TechIDManager EntraID/Azure AD Agent Install (Base & Link)

Install TechIDAgent for Microsoft Entra ID

Quick Start (TLDR):

Install the Azure CLI, and download the GUI TechIDAgent.EntraID install tool, and click around. Install the BASE in the MSP tenant, and LINK client tenants. It is pretty obvious.

 

Full Instructions:

The TechIDManager agent for Microsoft Entra ID provides MSPs with the same account-management capabilities available with other TechIDManager agents.

This includes:

  • Automatic creation of unique accounts for every technician in each Entra ID tenant they are authorized to access

  • Automatic password rotation

  • Role assignments tailored to each technician

  • Just-In-Time (JIT) or Managed accounts

  • Rights assignments using the same grouping and triplet system used by other TechIDManager agents

The Entra ID installation consists of two parts:

Base Install
This is installed once in your MSP’s Entra ID tenant. The Base installation contains the central TechIDManager Entra ID components and performs the executions required to manage linked tenants.

Linked Tenant Install
Performed for each customer Entra ID tenant that you want TechIDManager to manage.

In most environments, you will:

  1. Install the Base once in your MSP tenant.

  2. Link each customer tenant.

  3. Manage the linked tenants through the TechIDManager Portal.


Before You Begin

To install TechIDAgent for Entra ID, you must have:

  • An active TechIDManager subscription

  • Access to the TechIDManager Portal

  • Azure CLI installed on the computer where you will perform the installation https://learn.microsoft.com/en-us/cli/azure/install-azure-cli?view=azure-cli-latest 

  • An Azure subscription in your MSP tenant capable of running the required Azure resources, usually Pay-As-You-Go

  • Global Administrator account in the applicable MSP and customer EntraID tenants

The Base installation requires an Azure subscription capable of supporting the required Azure execution environment. This consumption plan, which costs about $0.25 per month per tenant—yes, just 25 cents. If you don’t already have one, the easiest option to set up is a “Pay-As-You-Go” plan.

TechIDManager supports most Microsoft Cloud Envisonments; Commercial Azure, GCC, and GCC High.


Base Install

Do this once in your MSP tenant

The Base installation is created once in your MSP’s Entra ID tenant.

4.3.1

Install Azure CLI

Install the Azure CLI on the computer you will use to perform the TechIDManager Entra ID installation.

You only need to install Azure CLI once on the computer, and only for the duration of the base install and client tenant linking.

If you are behind a proxy, make sure Azure CLI is configured to work through that proxy.

Expected Result:
Azure CLI is installed and available on your computer.


4.3.2

Download the TechIDAgent Entra ID Installer

Sign in to the TechIDManager Portal and go to the Downloads section.

Download the latest TechIDAgent Entra ID Installer.

The installer will download as a ZIP file.

Expected Result:
The TechIDAgent Entra ID Installer ZIP file is saved on your computer.


4.3.3

Extract and Run the Installer

Extract the downloaded ZIP file to a folder on your computer.

Open the extracted folder and run the TechIDAgent Entra ID Installer.

The same installer is used for:

  • Base installations

  • Linked Tenant installations

  • Updates to an existing Base installation

Expected Result:
The TechIDAgent Entra ID Installer opens.


4.3.4

Select the Azure Environment and Sign In

Select the Azure cloud environment you are installing into:

  • Commercial Azure

  • GCC

  • GCC High

TechIDManager recommends selecting the option to sign out of all other Azure tenants before beginning the installation.

This helps prevent accidentally performing the installation against the wrong tenant.

Sign in to the MSP Entra ID tenant where you want to create the Base installation.

The installer uses Azure CLI for the sign-in process – which OFTEN shows the login dialog BEHIND all other windows.

Complete the normal Microsoft authentication process required by your organization, including MFA when applicable.

If multiple tenants are available, make sure you select the correct MSP tenant.

Expected Result:
The installer is authenticated to the MSP tenant where the TechIDManager Base will be installed.


4.3.5

Review the Base Installation and Subscription

After authentication, the installer will inspect the tenant and determine whether a TechIDManager Base installation already exists.

The installer can display information including:

  • Whether a Base installation exists

  • Whether an existing Base requires an update

  • The Azure subscription associated with the Base

  • The Azure region associated with the installation

If no Base installation is found, the installer will provide the option to install one.

If multiple subscriptions or installations are available, select the appropriate one.

Expected Result:
The correct Azure subscription and Base installation option are selected.


4.3.6

Install the Base

Select Install to begin the Base installation.

The installer will run the required Azure CLI commands.

The commands being executed, along with their output, are displayed in the installer so you can monitor the installation.

Do not close the installer while the process is running.

When the installation completes, the installer should report:

Base Install Completed Successfully

After installation, sign in to the TechIDManager Portal and go to:

Client Options

Confirm that the Entra ID Base installation is shown as complete.

Expected Result:
The TechIDAgent Entra ID Base is installed and shown as complete under Client Options in the TechIDManager Portal.


Link Install

Do this for each customer Entra ID tenant

After the Base installation is complete, each customer Entra ID tenant that TechIDManager will manage must be linked.


4.3.7

Open the TechIDAgent Entra ID Installer

Run the same TechIDAgent Entra ID Installer used for the Base installation.

You do not need to download a separate Link installer.

Expected Result:
The TechIDAgent Entra ID Installer is open and ready to link a customer tenant.


4.3.8

Select Link Tenant

Select the option to Link a Tenant.

This begins the Linked Tenant installation process.

Expected Result:
The installer displays the options required to link a customer Entra ID tenant.


4.3.9

Sign In to the Customer Tenant

Sign in to the customer Entra ID tenant that you want to link.

