Modern authentication
To use modern authentication in your eCopy ShareScan connectors and email watchers, you need to perform a configuration process that combines tasks in the Token Vault tool as well as in the eCopy ShareScan Administration Console and third-party interfaces.
Overview
- Ensure that you have Token Vault installed along with eCopy ShareScan. (Verify if you must install the two programs on different servers - this depends on your deployment scenario.)
- Configure the Token Vault application.
- As the use of modern authentication requires active end-user participation (in the
authorization step on the Token Vault Available authorization providers page) it is
a best practice to clearly communicate this task and set expectations - especially
if an end-user tries to use connectors with modern authentication and fails. To
provide guidance in such situations ensure that you configure the ShareScan
Notification service and turn it on for
- NetDocuments connector profiles
- Exchange connector profiles configured with Exchange Online and modern authentication
- SharePoint connector profiles configured with SharePoint Online and modern authentication
- iManage Worksite connector profiles configured with iManage Cloud or iManage Work 10.3 or later and REST API protocol (modern authentication (OAuth2))
Important As access tokens might expire during extended idle periods for the connector, end-users may need to perform the authorization steps again at a later time.
Tasks to complete to use Modern Authentication in an Exchange, a Fax via Exchange or a SharePoint eCopy connector
- Go to the Microsoft Identity Platform (Azure Active Directory) admin center associated with your Microsoft 365 subscription and register a Microsoft 365 application for Token Vault. (This step enables Token Vault to get authentication tokens for applications - such as eCopy ShareScan connectors.)
- Log in to Token Vault as an administrator, select the Manage authorization
providers page and register a new Authorization Provider for Microsoft 365 cloud
provider.
In this step Token Vault generates an Authorization Provider ID that you will need to use when configuring your workflow in the eCopy Administration Console.
- Enable the new Authorization Provider and then authorize it on the Available authorization providers page.
- Launch the ShareScan Administration Console, go to Tools and specify Token Vault Settings (using the Authorization Provider ID that Token Vault generated previously).
- Still in the Administration Console, enable Modern authentication for your Exchange, or Fax via Exchange connector via the setting Use Exchange Online with modern authentication or SharePoint connector via the setting Enable modern authentication and configure accordingly.
- At this point you are ready to invite your end-users to carry out their own authorization step through Token Vault. Once this end-user authorization step is complete, the use of modern authentication in the supported connectors is operational.
Tasks to complete to use a NetDocuments connector
- Go to the NetDocuments portal and register an application for Token Vault. (This step enables Token Vault to get authentication tokens for applications - such as eCopy ShareScan connectors.)
- Log in to Token Vault as an administrator and register a new Authorization Provider
for NetDocuments cloud provider.
In this step Token Vault generates an Authorization Provider ID that you need to use while you are configuring Token Vault through the eCopy Administration Console.
- Enable the new Authorization Provider and then authorize it on the Available authorization providers page.
- Launch the ShareScan Administration Console, go to Tools and specify Token Vault Settings (using the Authorization Provider ID that Token Vault generated previously).
- Still in the Administration Console, configure your NetDocuments connector. (In the NetDocuments connector, modern authentication is the only available authentication method.)
- At this point you are ready to invite your end-users to carry out their own authorization step through Token Vault. Once this end-user authorization step is complete, the use of modern authentication in the supported connectors is operational.
Tasks to complete to use Modern Authentication in an iManage Worksite connector
- Contact the iManage Help Center (https://help.imanage.com/) and submit a new application registration request in case of iManage Cloud or go to the iManage Control Center of your on-premise iManage Work server and register an application for Token Vault. (This step enables Token Vault to get authentication tokens for applications.)
- Log in to Token Vault as an administrator and register a new Authorization Provider
for iManage Work (cloud) provider.
In this step Token Vault generates an Authorization Provider ID that you need to use while you are configuring Token Vault through the eCopy Administration Console.
- Enable the new Authorization Provider and then authorize it on the Available authorization providers page.
- Launch the ShareScan Administration Console, go to Tools and specify Token Vault Settings (using the Authorization Provider ID that Token Vault generated previously).
- Still in the Administration Console, enable Modern Authentication for your Worksite connector by selecting REST API as the Protocol setting value and configure accordingly.
- At this point you are ready to invite your end-users to carry out their own authorization step through Token Vault. Once this end-user authorization step is complete, the workflow with modern authentication is ready to use.
Tasks to complete to use Modern Authentication in email inbox watchers via POP3/IMAP using Microsoft 365 POP/IMAP server
- Go to the Microsoft Identity Platform (Azure Active Directory) admin center associated with your Microsoft 365 subscription and register a Microsoft 365 application for Token Vault. (This step enables Token Vault to get authentication tokens for applications - such as eCopy ShareScan email inbox watchers.)
- Log in to Token Vault as an administrator, select the Manage authorization providers page and register a new Authorization Provider for Microsoft 365 cloud provider.
- In this step Token Vault generates an Authorization Provider ID that you will need to use when configuring your workflow in the eCopy Administration Console.
- Enable the new Authorization Provider and then authorize it on the Available authorization providers page.
- Launch the ShareScan Administration Console, go to Tools and specify Token Vault Settings (using the Authorization Provider ID that Token Vault generated previously).
- Still in the Administration Console, enable Modern authentication for your email inbox watcher via POP3 or your email inbox watcher via IMAP via the E-Mail Server, Port, Security and Use Modern Authentication watcher settings and configure accordingly.
- Once the configuration steps are complete, the workflow with modern authentication is ready to use.
To ensure that you can quickly orient yourself in reference to where you currently are in the overall process, relevant help topics in the current documentation use the following visual aids:
![]() |
Perform the steps in this topic at the Microsoft Identity Platform (Azure Active Directory) admin center |
![]() |
Complete steps in this topic only after you finished the required configuration process at the Microsoft Identity Platform (Azure Active Directory) admin center |
|
![]() |
Perform the steps in this topic at the NetDocuments portal |
![]() |
Complete steps in this topic only after you finished the required configuration process at the NetDocuments portal |
|
![]() |
Perform the steps in this topic in Token Vault with a Token Vault administrator |
![]() |
Complete steps in this topic only after you finished the required configuration process in Token Vault with a Token Vault administrator |
|
![]() |
Perform the steps in this topic on the Token Vault Available authorization providers page |
![]() |
Complete steps in this topic only after you finished the required configuration process on the Token Vault Available authorization providers page |
|
![]() |
Perform the steps in this topic in the eCopy ShareScan Administration Console |