Access Token for Microsoft Azure Cloud Services

Configure an access token to connect to Microsoft Azure Cloud Services.

Figure: MS Azure Cloud Services Access Token Configuration screen

MS Azure Cloud Services Access Token Configuration screen

Background and Setup

Examples

Prerequisites

Good to Know

  • In most cases, you can use a global access token or an app level access token:
    • Global access tokens are shared across all users and apps. If you want all process designers and runtime app users in your AgilePoint NX tenant to be able to connect to an external data source, use a global access token. An example is a SharePoint site on an intranet that all employees in a company can access.
    • Application level access tokens are shared with all processes in a process-based app, or restricted to use within a form-based app. Use application level access tokens if only process designers or runtime app users for a particular application should access an external system — for example, a Box account that is only used to share files within a small team.
  • Access tokens are collections of credentials that are used to authenticate communication directly between AgilePoint NX and an external system. Because it is the AgilePoint NX system that uses these credentials, rather than an app, there is no difference between design time and runtime access tokens. Access tokens are never checked in or published, and they do not use version control. If you change an access token in App Builder or Manage Center, the access token changes immediately everywhere the access token is used. Changes to app level access tokens apply to all versions of an app, including running application instances. Changes to global access tokens apply everywhere they are used in AgilePoint NX. You can not roll back an access token to a previous version.

    For more information, refer to What Data Is Deleted When I Delete an App or Application Resource?

  • This screen may look different in different places. The UI varies for this screen depending upon how you open it. However, the fields for this screen are the same in all places.
  • Some information about third-party integrations is outside the scope of the AgilePoint NX Product Documentation. It is the responsibility of the vendors who create and maintain these technologies to provide this information. This includes specific business use cases and examples; explanations for third-party concepts; details about the data models and input and output data formats for third-party technologies; and various types of IDs, URL patterns, connection string formats, or other technical information that is specific to the third-party technologies. For more information, refer to Where Can I Find Information and Examples for Third-Party Integrations?

Fields

Field NameDefinition

Token Name

Description:
Specifies the unique name for your connection to Microsoft Azure Cloud Services.
Allowed Values:
One line of text (a string).

Accepted:

  • Letters
  • Numbers
  • Spaces
Default Value:
None
Example:
This is a common configuration field that is used in many examples. Refer to:
  • Examples - Step-by-step use case examples, information about what types of examples are provided in the AgilePoint NX Product Documentation, and other resources where you can find more examples.

Description

Description:
A description for your access token.
Allowed Values:
More than one line of text.
Default Value:
None
Example:
This is a common configuration field that is used in many examples. Refer to:
  • Examples - Step-by-step use case examples, information about what types of examples are provided in the AgilePoint NX Product Documentation, and other resources where you can find more examples.

Azure Service Bus / Azure Blob Storage

Description:
Specifies the type of service to connect in Microsoft Entra ID.
Allowed Values:
  • Azure Service Bus - Connects to the Microsoft Azure Service Bus service in Microsoft Entra ID.
  • Azure Blob Storage - Connects to the Microsoft Azure Blob Storage service in Microsoft Entra ID.
Default Value:
Azure Service Bus

Service Bus Namespace

Description:
Specifies your namespace for Microsoft Azure Service Bus in Microsoft Entra ID.
To Open this Field:
  1. On the MS Azure Cloud Services Access Token screen, click Azure Service Bus.
Allowed Values:
One line of text (a string).

Accepted:

  • Letters
  • Numbers
  • Hyphens (-)

Not Accepted:

  • Spaces
  • Other special characters
Default Value:
None

Storage Account Name

Description:
Specifies the name of the storage account for Microsoft Azure Blob Storage in Microsoft Entra ID.
To Open this Field:
  1. On the MS Azure Cloud Services Access Token screen, click Azure Blob Storage.
Allowed Values:
One line of text (a string).

Accepted:

  • Letters
  • Numbers
Default Value:
None

Authentication Types

Description:
Specifies the authentication type to connect to the Microsoft Azure Service Bus or Microsoft Azure Blob Storage environment.
To Open this Field:
  1. On the MS Azure Cloud Services Access Token screen, select one of these:
    • Azure Service Bus
    • Azure Blob Storage
Allowed Values:
  • OAuth 2.0 - Uses token-based authentication to connect to Microsoft Azure Service Bus or Microsoft Azure Blob Storage.
  • Shared Access Signature - Uses a connection string to authenticate to Microsoft Azure Service Bus or Microsoft Azure Blob Storage.
  • Access Key - Uses an access key to connect to Microsoft Azure Blob Storage.
Default Value:
OAuth 2.0

Tenant ID

Description:
Specifies the tenant ID for your Microsoft Azure Service Bus or Microsoft Azure Blob Storage app in Microsoft Entra ID.
To Open this Field:
  1. On the MS Azure Cloud Services Access Token screen, select one of these:
    • Azure Service Bus
    • Azure Blob Storage
  2. Click OAuth 2.0.
Allowed Values:
One line of text (a string).

