Executing the SAM Setup Wizard
Do not attempt to log in to CIPP with the CIPP Service Account you created. Make sure you've gone through the steps of inviting yourself into your CIPP instance either via Azure (self-hosted) or through the Management Portal (hosted).
Walkthrough Video for Running the SAM Setup Wizard
When using the SAM Wizard to create your CIPP-SAM application, it's important to remember the following:
You're using a chromium based browser. It MUST allow cookies and have any ad-blocker disabled for the duration of the wizard. Do not use in-private mode.
When you're asked to authenticate during the SAM Setup Wizard, remember to use to the CIPP service account credentials. If you do not have a service account prepared you can do so now by going to the Creating the CIPP Service Account page and following the instructions there.
The SAM Wizard only needs to be run once to connect to your tenant, including all partner tenants, but there may be situations where you need to reinitialize the process.
This guide walks you through the process from the video of executing the SAM Wizard inside CIPP for the first time, and has 3 options based on what you're looking to accomplish. In this example, we use the first-time setup option, but more details on additional options can be found in the sections below.
Walkthrough Steps for Running the SAM Setup Wizard
Once you've logged into your CIPP instance, navigate to
Settings
->SAM Setup Wizard
For the purposes of this walkthrough, we'll act as if this is your first time running through this process, and you'd like to follow CIPP's recommended settings by clicking
I would like CIPP to create an application for me
.
On the next page, click on the
Start Setup Wizard
button.
Copy the code from the returned step to your clipboard.
Then click on the "HERE" link beside the code.
Enter the code we've copied in the previous step & click Next.
Select the option "Use another account".
This is where we will enter the credentials you've created for the CIPP service account. If you have not yet done that, follow the steps on the Creating the CIPP Service Account page. Remember that this account MUST use multifactor authentication.
Click on the "Continue" button. You may close this window when prompted.
Back in CIPP, click on the link that now appears when you see we've arrived at step number 2.
Login with the CIPP Service Account again.
Click on the
Accept
button. This will forward you to the page that reports the authentication status. You may close this page when instructed.
Back in CIPP, you should see it says "Setup Completed". You can now click on the "Application Settings" button.
From there, you'll want to click on the "Run Permissions Check" button. This check should show a successful result when all steps have been performed.
And that's it! Now you're ready to move on to adding your tenants and consenting the application.
Last updated