Simply having an account in Azure AD does not automatically grant access to Navigator apps.
-
User Action:
The user navigates to the Navigator URL.
The user clicks "Log in with Azure AD" (or "Microsoft").
The "Request Sent" Screen: If the user has not been approved yet, they will see a screen stating that their access is pending approval.
-
System Action:
Navigator generates an internal "Access Request" for this specific identity.
Approving or Denying Access
Only users with the Tenant Admin role in Navigator can perform these steps.
Log In: Sign in to Navigator with your Tenant Admin account.
-
Navigate to Access Requests:
Go to Settings (Gear Icon) Access Requests.
-
Process the Request:
You will see a list of pending identities (users who attempted to log in).
Click Grant to allow access or Deny to block the request.
Once granted, the user can log in immediately.
Granting App Permissions & Access
Creating the account only allows the user to log in. An Tenant Admin must then grant them access to specific applications (e.g., Stores, Menus). Which is managed by Navigators access management tool.