4.6 Correcting Identity Provider Information
Jump to:
No content available.
Welcome!
User management application has been developed to create and manage users in the NFON X powered by Telekom app suite.
Subject to change
Version 2 / 06/2025 (EN)
| Type | Icon/Character | Description |
| NOTE
CAUTION
WARNING | NOTE: Information that is useful but not critical to the reader.
CAUTION: Tells the reader to proceed with caution.
WARNING: Stronger than CAUTION; means "don't do this" or that this step could be irreversible, e.g., result in permanent data loss. | |
| TIP |
| Useful tips that provide additional information. |
| Procedure | 1. 2. 3. | Procedures are numbered steps to perform an action, where the order of the steps is relevant. |
| Result of procedure/action | ⇒ | Indicates the result of an action//procedure. |
| Lists | • • | Used for listings and items where the order of steps is irrelevant. |
No content available.
Accessing the user management application from the Web/Desktop App/Admin Portal
To access the user management application from the Web/Desktop App/Admin Portal:
Click on your username or avatar.
Click on Manage users (Web/Desktop app)/User management (Admin Portal).
⇒ A new tab will open. You will be required to reenter your password.Reenter your password.
⇒ The user management application will open.
No content available.
Once in the user management application, you will land in the User tab. In this tab, you can:
See which users have been added and whether they have admin rights
Edit users
Delete users
Create users
To edit users:
Hover your mouse over the user name.
Click Edit (pencil icon)
.
⇒ The User Data page opens.
Editing user data
In the User data tab, you can:
Change user first name
Change user last name
Change username
Select a different language from a drop-down menu
Restore user password
Editing phone number
In the Phone number tab, you can:
Remove the extension.
Editing user permissions
To edit user permissions:
Click Permissions.
⇒ Here you can see all the licenses allocated to this user.Tick or untick the boxes to assign to or revoke licenses from this user.
Tick on untick the box next to System configuration access to assign to or revoke admin rights from this user
To create a user:
Click on the plus icon in the upper right-hand corner.
⇒ A new field will open.Enter the details for the new user.
Tick Admin rights if you want the user to have admin rights.
Click Save.
⇒ A new user has been created. After a quick update, you will see the user in the list.
Please note that after a new user has been created, they will automatically receive an email where they will be able to set their own password.
Viewing license information
To access licensing information:
Click License.
⇒ You will see how many product licenses are in use or available, along with the total number of licenses.
Revoking user licenses
To revoke a license:
Click on a product (in the example here: Softphone Pro) to see which users have licenses.
Click Revoke to remove the license for this product from a user.
You can also revoke a license from User -> Edit (pencil icon
) -> Permissions.
No content available.
4.1 Overview
Single Sign-On (SSO) login allows users to sign into NFON X powered by Telekom cloud telephony applications using the same login they already use in their organisation, for example, the account they use for email, PC login or other business applications.
It replaces the separate NFON X powered by Telekom cloud telephony username and password.
The SSO login can be used for various products, such as
Desktop App,
Web App,
Mobile App (Android and iOS),
Admin Portal,
User Profile and User Management Applications
Softphone Pro Telekom.
NFON X powered by Telekom cloud telephony no longer manages passwords for SSO users. Authentication is performed entirely by the Identity Provider, for example, Microsoft Entra ID or Google Workspace. This means that user identities, login credentials and authentication methods (such as MFA or password policies) are fully managed by your organization.
Once an SSO login is activated for your tenant (K account), you must link every NFON X powered by Telekom cloud telephony user to your Identity Provider. This ensures that when a user enters their email address on the NFON X powered by Telekom cloud telephony login page, they are automatically redirected to your organisation regular login page instead of entering a password which they only use for NFON X powered by Telekom cloud telephony.
Please note that the use of SSO is optional. This means that within your tenant, you can manage users who sign in via SSO and users who continue to sign in with a username and password.
No content available.
Before configuring an SSO login, ensure that:
you are a cloud application administrator in Microsoft Entra ID
you have telephony administrator permissions in the User Management application
user email addresses are consistent between NFON X powered by Telekom and your Identity Provider
users already exist in Microsoft Entra ID
To open the SSO configuration:
Sign into the User Management Application as a telephony administrator.
Click Single Sign-On (SSO).
Toggle on Enable SSO Login configuration.