Accepted:

  • Letters
  • Numbers
  • Hyphens (-)

Not Accepted:

  • Spaces
  • Other special characters
Default Value:
None

Client ID

Description:
Specifies the client ID for your Microsoft Azure Service Bus or Microsoft Azure Blob Storage app in Microsoft Entra ID.
To Open this Field:
  1. On the MS Azure Cloud Services Access Token screen, select one of these:
    • Azure Service Bus
    • Azure Blob Storage
  2. Click OAuth 2.0.
Allowed Values:
One line of text (a string).

Accepted:

  • Letters
  • Numbers
  • Hyphens (-)

Not Accepted:

  • Spaces
  • Other special characters
Default Value:
None

Client Secret ID

Description:
Specifies the client secret ID of your Microsoft Azure Service Bus or Microsoft Azure Blob Storage app in Microsoft Entra ID.
To Open this Field:
  1. On the MS Azure Cloud Services Access Token screen, select one of these:
    • Azure Service Bus
    • Azure Blob Storage
  2. Click OAuth 2.0.
Allowed Values:
One line of text (a string) that can have letters, numbers, and special characters, and can not have spaces.
Default Value:
None

OAuth 2.0 Access Token

Description:
Specifies an OAuth 2.0 access token from Microsoft Azure Service Bus or Microsoft Azure Blob Storage.
To Open this Field:
  1. On the MS Azure Cloud Services Access Token screen, select one of these:
    • Azure Service Bus
    • Azure Blob Storage
  2. Click OAuth 2.0.
Allowed Values:
An OAuth 2.0 access token

This value comes from Microsoft Azure Service Bus or Microsoft Azure Blob Storage.

Default Value:
None.

Get OAuth 2.0 Access Token

Function:
Sends a request to the Microsoft Azure Service Bus or Microsoft Azure Blob Storage environment to get the access token.

To complete this process, you must sign in to Microsoft Azure Service Bus or Microsoft Azure Blob Storage, and specify your consent when prompted.

To Open this Field:
  1. On the MS Azure Cloud Services Access Token screen, select one of these:
    • Azure Service Bus
    • Azure Blob Storage
  2. Click OAuth 2.0.

Renewal Rate

Description:
Specifies how frequently to renew your application's access token.
To Open this Field:
  1. On the MS Azure Cloud Services Access Token screen, select one of these:
    • Azure Service Bus
    • Azure Blob Storage
  2. Click OAuth 2.0.
Allowed Values:
  • Disabled
  • Every 15 minutes
  • Every half an hour
  • Every hour
Default Value:
Every hour

Primary Connection String

Description:
Specifies the primary connection string to authenticate to Microsoft Azure Service Bus or Microsoft Azure Blob Storage.

The primary connection string comes from Microsoft Azure Service Bus or Microsoft Azure Blob Storage.

To Open this Field:
  1. On the MS Azure Cloud Services Access Token screen, select one of these:
    • Azure Service Bus
    • Azure Blob Storage
  2. Click Shared Access Signature.
Allowed Values:
One line of text (a string) that can have letters, numbers, and special characters, and can not have spaces.
Default Value:
None
Example:
Endpoint=sb://mynamespace.servicebus.windows.net/;SharedAccessKeyName=RootManageSharedAccessKey; SharedAccessKey=2B5K28DMymL349ab4641sq5N77An947FB7062853=

Key

Description:
Specifies the key for the app you created for Microsoft Azure Blob Storage in Microsoft Entra ID.
To Open this Field:
  1. On the MS Azure Cloud Services Access Token screen, click Azure Blob Storage.
  2. Click Access Key.
Allowed Values:
An access key from Microsoft Azure Blob Storage.
Default Value:
None

Test Connection

Function:
Makes sure that the specified Microsoft Azure Service Bus or Microsoft Azure Blob Storage credentials are correct.
To Open this Field:
  1. On the MS Azure Cloud Services Access Token screen, select one of these:
    • Azure Service Bus
    • Azure Blob Storage
  2. Click Shared Access Signature.