How to configure K2 Package and Deployment to authenticate an AAD User in K2 Five
KB002069
PRODUCTK2 Package and Deployment in K2 Five is configured to leverage Windows integrated security. This means that your Active Directory ID (DomainUsername) will be passed to K2 and used to determine if you have the required permissions and memberships to execute package creation and deployment tasks. However, K2 Package and Deployment can be manually configured to use an Azure Active Directory (AAD) identity.
This article will walk you through the steps necessary to create a K2 Package and Deployment server connection for an AAD identity.
- Consent to the K2 AAD Login application.
In order to log into K2 Package and Deployment with an AAD identity, K2 Package and Deployment needs to authenticate the credentials against AAD. To do this requires that the K2 for AAD Log app be previously granted consent within the target AAD tenant. This is the same app used by the K2 APIs, so follow these steps to grant consentConsent must be granted by an AAD tenant admin- Open K2 Management.
- Select Integration > APIs.
- Click on the Setup AAD Consent button.
- This will redirect you to the AAD login screen (notice the “K2 for AAD Login” app title). Enter the username and password for the AAD tenant admin and sign in.
- You should now be at the consent screen. Click Accept.
- Upon acceptance, you are redirected to the K2 website. You can close that browser window.
-
K2 Package and Deployment Configuration
-
Open K2 Package and Deployment
-
Click on New
-
At the add a new server dialog enter in the following fields:
Server Name – the name or IP address of the K2 server
Server Port – this should most likely be 5555
Username – the AAD login name (e.g. codi@denallix.com)
Password
Label – this should be AAD
Integrated Security – *** must be unchecked***The AAD user must be a member of the Package and Deployment role, and must have export rights (or be a member of a group that has export rights) on the K2 server. -
Click OK
-
-
Usage
-
Select the newly added server.
-
Now select either Create New Package, Edit Package, or Deploy Package.
-
At this point K2 will use the AAD identity when attempting to package or deploy solutions.
-