Please note that the Single Sign-On (SSO) configuration page includes the relevant Service Provider Information with the Identifier (Entity ID) and Reply URL (Assertion Consumer Service URL) which you will need in the following steps.
To configure SSO for NFON X powered by Telekom cloud telephony in Microsoft Entra ID:
Sign in to the Microsoft Entra admin center as a Cloud Application Administrator.
Browse to Entra ID > Enterprise apps > All applications.
Select New Application.
4. Select Create your own application.
5. Name your application.
6. Click Create.
7. In the Manage section of the menu on the left, select Single sign-on to open the Single sign-on pane for editing.
8. Select SAML to open the SSO configuration page.
9. Edit the Basic SAML Configuration on the SAML-based sign-on page.
10. Enter the Identifier (Entity ID) and Reply URL (Assertion Consumer Service URL) from the NFON X powered by Telekom Single Sign-On configuration page.
11. Enter the Logout URL by using the Reply URL (Assertion Consumer Service URL).
The Logout URL ensures that after the user logs out from an NFON X powered by Telekom application, they will first log out from Microsoft Entra and then be redirected back to the NFON X powered by Telekom application login screen.
12. Keep the standard settings for Attribute & Claims.
13. Download the Certificate (Base64) version of the SAML certificates to your local machine.
14. You can open the downloaded file (.cer) with a text editor of your choice to get the certificate in a PEM format – including the BEGIN/END CERTIFICATE markup.
15. You will find the Login URL, Microsoft Entra Identifier and the Logout URL below the SAML certificates step.
Please note that you will need these three values and the certificate later on.
For your Microsoft Entra ID users to be able to use the single sign-on in the application that you configured in Microsoft Entra, choose one of the following options:
Allow all users
You can allow all users in your organisation to sign in through the newly created application.
To activate this option:
1. Go to Entra ID > Enterprise apps.
2. Select your application.
3. Within your application, navigate to the Properties page.
4. In the Properties page, turn off Assignment Required?
Select individual users or groups
You can select individual users or groups in the User and groups page of your application.
The assignment in Microsoft Entra only controls which user is allowed to authenticate through Microsoft Entra ID. However, you will always need to create a corresponding user in the NFON X powered by Telekom cloud telephony with the same email address as in Microsoft Entra ID.
To configure Single Sign-On:
Go back to NFON X powered by Telekom Single Sign-On (SSO) configuration in the User Management Application.
Click Setup SAML 2.0 Provider.
3. Enter the Login URL, Identifier (Entity ID) and Logout URL from Microsoft Entra.
4. Enter the SAML certificate from the file you have downloaded.
Remember to include the full content of the certificate file including the BEGIN / END CERTIFICATE markup.
5. You can optionally add a Description to make a note for yourself.
6. Click Save to store the configuration permanently.
Activate Single Sign-On (SSO) for your tenant (K account).
Please note that the activation will enable your SAML 2.0 configuration and add new workflows to the User Management Application to manage users with SSO, which will be described in the following sections.
Once you have enabled the SSO for your tenant (K account), you need to link each NFON X powered by Telekom cloud telephony user to your Identity Provider, e.g. Microsoft Entra ID in order for the user to be able to sind in using SSO.
However, the use of SSO is optional. This means that within your tenant, you can manage users who sign in via SSO and users who continue to sign in with a username and password.
In most cases, you can migrate existing users by simply activating the SSO login in their user details page:
Open the User Management Application by going to https://accounts.nfon.telekom.net.
Click Users.
Select the user you want to migrate.
Click Activate SSO login.
This connects the user to your organisation Identity Provider by using the exact NFON X powered by Telekom username (email address).
Please note that the NFON X powered by Telekom username must match exactly with the corresponding email address in your Identity Provider.
Important
Please note that the matching is case sensitive, i.e. a user with the email address in your Identity Provider, e.g. John.Doe@company.org must have the same NFON X powered by Telekom username John.Doe@company.org.
For Microsoft Entra ID: Usually, the user principal name is used as the primary email address.
In some cases, the existing NFON X powered by Telekom username does not match with the corresponding email address in your Identity Provider, or you have a customised Identity Provider configuration for your tenant (K account). In this case, you can use the advanced configuration wizard.
Open the User Management Application by going to https://accounts.nfon.telekom.net.
Click Users.
Select the user you want to migrate.
Select the wrench icon next to Activate SSO Login.