The installer uses Azure CLI for authentication – which OFTEN shows the login dialog BEHIND all other windows.

Complete the normal Microsoft authentication process required by that tenant, including MFA when applicable.

If multiple tenants are available, make sure you select the correct customer tenant.

Expected Result:
The installer is authenticated to the customer Entra ID tenant you want to manage with TechIDManager.


4.3.10

Configure the Tenant Name

Configure the identifying information for the linked tenant.

This includes:

Friendly Name
The friendly name used to identify the environment.

RMM Name
The RMM name associated with the tenant and displayed to technicians where applicable.

Use names that make it easy for your technicians to identify the correct customer environment.

Expected Result:
The linked tenant has the appropriate Friendly Name and RMM Name.


4.3.11

Select JIT or Managed Accounts

Choose how technician accounts should operate for this tenant.

Just-In-Time (JIT)
Technician privileged accounts are enabled when needed and disabled when they are no longer required.

Managed
Technician accounts remain available and are continuously managed by TechIDManager.

These settings can also be changed later from the TechIDManager Portal.

Expected Result:
The initial account-management mode for the customer tenant is configured.


4.3.12

Review Advanced Options

Expand the Advanced Options if the customer environment requires additional customization.

Depending on the environment, available settings can include:

Multiple Instances
Allows more than one instance to be configured. This is uncommon and normally does not need to be changed.

Username Formatting
Controls the format TechIDManager uses when creating technician usernames.

Display Name Formatting
Controls the display name assigned to technician accounts.

Account Description
Controls the description assigned to TechIDManager-managed accounts.

Hybrid
Use this option when the Entra ID tenant is part of a hybrid environment where technician accounts originate from an Active Directory domain. This is uncommon and not normally used. 

Hybrid Domain GUID
When using a hybrid configuration, enter the Domain GUID associated with the TechIDAgent running on the Active Directory domain being synchronized to Entra ID.

If the environment does not require any of these options, leave the default settings in place.

Expected Result:
Any required advanced configuration settings are complete.


4.3.13

Link the Customer Tenant

Select Link Tenant.

The installer will perform the required configuration using Azure CLI.

All Azure CLI commands being executed, along with their output, are displayed in the installer.

Monitor the output for errors while the process runs.

When the process completes successfully, the customer tenant is linked to your TechIDManager Base installation.

Expected Result:
The customer Entra ID tenant is successfully linked to TechIDManager.


4.3.14

Verify the Linked Tenant in TechIDManager

After linking the tenant, allow TechIDManager time to discover and process the new installation.  

The linked tenant should appear in the TechIDManager Portal within approximately one hour.

In the TechIDManager Portal, go to:

Agents

The tenant should appear as a PAM Entra ID agent.

Once it appears, you can manage the tenant’s TechIDManager configuration from the portal.

This includes settings such as:

  • Just-In-Time or Managed account behavior

  • Technician rights

  • Groups and triplets

  • Username and account settings

  • Tenant-specific TechIDManager options

Repeat steps 4.3.7 through 4.3.14 for each additional customer Entra ID tenant you want TechIDManager to manage.

Expected Result:
The linked customer tenant appears under Agents in the TechIDManager Portal and is ready to configure.


Update an Existing Base Installation

To update an existing TechIDAgent Entra ID Base installation:

  1. Open the TechIDAgent Entra ID Installer.

  2. Select the appropriate Azure cloud environment.

  3. Sign in to your MSP Entra ID tenant.

  4. Allow the installer to locate the existing Base installation.

  5. Select the Base installation you want to update.

  6. Select Update.

  7. Monitor the Azure CLI commands and their output in the installer.

  8. Wait for the installer to report that the Base was updated successfully.

There should normally only be one Base installation.

If multiple subscriptions or Base installations are displayed, make sure you select the correct installation before proceeding.


Entra ID Configuration Options

After a tenant has been linked, most ongoing configuration can be managed from the TechIDManager Portal.

Available options can include:

RMM Name

The RMM name associated with the tenant and displayed in the TechIDClient where applicable.

Friendly Name

The friendly name used to identify the tenant.

Username

Controls the formatting used when TechIDManager creates technician usernames.

Display Name

Controls the formatting used for technician account display names.

Just-In-Time

Determines whether technician accounts use Just-In-Time access.

  • Yes — Use Just-In-Time accounts.

  • No — Use Managed accounts.

Hybrid

Determines whether TechIDManager should work with technician accounts synchronized from an Active Directory domain or create and manage accounts directly in Entra ID. This is uncommon and not normally used. 

Hybrid Domain GUID

Required when the tenant is configured as a hybrid environment.

Use the Domain GUID belonging to the TechIDAgent running on the Active Directory domain that is synchronized to the Entra ID tenant.

The Domain GUID can be found in the TechIDManager Portal by viewing the applicable domain’s configuration.


Why a Base Installation Is Required

TechIDManager is designed so Ruffian Software does not need access to your customers’ Entra ID tenants.

We do not ask for, or store, client OAuth tokens, Bearer tokens, Global Administrator passwords, or similar credentials that would provide direct access to your customers’ tenants.

For TechIDManager to create users, set passwords, and perform privileged-access operations, something must run with the appropriate permissions within the Microsoft tenant environment.

TechIDManager accomplishes this using a Base installation in your MSP’s Azure tenant with connections to the customer tenants you link to TechIDManager.

This keeps the execution infrastructure, and client tenant secrets, under your control rather than requiring Ruffian Software to maintain credentials that provide access to your customers’ environments.


 

Need Help?

If you have questions or need help installing TechIDManager for Microsoft Entra ID, contact: support@techidmanager.com

You can also book a support meeting through the TechIDManager website for assistance with your installation.