<!DOCTYPE html>
<html>
<head>
<title>TreeSize verwenden > Einen SharePoint scannen > Azure AD Registrierung > Benutzerbasierte Authentifizierung</title>
<meta name=viewport content="width=device-width, initial-scale=1">
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />
<meta http-equiv="X-UA-Compatible" content="IE=edge" />
<meta name="generator" content="Help & Manual" />
<meta name="keywords" content="" />
<meta name="description" content="Wenn Sie eine benutzerbezogene Authentifizierung verwenden, müssen folgende Einstellungen in Ihrer Azure Registrierung vorgenommen werden: " />
<link type="text/css" href="default.css" rel="stylesheet" />
<link type="text/css" href="custom.css" rel="stylesheet" />
<style TYPE="text/css" media="screen">
html, body { margin:0;
padding:0;
background: #FFF;
font-family:"Segoe UI",Arial,Helvetica,sans-serif;
}
table,tr,th {font-family:"Segoe UI",Arial,Helvetica,sans-serif;}
div#printheader { display: none; }
#idheader {
width:100%;
height:auto;
padding: 0;
margin: 0;
position: fixed;
top: 0;
z-index: 2;
}
/* The "min-height" for "#idheader table" ensures that the (blue) header of the topic
has at least the same height as the header of the navigation panel left of it */
#idheader table {min-height: 72px; background: #F3F3F3;}
#idheader h1 { color: #252E30; }
#idnav {
text-align: right;
width: 126px;
vertical-align: middle;
}
#idnav a { text-decoration: none }
#idnav span {
display: inline-block;
width: 24px;
height: 24px;
margin-left: 4px;
background:url('hm_webhelp_buttons_white.png') top left no-repeat;
}
#idnav a span {
background-image:url('hm_webhelp_buttons_grey.png');
}
#idnav a span:hover {
background-image:url('hm_webhelp_buttons_black.png');
}
#idnav span.hmbtnprev { background-position: 0 -32px }
#idnav span.hmbtnnext { background-position: -24px -32px }
#idnav span.hmbtntop { background-position: -48px -32px }
#idnav span.hmbtntoggle { width: 20px; background-position: -70px -32px }
#idnav span.hmbtnprint { background-position: -88px -32px }
#callout-table, #overview-table {display:block; position:relative; top:0; left:0;}
#callout-icon {display:block; position:absolute; top:-11px; left:-11px;}
#callout-icon-flag {display:block; position:absolute; top:-11px; left:-8px;}
#callout-table a {text-decoration: none; color: blue;}
#callout-table a:visited {text-decoration: none; color: blue;}
#overview-table a {text-decoration: none; color: black;}
#overview-table a:visited {text-decoration: none; color: black;}
#callout-table a:hover, #overview-table a:hover {text-decoration: underline;}
p.help-url { margin: 20px 0 5px 0; text-align: center; font-size: 80%; text-decoration: none }
#switchtoggles { text-align: right; padding: 0 2px 0 0; font-size: 90%; }
.sync-toc { color: #252E30; font-size: 8pt; font-weight: bold; display: none; }
.sync-toc a { color: #252E30; text-decoration: none; font-weight: bold;}
.sync-toc a:visited { color: #252E30; }
.sync-toc a:hover { text-decoration: underline; }
a.hmanchor { display: inline-block; margin-top: 4em; padding-top: 4em }
</style>
<style TYPE="text/css" media="print">
div#idheader, img.dropdown-toggle-icon, p.help-url { display:none }
</style>
<script type="text/javascript" src="jquery.js"></script>
<script type="text/javascript" src="helpman_settings.js"></script>
<script type="text/javascript" src="helpman_topicinit.js"></script>
<script type="text/javascript">
HMSyncTOC("index.html", "userbased_auth.html");
</script>
<script type="text/javascript" src="highlight.js"></script>
<script type="text/javascript">
