Azure AD authentication with card registration

This topic describes options for using Azure AD authentication with card registration.

When Azure AD is enabled with ControlSuite, users can register their cards by authenticating against Azure AD, if that option is selected as an authentication method for the Unified Client for Ricoh. When the registration is complete, users swipe their cards again to log in.

Depending on the login configuration, a user can select between more than one authentication method.

  • If Azure AD is the only configured method for unknown card registration, when the user swipes their card for the first time, the device screen displays a QR code and an alphanumeric code. The user scans the QR code to open the Microsoft login site, or enters the URL in a browser not on the device, enters the code, and selects their account. When returning to the device, the card is registered to the user.
  • If Azure AD is enabled alongside at least one more method of card registration, such as Card ID or username/password, after swiping their card for the first time, the user is prompted to choose their authentication method and can then select Azure AD as the Authentication Method. When the user clicks Login, the QR code and alphanumeric code appears.
  • If Azure AD is enabled alongside either PIN required with card swipe or PIN required with manual card ID, then the user receives an additional prompt before the QR code and alphanumeric code appear.
  • If you do not complete the authentication within 5 minutes, the Output Manager server closes the user session and ends the card registration. The alphanumeric code resets after 5 minutes.
  • If the authentication is not performed within that time, the registration ends and a new alphanumeric code is issued during the next attempt at registration.