Enter the username and user ID.
In the Activate SSO Login wizard, you can enter the data that matches the information from your Identity Provider. For example, if the existing NFON X powered by Telekom username is john.doe@company.org but in your Identity Provider the corresponding email address is John.Doe@company.org. To make the exact matching work, you can enter for both fields the email address from your Identity Provider John.Doe@company.org.Click Activate.
To create a new user who will use the SSO Login, you will need to create the user and link the Identity Provider information. Using the Export / Import feature, you can complete both steps in a single workflow.
Create Extensions in the Admin Portal.
Make sure that all the required extensions exist at https://admin.nfon.telekom.net.
Click Wizards in the User Management Application.
The Import function allows creating up to 1000 users.Export an CSV file for unassigned extensions.
Download the CSV file to prepare your import. You can open the file with Microsoft Excel or any text editor of your choice.
The file includes the correct column structure and one entry for each unassigned extension.Remove the rows for any extensions you do not plan to assign.
7. Fill out the CSV file.
8. Add the required user information, including the identity provider fields:
idp_user_id
idp_username
Keep in mind that for regular NFON X powered by Telekom Single Sign-On which you configure in the User Management Application, the username, idp_user_id and idp_username must match exactly with the corresponding email address to your user in your Identity Provider.
In a standard Microsoft Entra SAML integration, the username, idp_user_id and idp_username must match the User Principal Name (UPN) of your user.
9. Import the completed CSV file.
10. Upload the file to the Export / Import page.
In some cases, you might want to set up a user with username and password, as these users are not part of your Identity Provider, e.g. external staff.
To create a new user who will use username and password, you have to use the user import described in the previous section and provide placeholder values for the Identity Provider columns. Afterwards, you can deactivate the SSO login under Users in the User Management Application.
If a user has been activated for Single Sign-On with incorrect Identity Provider information, e.g. a wrong User Principal Name (UPN), you can correct this by deactivating and activating the SSO login. This process ensures that the user is correctly associated with the entry in your Identity Provider.
Open the User Management Application by going to https://accounts.nfon.telekom.net.
Click Users.
Select the user whose Identity Provider information you would like to correct.
4. Click Deactivate SSO Login.
This removes the existing, incorrect mapping between the NFON X powered by Telekom cloud telephony user and your Identity Provider.
5. Click Activate SSO login.
When your tenant (K account) is configured to use the SSO login, certain parts of the user workflow and user management will change.
In the User Profile Application, users can usually edit their own personal information.
However, for users who authenticate via your Identity Provider, several functions are restricted:
Users cannot change their email address
Email addresses are managed exclusively by your Identity Provider.
Users cannot reset a password
NFON X powered by Telekom cloud telephony does not store a password for these users, as authentication is handled entirely by the Identity Provider.
Users cannot configure authentication factors (MFA)
MFA must be configured within your Identity Provider (e.g. Microsoft Entra ID).
User list
As a rule, administrators can manage all users of a tenant (K account).
However, If your tenant is configured to use the SSO login, the following applies:
Administrators cannot create new users using the “+” button
This option is disabled when the SSO login is active. Instead, administrators must create users using the User Import function.
Under Users, the following actions are restricted:
Administrators cannot revoke a user password
Users with the SSO login do not have NFON X powered by Telekom cloud telephony passwords since they authenticate through your Identity Provider.
Administrators cannot change the name of a user
Users with the SSO login are managed in your Identity Provider and need to be be updated there.
Limitation | Affected products | Description |
|---|---|---|
Microsoft Entra FIDO2 | NFON X powered by Telekom Desktop App (Versions before 2.1.0) | Microsoft Entra does not support FIDO2 as an authentication method for the NFON X powered by Telekom Desktop App in versions prior to 2.1.0. Note: NFON X powered by Telekom Desktop App 2.1.0 includes a configuration option that enables FIDO2 authentication for Microsoft Entra. |
Microsoft Entra Conditional Access (based on Device ID) | NFON X powered by Telekom Desktop App (all versions) Softphone Pro (all versions) | Microsoft Entra Conditional Access based on Device ID is not supported on desktop clients using embedded browsers. These embedded browsers do not transmit a Device ID, unlike Microsoft Edge. Device ID–based Conditional Access works as expected when users sign in the Web App via a standard Microsoft Edge browser. |