$(document).ready(function(){highlight();});
</script>
</head>
<body>
<div id="printheader"><h1 class="p_Heading1"><span class="f_Heading1">Benutzerbasierte Authentifizierung</span></h1>
</div>
<div id="idheader">
<div id="idheaderbg">
<table style="width:100%;border:none;margin:0px;" cellspacing="0" cellpadding="0">
<tr>
<td class="topichead" style="text-align:left; vertical-align:bottom">
<p class="sync-toc"><< <a rel="nofollow" href="index.html?userbased_auth.html" target="_top">Zum Inhaltsverzeichnis</a> >></p>
<p class="crumbs"><b>Navigation:</b>
<a href="using_treesize.html">TreeSize verwenden</a> > <a href="sharepoint.html">Einen SharePoint scannen</a> > <a href="azure-ad-configuration.html">Azure AD Registrierung</a> ></p>
<h1 class="p_Heading1"><span class="f_Heading1">Benutzerbasierte Authentifizierung</span></h1>
</td>
<td class="topichead" id="idnav">
<a href="certificatebased-auth.html" title="Vorheriges Thema"><span class="hmbtnprev"></span></a>
<a href="azure-ad-configuration.html" title="Vorheriges Kapitel"><span class="hmbtntop"></span></a>
<a href="options_dialog.html" title="Nächstes Thema"><span class="hmbtnnext"></span></a>
</td>
</tr>
</table>
</div>
</div>
<div id="idcontent"><div id="innerdiv">
<!-- Ask Internet Explorer 6.users to update their obsolete and dangerous browser -->
<!--[if lt IE 7]><div style=' clear: both; height: 59px; padding:0 0 0 15px; position: relative;'><a href="http://windows.microsoft.com/en-US/internet-explorer/products/ie/home?ocid=ie6_countdown_bannercode"><img src="http://storage.ie6countdown.com/assets/100/images/banners/warning_bar_0000_us.jpg" border="0" height="42" width="820" alt="You are using an outdated browser. For a faster, safer browsing experience, upgrade for free today." /></a></div><![endif]-->
<!--ZOOMRESTART-->
<p class="p_Normal">Wenn Sie eine benutzerbezogene Authentifizierung verwenden, müssen folgende Einstellungen in Ihrer Azure Registrierung vorgenommen werden: </p>
<p class="p_Normal"> </p>
<p class="p_Normal" style="text-indent: 0; padding-left: 20px; margin-left: 0;"><span class="f_Normal" style="display:inline-block;width:20px;margin-left:-20px">1.</span>Wählen Sie nun in der linken Navigationsliste den Punkt <span style="font-weight: bold;">API-Berechtigungen</span> und Sie klicken dort auf <span style="font-weight: bold;">Berechtigung hinzufügen</span>. </p>
<p class="p_Normal" style="text-indent: 0; padding-left: 40px; margin-left: 0;"><span class="f_Normal" style="font-family: Arial,'Lucida Sans Unicode','Lucida Grande','Lucida Sans';display:inline-block;width:20px;margin-left:-20px">•</span>Wählen Sie <span style="font-weight: bold;">SharePoint </span>aus. </p>
<p class="p_Normal" style="text-indent: 0; padding-left: 40px; margin-left: 0;"><span class="f_Normal" style="font-family: Arial,'Lucida Sans Unicode','Lucida Grande','Lucida Sans';display:inline-block;width:20px;margin-left:-20px">•</span>Konfigurieren Sie die Zugriffsrechte unter <span style="font-weight: bold;">Delegierte Berechtigungen </span>und bestätigen Sie die Einstellungen mit einem Klick auf <span style="font-weight: bold;">Fertig</span>.</p>
<p class="p_Normal" style="text-indent: 0; padding-left: 60px; margin-left: 0;"><span class="f_Normal" style="font-family: 'Courier New';display:inline-block;width:20px;margin-left:-20px">o</span>Wird eine Berechtigung hier nicht gewährt, kann ein Nutzer eine mit dieser Berechtigung verknüpfte Aktion mit TreeSize nicht durchführen, selbst wenn er dies in anderen Apps (z.B. dem SharePoint Web Interface) könnte.</p>
