Overview
This article outlines instructions for implementing SS&E Authentication for new customers. If you are an existing customer and your institution would like to move from another authentication method to Microsoft Authentication for SS&E, please reach out to your CSM or submit a support request at https://support.watermarkinsights.com/hc/en-us/requests/new for help.
The details outlined in this guide are subject to change as Watermark processes and requirements change over time.
Register Aviso Retention as an Application in Microsoft Entra ID/Azure AD.
- As an Entra ID/Azure AD administrator, navigate to the following url: https://login.microsoftonline.com/common/oauth2/authorize?client_id=3b9b9db1-b739-4237-8caa-89f22917ce3a&response_type=code&redirect_uri=https%3A%2F%2Fwww.avisoretention.com&prompt=admin_consent
- Accept the required permissions for the application. On success, you will be redirected to: https://www.avisoretention.com.
- Navigate to https://portal.azure.com and verify that the Watermark Student Success & Engagement (formerly Aviso Engage) application has been added to your Enterprise Applications.
- Let Watermark Technical Consultants know that you have completed the steps above.
Setup Notes
- Only Microsoft Entra/Azure AD administrators (or those who have access to "add enterprise applications") will be able to use this link.
- Clicking the link in the Entra/Azure menu will most likely not work as it is not supported.
- To test the authentication enter your SS&E/Aviso instance URL in your web browser directly. If you do not know your SS&E URL please reach out to your CSM, Implementation project manager or our support team.
- Technical Note: When using Microsoft OAuth 2.0 authentication, SS&E will examine the response from the user API endpoint for userPrincipalName (user identifier in Entra/Azure). This value is then examined for an '@' symbol. If an '@' symbol is in the userPrincipalName, the user will be looked up by email address; otherwise the user will be looked up by username. If a match exists, the user will be logged in to the system based on the record that is found. Otherwise, the user will receive a message indicating that their user account has not been configured for authentication with SS&E.
Configure Student Success & Engagement and Test
Once the above has been completed, the authentication mode of your SS&E Instance can be modified to use this authentication integration to sign users into SS&E.