Verification and Testing

After completing the configuration, validate the integration by authenticating to ESKM using Microsoft Entra ID credentials.

Logging in to ESKM Using OIDC Authentication

  1. Launch a web browser and navigate to the ESKM Management UI using port 8443. Example: https://<ESKM_HOSTNAME>:8443

  2. Click on Login.

  3. On the ESKM login page, click Sign In using OpenID.

image-20260810-081659.png

ESKM OIDC login page

  1. The browser is redirected to the Microsoft Entra ID sign-in page.

  2. Enter the credentials of the Microsoft Entra ID user that was configured as an OpenID administrator in ESKM.

  3. Complete any Multi-Factor Authentication (MFA) verification steps, if applicable.

  4. After successful authentication, Microsoft Entra ID redirects the user back to ESKM.

  5. Verify that the user is successfully logged in to the ESKM Management UI.

Verifying Successful Authentication

Perform the following validation checks:

  • Verify that the user is successfully authenticated through Microsoft Entra ID and redirected to the ESKM Management UI.

  • Verify that the authenticated user is granted the expected administrative privileges configured in ESKM.

  • Verify that the user can successfully perform ESKM administrative operations according to the assigned permissions.

  • Verify successful Single Sign-On (SSO) behavior:

    • Click Home in the ESKM Management UI and verify that ESKM redirects the user to the Home page on port 9443.

    • Confirm that the user remains authenticated and is not prompted to log in again after the redirection.

Logs and Validation Steps

The integration can be validated by reviewing authentication events in Microsoft Entra ID and ESKM.

Reviewing Authentication Logs in Microsoft Entra ID

Microsoft Entra ID records authentication attempts performed through OIDC.

  1. Sign in to the Azure Portal.

  2. Navigate to Microsoft Entra ID → Monitoring → Sign-in logs.

  3. Locate the authentication event corresponding to the ESKM login attempt.

  4. Verify that the sign-in status is reported as successful.

  5. Review additional details such as:

    • User

    • Application

    • Status

image-20260814-043707.png

Sign-in logs

Reviewing Authentication Logs in ESKM

ESKM records OIDC authentication events and administrator login activities.

  1. Log in to the ESKM Administration Console.

  2. Navigate to Device → Log Viewer → Audit.

  3. Select the desired log file.

  4. Click Display Log and verify that an entry similar to the following is present.

[abc@xyz.com] [Login] Logged in from <IP Address> via web