<p class="p_Normal" style="text-indent: 0; padding-left: 60px; margin-left: 0;"><span class="f_Normal" style="font-family: 'Courier New';display:inline-block;width:20px;margin-left:-20px">o</span>Wird eine Berechtigung hier gewährt, die dem angemeldeten Nutzer aus der zu SCannenden SharePoint Seite selbst nicht gewährt ist, kann er Aktionen, die diese Berechtigung benötigen, weiterhin nicht ausführen.</p>
<p class="p_Normal" style="text-indent: 0; padding-left: 60px; margin-left: 0;"><span class="f_Normal" style="font-family: 'Courier New';display:inline-block;width:20px;margin-left:-20px">o</span>Um auf SharePoint Seiten zugreifen zu können, wird die Berechtigung allSites.Manage benötigt. </p>
<p class="p_Normal" style="text-indent: 0; padding-left: 60px; margin-left: 0;"><span class="f_Normal" style="font-family: 'Courier New';display:inline-block;width:20px;margin-left:-20px">o</span>Um die Zeitstempel beim Hochladen von Dateien zu SharePoint zu erhalten, wird die Berechtigung allSites.FullControl benötigt. </p>
<p class="p_Normal" style="text-indent: 0; padding-left: 60px; margin-left: 0;"><span class="f_Normal" style="font-family: 'Courier New';display:inline-block;width:20px;margin-left:-20px">o</span>Soll der Zurgiff nur auf Dokumentbibliotheken eingeschränkt sein, ist die Berechtigung AllSites.Read ausreichend.</p>
<p class="p_Normal" style="text-indent: 0; padding-left: 60px; margin-left: 0;"><span class="f_Normal" style="font-family: 'Courier New';display:inline-block;width:20px;margin-left:-20px">o</span>Soll es auch möglich sein alle verknüpften Site Collections zu scannen, wird die Berechtigung '<span style="font-style: italic;">Sites.Search.All</span>' benötigt.</p>
<p class="p_Normal" style="text-indent: 0; padding-left: 60px; margin-left: 0;"><span class="f_Normal" style="font-family: 'Courier New';display:inline-block;width:20px;margin-left:-20px">o</span>Zum Schreiben bzw. Hochladen von Dateien, werden ggf. die Rechte '<span style="font-style: italic;">Read and write user files</span>' und '<span style="font-style: italic;">Read and write items and lists in all site collections</span>' benötigt.</p>
<p class="p_Normal" style="text-indent: 0; padding-left: 40px; margin-left: 0;"><span class="f_Normal" style="font-family: Arial,'Lucida Sans Unicode','Lucida Grande','Lucida Sans';display:inline-block;width:20px;margin-left:-20px">•</span>Klicken Sie abschließend auf <span style="font-weight: bold;">Berechtigungen hinzufügen</span>, um die geänderten Berechtigungen auf Ihren Account anzuwenden.</p>
<p class="p_Normal" style="text-indent: 0; padding-left: 40px; margin-left: 0;"><span class="f_Normal" style="font-family: Arial,'Lucida Sans Unicode','Lucida Grande','Lucida Sans';display:inline-block;width:20px;margin-left:-20px">•</span>Je nachdem, welche Berechtigungen sie gewählt haben, müssen diese durch einen Administrator bestätigt werden (<span style="font-weight: bold;">Administratorzustimmung erteilen</span>)</p>
<p class="p_Normal" style="text-indent: 0; padding-left: 20px; margin-left: 0;"><span class="f_Normal" style="display:inline-block;width:20px;margin-left:-20px">2.</span>Um<span style="font-weight: bold;"> SSO für Windows Systeme</span> die einer Domäne angehören (Windows Integrated Auth Flow) oder die über TreeSize eingegebenen Anmeldeinformationen verwenden zu können, muss die Option <span style="font-weight: bold;">Öffentliche Clientflows zulassen</span> unter <span style="font-weight: bold;">Authentifizierung -> Erweiterte Einstellungen</span> aktiviert sein. Alternativ kann auch direkt im <span style="font-weight: bold;">Manifest</span> der Wert von <span style="font-weight: bold;">allowPublicCLient</span> auf True gesetzt werden. </p>
