Home Knowledgebase Onboarding
Knowledgebase

Getting Onboarded

How to create your Alira workspace, connect it to your Microsoft Entra tenant, populate it with your resources, and provision your users — start to finish.

~20 min read
Global or Application Administrator required
Microsoft Entra ID P2 recommended
1
Create Workspace
2
Connect Entra
3
Add Resources
4
Provision Users

Support Scope

During the onboarding process, Kocho provides comprehensive support including configuration, validation, and hands-on training so your administrators can confidently manage Alira independently after go-live.

What’s included

  • Setup and configuration support
  • Validation and testing
  • Administrator training
  • Hyper-care support during rollout
  • Expedited bug remediation at go-live

What’s not included

  • Adding new resources post-onboarding
  • Managing users post-onboarding
  • Direct Entra configuration or management
  • Ongoing admin of Access Packages or PIM
Note: All administrative actions within Microsoft Entra remain the responsibility of your internal team. Kocho can advise on setup and best practice, but will not configure or manage components within your Entra environment.

Requirements

Licensing

For full access to all Alira features, your tenant should have one of the following Microsoft licence SKUs:

LicenceFull AccessNotes
Microsoft Entra ID P2Recommended — unlocks PIM, Access Packages, and all Alira features
Microsoft Entra ID GovernanceFull governance feature set
Microsoft Entra SuiteIncludes Entra ID P2 capabilities
Enterprise Mobility + Security E5Includes Entra ID P2
Microsoft 365 E5 / A5 / G5Includes Entra ID P2
Microsoft 365 F5 Security & ComplianceIncludes Entra ID P2
Microsoft Entra ID P1PartialApplications (MyApps) page only — PIM and Access Packages not available

Security — required roles

Global Administrator or Privileged Role Administrator

Required to grant tenant-wide admin consent and to approve OAuth permissions when logging in to Alira for the first time. Some tenants allow any user to approve — others require admin approval. Check your tenant’s consent settings before starting.

Application.ReadWrite.All permission

Required when creating the App Registration from within Alira. The signed-in user must hold an active role with this permission at the time of setup.

Entra resources needed per feature

Alira surfaces three core functions — Applications, Request, and Manage. Each draws from specific Entra resources:

Applications

Request

Manage

  • PIM Groups (where you are Owner)
  • PIM approvals and requests
  • Access Package approvals
1

Create a Workspace

The first step is creating your Alira workspace and signing in with your Entra ID account.

Sign in and create your workspace

  1. Navigate to alira.kocho.co.uk and click Sign in with Entra ID
  2. Sign in with your Entra account and complete any MFA requirements
  3. If this is your first login, you’ll see an OAuth Permissions Request. If you’ll be adding members to the app, tick Consent on behalf of your organisation before approving. You must hold an Application or Global Administrator role to do this.
  4. Once signed in, click Create Workspace
  5. Enter your desired Workspace Name and click Create Workspace
Tip: Choose a workspace name that reflects your organisation — this will be visible to users and administrators throughout the app.
2

Connect your Entra Tenant

After creating your workspace you’ll be taken to the Alira dashboard. The next step is connecting your Microsoft Entra tenant.

⚠ Important: Do not turn on Resource Synchronisation until you have completed the App Registration setup below. Enabling sync before the App Registration is configured will result in an incomplete or failed connection.

Create the App Registration

  1. In Alira, go to Settings → Sync
  2. Click Create App Registration
  3. A pop-up will appear — select the appropriate tenant from the Select Tenant dropdown
  4. Click Create App Registration to confirm
Required permission: The signed-in user must hold an active role with the Application.ReadWrite.All permission when performing this step.

Configure the App Registration and grant consent

After clicking Create you’ll be redirected to your Entra tenant to complete the setup.

  1. In the Entra Portal, go to Identity → Applications → App registrations
  2. Select All applications and sort by Created on
  3. Find the newly created App Registration named Alira Resource Sync (DATE) and click on it
  4. Go to API permissions
  5. Click ✔ Grant admin consent for {Tenant Name}
  6. Click Yes to confirm — the status for all API permissions will turn green
Note: Full details on the API permissions Alira requires and the justification for each are available from your Kocho onboarding contact.

Enable Resource Synchronisation

  1. Return to Alira and go to Settings → Sync
  2. Toggle Resource Synchronisation on
  3. Click Save
🎉 Your Entra tenant is now connected. Allow up to 15 minutes for Alira to pull your resources. To speed this up, go to Resources and force a manual sync.
3

Add Resources

The sync will pull all resources from your Entra tenant. To control what users see — and to filter out test, dev, or irrelevant resources — you organise them into Collections.

What are Collections?

Collections are folders for your resources

Think of a Collection as a named group of resources that share a purpose. They improve navigation, control what users can see and request, and let you define whether a resource is Access type (e.g. Salesforce Systems Administrator) or Software type (e.g. DocuSign). This type determines which tab the resource appears on in the Requests section.

Go to Access Portal → Resources → Collections to see the default Collections created for you. You can use these as-is or create your own.

Creating and editing a Collection

  1. Go to Access Portal → Resources → Collections and click Create Collection
  2. Enter a Name and Description for the collection
  3. Set the Type — either Access or Software
  4. Toggle Enabled if you want the collection visible immediately, or leave it off to populate it first
  5. Click Create Collection

Editing a Collection

  1. Click on any Collection to open it
  2. In the Basic Information section, click Edit to update the name, description or type
  3. Under Resources, mass-add or remove resources from the collection
  4. Update the Collection Icon with a relevant image to help users navigate
Best practice: Populate and test each collection before enabling it. This prevents users from seeing incomplete or incorrectly categorised resources.
4

Provision Users

User provisioning is handled via SCIM — a standard protocol that lets Entra automatically push users and roles into Alira. This controls who can access the app and what role they’ll have.

Create the SCIM Application

  1. In Alira go to Administration → Settings → SCIM
  2. Click Create SCIM App
  3. Select the appropriate tenant from the Select Tenant dropdown
  4. Optionally customise the Application name
  5. Click Create SCIM Application
  6. You’ll be redirected to authorise your OAuth credentials. Click Open in Azure Portal to go to the Enterprise Application
  7. In the Enterprise Application, click Provisioning and then Test Connection to confirm the connection is successful

Assign users and groups to Alira

  1. In Entra go to Identity → Enterprise Applications → (your SCIM app name)
  2. Go to Users and Groups and click Add user/group
  3. Under Users and Groups click None Selected and choose the users or groups you want to add to Alira
  4. Under Select a role click None Selected and assign the appropriate Alira role
  5. Click Assign
  6. To test provisioning before going live, go to Provisioning → Provision on Demand, select a test user or group, and click Provision
  7. A success page will confirm the attributes synced. Then check Alira → Administration → Members to see the provisioned user
  8. When ready to go live, return to Provisioning on the Enterprise Application and click Start provisioning
⚠ Multiple role grants are not supported. A user cannot be in two different groups mapped to different Alira roles on the same provisioning app. Assign each user to only one role group.

Use Dynamic Groups for automated role management

It’s strongly recommended to use Entra Dynamic Groups mapped to Alira roles rather than adding users directly. Dynamic Groups automatically add and remove users based on attributes — so when someone joins or leaves your organisation, their Alira access updates without any manual intervention.

🎉 Onboarding complete. Your users can now log in to Alira and access the resources you’ve configured. Your Kocho onboarding contact will walk through a final validation before formally signing off the onboarding phase.