Download the Staged Rollout Configuration Guide
Download the complete guide as a PDF for offline use.
Download PDF ↓
Configuration Guide

Configuring Staged Rollout Group with Secret Double Octopus for existing customers

Learn how to register an application in Microsoft Entra ID, configure the required API permissions, enable staged rollout, and connect the environment to Secret Double Octopus for controlled user migration.

Microsoft Entra ID Secret Double Octopus Existing Customers
Before you begin

This guide applies to existing Microsoft Entra ID hybrid environments where Secret Double Octopus is integrated with the local Active Directory through remoteAD. Make sure you have administrator access to Microsoft Entra ID and the SDO Management Console.

Information to retain

Keep the Application (client) ID, Directory (tenant) ID, and client secret available. You will enter all three values when creating the Entra ID directory in the SDO Management Console.

Contents
01 Microsoft Entra App Registration
02 Authentication and Secrets Configuration
03 API Permissions and Consent
04 Entra Tenant Configuration
05 SDO Directory Integration
06 Group Sync and Assignment
Section 01

Microsoft Entra App Registration

1
In the Microsoft Entra admin center, open App registrations.
Step 1
2
Click New registration.
Step 2
3
Enter a display name for the application.
Step 3
Step 3 - screenshot 2
Step 3 - screenshot 3
Step 3 - screenshot 4
Step 3 - screenshot 5
4
Open the Redirect URI (optional) field.
Step 4
5
Enter https://login.microsoftonline.com/common/oauth2/logout as the redirect URI, and then click Register.
Step 5
6
Copy the Application (client) ID for use later in the SDO Management Console.
Step 6
7
Copy the Directory (tenant) ID for use later in the SDO Management Console.
Step 7
Section 02

Authentication and Secrets Configuration

8
Select Authentication (Preview) from the sidebar.
Step 8
9
Open the Settings tab.
Step 9
10
Enable ID tokens (used for implicit and hybrid flows).
Step 10
11
Click Save.
Step 11
12
Open Certificates & secrets.
Step 12
13
Create a new client secret and enter a descriptive name.
Step 13
Step 13 - screenshot 2
Step 13 - screenshot 3
14
Copy the client secret value for use later in the SDO Management Console.
Step 14
Section 03

API Permissions and Consent

15
Open API permissions.
Step 15
16
Click Add a permission.
Step 16
17
Select Microsoft Graph.
Step 17
18
Select Application permissions.
Step 18
19
Search for and add the Directory.ReadWrite.All application permission.
Step 19
Step 19 - screenshot 2
Step 19 - screenshot 3
Step 19 - screenshot 4
Step 19 - screenshot 5
20
Click Add a permission.
Step 20
21
Select Microsoft Graph.
Step 21
22
Search for and add the User-PasswordProfile.ReadWrite.All application permission.
Step 22
Step 22 - screenshot 2
Step 22 - screenshot 3
Step 22 - screenshot 4
Step 22 - screenshot 5
23
Click Add a permission.
Step 23
24
Select Microsoft Graph.
Step 24
25
Search for and add the Group.ReadWrite.All application permission.
Step 25
Step 25 - screenshot 2
Step 25 - screenshot 3
Step 25 - screenshot 4
Step 25 - screenshot 5
26
Click Add a permission.
Step 26
27
Select Microsoft Graph.
Step 27
28
Search for and add the User.ReadWrite.All application permission.
Step 28
Step 28 - screenshot 2
Step 28 - screenshot 3
Step 28 - screenshot 4
Step 28 - screenshot 5
29
Click Grant admin consent for SDO.
Step 29
30
Click Yes to confirm admin consent.
Step 30
Section 04

Entra Tenant Configuration

31
Use the Entra search bar to search for Password Reset.
Step 31
32
Select Password Reset from the results.
Step 32
33
Open Registration.
Step 33
34
Set the registration option shown to No.
Step 34
35
Click Save.
Step 35
36
Use the Entra search bar again.
Step 36
37
Select User settings from the results.
Step 37
38
Enable Show keep user signed in.
Step 38
39
Click Save.
Step 39
40
Use the Entra search bar again.
Step 40
41
Open Microsoft Entra Connect.
Step 41
42
Select Connect Sync from the navigation menu.
Step 42
43
Enable staged rollout for managed user sign-in.
Step 43
44
Click Manage groups and verify that the staged rollout group is configured.
Step 44
Section 05

SDO Directory Integration

45
Switch to the Secret Double Octopus Management Console and open Directories.
Step 45
46
Click Create Directory.
Step 46
47
Select Entra ID from the Directory Type menu.
Step 47
48
Click Select.
Step 48
49
Enter a name for the new directory integration.
Step 49
Step 49 - screenshot 2
Step 49 - screenshot 3
50
Enter the Tenant ID and Client (Application) ID created in Microsoft Entra ID.
Step 50
51
Enter the client secret created in Microsoft Entra ID.
Step 51
52
Select mail as the user identifier attribute.
Step 52
53
Click Test Connection.
Step 53
54
Click Create.
Step 54
55
Click Publish.
Step 55
56
Confirm publishing the new directory.
Step 56
57
Run directory synchronization.
Step 57
58
Click Publish.
Step 58
59
Confirm publishing the synchronization changes.
Step 59
Section 06

Group Sync and Assignment

60
Open Groups.
Step 60
61
Click Add Groups.
Step 61
62
Search for the staged rollout group and add it to the synchronization list.
Step 62
Step 62 - screenshot 2
Step 62 - screenshot 3
Step 62 - screenshot 4
Step 62 - screenshot 5
63
Click Publish.
Step 63
64
Confirm publishing the group changes.
Step 64
65
Edit the Entra ID directory that you added.
Step 65
66
Open Groups.
Step 66
67
Edit the staged rollout group.
Step 67
68
Open Settings.
Step 68
69
Enable the Staged Rollout (SRO) toggle.
Step 69
70
Click Publish.
Step 70
71
Confirm publishing the staged rollout group settings.
Step 71
72
Open Services.
Step 72
73
Edit the WS-Federation service.
Step 73
74
Open the Users tab.
Step 74
75
Click Add.
Step 75
76
Add the staged rollout group.
Step 76
77
Click Save.
Step 77
78
Click Publish.
Step 78
79
Confirm publishing the WS-Federation service changes.
Step 79
80
Edit the staged rollout group and validate that the user is in the SRO state.
Step 80
81
Confirm that the user is displayed with the SRO status.
Step 81
Staged rollout configuration complete

Confirm that users in the staged rollout group appear with the SRO status and can access the configured WS-Federation service.

Footer - Secret Double Octopus