<p class="p_Normal"> <img alt="Azure_Advanced_settings" width="891" height="280" style="margin:0;width:891px;height:280px;border:none" src="azure_advanced_settings.png"/></p>
<h1 class="p_Heading1" style="margin: 19px 0 19px 0;"><span class="f_Heading2">Benutzerberechtigungen und Berechtigungsstufen in SharePoint Server</span><br />
Damit ein Anwender SharePoint-Seiten mittels TreeSize scannen kann, müssen diesem hierzu in SharePoint bestimmte Berechtigungen gewährt werden. </h1>
<p class="p_Heading2" style="text-indent: 0; padding-left: 13px; margin-left: 0;"><span class="f_Normal" style="font-family: Arial,'Lucida Sans Unicode','Lucida Grande','Lucida Sans';display:inline-block;width:13px;margin-left:-13px">•</span>Ein Nutzer benötigt auf den Seiten die er scannen darf eine Berechtigungsstufe, die die Websiteberechtigung "Verzeichnisse durchsuchen" enthält.</p>
<p class="p_Heading2" style="text-indent: 0; padding-left: 13px; margin-left: 0;"><span class="f_Normal" style="font-family: Arial,'Lucida Sans Unicode','Lucida Grande','Lucida Sans';display:inline-block;width:13px;margin-left:-13px">•</span>Sollen die Standardberechtigungsstufen verwendet werden, benötigt der Nutzer auf diesen Seiten mindestens die Berechtigungsstufe "Mitwirken".</p>
<h2 class="p_Heading2">Bitte beachten Sie, dass die Rolle "SharePoint-Administrator" einem Nutzer nicht automatisch Zugriff auf alle Webseiten gewährt. Soll ein SharePoint-Administrator TreeSize zum Scannen von SharePoint-Seiten nutzen können, überprüfen Sie bitte auch hier die zugewiesenen Berechtigungsstufen. </h2>
<h2 class="p_Heading2"><span class="f_Heading2">Probleme bei der Authentifizierung</span></h2>
<p class="p_Heading2" style="text-indent: 0; padding-left: 13px; margin-left: 0;"><span class="f_Normal" style="font-size:12pt; font-family: Arial,'Lucida Sans Unicode','Lucida Grande','Lucida Sans';display:inline-block;width:13px;margin-left:-13px">•</span>Sollte sich ein Nutzer, trotz der vergebenen Berechtigungen, nicht über TreeSize mit SharePoint verbinden können, überprüfen Sie bitte ob dieser Nutzer eine gültige Office 365 Lizenz mit Zugriff auf die Microsoft Graph-API besitzt (z.B. Office 365 E3).<span style="font-size: 12pt; font-family: 'Times New Roman',Times,Georgia,serif;"> </span></p>
<!--ZOOMSTOP-->
</div></div>
<script type="text/javascript">
$(document).ready(function(){
$(window).bind('resize', function() {
var y = $('#idheader').height();
$('#idcontent').css('margin-top', y);
var par = window.parent;
if ($( par ).width() <= $( window ).width()+20) {
$('#idheader').css('position', 'relative');
$('#idcontent').css('margin-top', 0);
$('#idbacktotop').css('display', 'block');
$('.hmanchor').css('margin-top', -20);
$('.hmanchor').css('padding-top', 20);
}
else {
$('#idheader').css('position', 'fixed');
$('#idcontent').css('margin-top', $('#idheader').height());
$('#idbacktotop').css('display', 'none');
$('.hmanchor').css('margin-top', -y-20);
$('.hmanchor').css('padding-top', y+20);
}
});
if (/touch/i.test(navigator.userAgent)) {
$("a#printbuttonlink").hide();
$("div#idnav").css("width","126px");
}
$(window).resize(); //trigger event for initially small displays
});
if ((!parent.hmNavigationFrame) && (parent.location) && (parent.location.href)) { $('.sync-toc').show();$('p.crumbs').hide();}
</script>
</body>
</html>