Adding an OAuth (Entra ID) Identity Provider Profile

An OAuth (Entra ID) Identity Provider profile connects RUCKUS One to a Microsoft Entra ID App Registration. You can create a profile, review its connection details and associated Wi-Fi networks, and update its Microsoft Entra ID credentials.

Obtain the tenant ID, client ID, and client secret from the Microsoft Entra ID App Registration before you create the profile. You must test the connection successfully before you can add the profile.

The Microsoft Entra ID App Registration must include the required OpenID Connect (OpenID) delegated permission, and tenant-wide administrator consent must be granted before runtime authentication can be performed.

Note:

When you edit a profile, RUCKUS One does not display the current client secret. Leave the Client Secret field blank to retain the current secret, or enter a new client secret to replace it.

Complete the following steps to create an OAuth (Entra ID) Identity Provider profile:

  1. From the navigation bar, select Network Control > Service CatalogCatalog. The Service Catalog page is displayed.
  2. Find the Identity Provider tile and click Add.
    The Add Identity Provider page is displayed.
  3. Select OAuth (Entra ID) as the Identity Provider type.
  4. Click Next. The Add OAuth (Entra ID) Identity Provider page is displayed.
  5. Configure the profile fields.
    • Profile Name: Enter a name that identifies the OAuth (Entra ID) Identity Provider profile in RUCKUS One.
    • Tenant ID: Enter the identifier of the Microsoft Entra ID tenant that contains the App Registration.
    • Client ID: Enter the application identifier assigned to the Microsoft Entra ID App Registration.
    • Client Secret: Enter the client secret generated for the Microsoft Entra ID App Registration. The example values illustrate the expected value formats. Replace them with the values from your Microsoft Entra ID App Registration.
  6. Click Test Connection.

    RUCKUS One displays Testing connection... while validating the credentials. The Add button remains unavailable during the connection test.

    Review the connection test result:
    • If the connection test succeeds, RUCKUS One displays Connection successful. Handshake passed.
    • If the connection test fails, RUCKUS One displays Connection failed., followed by error details that identify the cause. Verify the Tenant ID, Client ID, and Client Secret, and then click Test Connection again.
    Note:

    A successful connection test validates the Microsoft Entra ID profile configuration and confirms that RUCKUS One can communicate with the configured Microsoft Entra ID application. It does not verify client-side configuration or successful 802.1X authentication for individual users or devices.

  7. Click Add. The new profile is added to the list on the OAuth (Entra ID) tab of the Identity Provider page.