| ℹ️ Information |
|---|
| This repository contains the connector and configuration code only. The implementer is responsible for acquiring the connection details such as username, password, certificate, etc. You might even need to sign a contract or agreement with the supplier before implementing this connector. Please contact the client's application manager to coordinate the connector requirements. |
HelloID-Conn-SA-Full-EntraID-AFAS-Update-Phone is a template designed for use with HelloID Service Automation (SA) Delegated Forms. It can be imported into HelloID and customized according to your requirements.
By using this delegated form, you can manage resource attributes across your connected systems. The following options are available:
- Search and select the resource
- Enter new values for the resource attributes
- The entered values are validated
- Resource attributes are updated with new values across connected systems
- Writing back values will be handled according to system-specific rules and configurations
Before implementing this connector, make sure to configure a Microsoft Entra ID, an App Registration. During the setup process, you’ll create a new App Registration in the Entra portal, assign the necessary API permissions (such as user and group read/write), and generate and assign a certificate.
Follow the official Microsoft documentation for creating an App Registration and setting up certificate-based authentication:
Once you have completed the Microsoft setup and followed their best practices, configure the following HelloID-specific requirements.
- API Permissions (Application permissions):
User.ReadWrite.AllUser-Phone.ReadWrite.All
Ensure AFAS Profit is configured with:
- AFAS AppConnector configured for OAuth client credentials (OAuth-only)
- AFAS OAuth credentials:
- ClientId
- ClientSecret
- Loaded AFAS GetConnector:
- Tools4ever - HelloID - T4E_HelloID_Users_v2.gcn
- https://github.com/Tools4everBV/HelloID-Conn-Prov-Target-AFAS-Profit-Employees
- Built-in Profit update connector: KnEmployee
HelloID requires a base64 string to import the certificate. With the example below, it is possible to create a base64 string:
$filePath = 'C:\Cert'
$pfxCertName = 'Cert.pfx'
$pfxPath = "$filePath\$pfxCertName"
$fileContentBytes = [System.IO.File]::ReadAllBytes("$pfxPath")
[System.Convert]::ToBase64String($fileContentBytes) | Set-Content "$filePath\HelloID_Cert_Base64.txt"The following user-defined variables are used by the connector.
| Setting | Description | Mandatory |
|---|---|---|
| EntraIdAppId | The Application (client) ID of the Entra ID app registration | Yes |
| EntraIdTenantId | The Directory (tenant) ID of the Entra ID tenant | Yes |
| EntraIdCertificateBase64String | The Base64 encoded certificate string for Entra ID authentication | Yes |
| EntraIdCertificatePassword | The password for the certificate | Yes |
| AFASBaseUrl | The base URL to the AFAS Profit REST API | Yes |
| AFASClientId | The OAuth ClientId for AFAS Profit authentication | Yes |
| AFASClientSecret | The OAuth ClientSecret for AFAS Profit authentication | Yes |
| companyName | The company name (used for display purposes only) | No |
- Entra ID Authentication: This connector uses certificate-based authentication for Microsoft Entra ID instead of client credentials. The certificate must be properly configured in the app registration and provided as a Base64 encoded string with its password.
- Employee ID Correlation: The connector correlates Entra ID users with AFAS employees using the Employee ID field. If no matching AFAS employee is found, the update for AFAS will be skipped, but the Entra ID update will still proceed.
-
Pattern Validation: The form includes RegEx pattern validation for mobile and fixed phone numbers. The default patterns are:
- Mobile Phone:
^\\+316\\d{8}$(format: +31612345678) - Business Phone:
^(088-123)+[0-9]{4}$(format: 088-123xxxx)
These patterns should be adjusted according to your organization's phone number format requirements.
- Mobile Phone:
- Skip Unnecessary Updates: The connector checks if the phone numbers in AFAS are already set to the requested values. If no changes are detected, the update operation is skipped to avoid unnecessary API calls and potential errors.
The following endpoints are used by the connector
| Endpoint | Description |
|---|---|
| https://graph.microsoft.com/v1.0/users/{id} | Update Entra ID user attributes |
| https://login.microsoftonline.com/{tenant}/oauth2/token | Obtain access token for Microsoft Graph API |
| {AFASBaseUrl}/connectors/T4E_HelloID_Users_v2 | Retrieve AFAS employee information |
| {AFASBaseUrl}/connectors/KnEmployee | Update AFAS employee phone numbers |
💡 Tip:
For more information on Delegated Forms, please refer to our documentation pages.
The official HelloID documentation can be found at: https://docs.helloid.com/