SOP 016 - Milrose (HLZ/Surface Design) – Deltek Ajera SSO Configuration with Microsoft Entra ID

Created by Allwyn, Modified on Fri, 18 Sep at 9:37 AM by Allwyn

Milrose (HLZ/Surface Design) – Deltek Ajera SSO Configuration with Microsoft Entra ID

SOP #:

016

 

Prepared by:

Kwayne James

Revision Date:

May 14, 2026

 

Approved by:

Allwyn Griffith

 

 

Purpose/Summary Statement:

The purpose of this document is to provide instructions for configuring OpenID Connect (OIDC) Single Sign-On between Microsoft Entra ID and Deltek Ajera. This ensures secure, centralized authentication and enables the Ajera application icon within the Microsoft My Apps portal for end-users.

 

Scope

This procedure affects the IT Administration team. It covers the configuration of the Enterprise Application "Ajera Login" and the synchronization of authentication for all Milrose Consultants employees.

Procedure:

Step 1: Enterprise Application Properties & Visibility

  • Navigate to Entra ID > Enterprise Applications > Ajera Login.
  • Go to the Properties blade.
  • Ensure Enabled for users to sign-in? is set to Yes.
  • Homepage URL: Ensure this is set to https://ajera.com/V007177. (This is critical for the My Apps portal launcher to function).
  • Visible to users?: Set to Yes so the icon appears in the Microsoft 365 App Launcher.
  • Assignment required?: Set to No if you want all employees in the "Users and Groups" list to see it immediately, or Yes if you want to strictly control access.

Step 2: Users and Groups (Access Control)

  • Navigate to the Users and groups blade.
  • Click + Add user/group.
  • Add the following to ensure company-wide access:
  • SG_Milrose_Employees (Security Group)
  • Individual Admin accounts (e.g., Kwayne James) for testing.
  • Assigned roles should be set to Default Access.

Step 3: Single Sign-on & App Registration Integration

  • Navigate to the Single sign-on blade.
  • Note that this is an OIDC-based application. Basic configuration (Attributes & Claims) is handled automatically by the OIDC protocol.
  • Click the link "Go to application" to jump to the App Registration backend to verify technical tokens:
  • Under Authentication, verify that ID tokens and Access tokens are checked under the "Implicit grant" section.
  • Under API Permissions, ensure User.Read is granted with Admin Consent for Milrose Consultants, LLC.

Step 4: Finalizing the Ajera Client Integration

  • Open the Deltek Ajera Desktop Application.
  • Go to Setup > Company > Preferences > Integration > Microsoft Entra ID.
  • Input the Application ID, Directory ID, and Client Secret from the App Registration.
  • Check "Enable Windows Authentication": This turns on the SSO feature.
  • Check "Enable Windows Authentication Log in Only": This forces the SSO and disables the old Ajera password login, ensuring a "zero-click" experience when launching from Microsoft.
  • Click Save.

Step 5: Validation

  • Log into myapps.microsoft.com as a standard user.
  • Click the Ajera Login icon.
  • Verify the user is redirected to the Ajera dashboard without a manual password prompt.

 

 

 

 

 

Accounts / Access:

•              Entra ID: Requires Global Administrator or Cloud Application Administrator role.

•              Deltek Ajera: Requires Ajera Administrator permissions.

•              Credentials: All App IDs and Secret Keys should be documented and stored securely in IT Glue.

 

 

 

 

 

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article