/mcpas an Authz server. After configuring an Authz server, Unity Connection uses the authorization keys provided by the Authz server to validate the token of a Jabber client. If authorization keys are changed on Cisco Unified CM, you must synchronize the keys between Unity Connection and Authz server. You can configure multiple Authz server by providing the credential of Cisco Unified CM associated with the phone system. In multisite deployment where CUCM SME is installed, you can configure the publisher server (where Jabber end points are connected) of every leaf cluster as an Authz server for connecting with Unity Connection. Note To configure an Authz server, see Configuring an Authz Server in Unity Connection Consider the following points while configuring the Authz server in Unity Connection: • Make sure that OAuth Authorization Code Grant Flow feature is enabled on both Cisco Unified CM and Cisco Unity Connection. By default, the OAuth flow is disabled on Cisco Unity Connection. To enable the feature, navigate to System Settings > Enterprise Parameters in Cisco Unity Connection Administration. On Enterprise Parameters page, enter the applicable settings under SSO and OAuth Configuration field and select the Enabled option for OAuth with Refresh Login Flow. • The username and password entered for the Authz server must be same as the username and password of the system administrator of Cisco Unified CM. • The Tomcat services of Cisco Unified CM are up and running. • Make sure to upload the valid certificates of Cisco Unified CM to the tomcat trust of Cisco Unity Connection or check the Ignore Certificate Errors check box to ignore the certificate validation errors for the Authz server. For more information on certificates, see "Security" chapter of Cisco Unified Communications Operating System Administration Guide for Cisco Unity Connection Release 15 at https://www.cisco.com/c/en/us/ td/docs/voice_ip_comm/connection/15/os_administration/guide/b_15cucosagx.html. • The version of Jabber client must be 11.9 and later. • The version of Cisco Unified CM must be 11.5.1 SU3 and later. Configuring an Authz Server in Unity Connection To configure an Authz server in Unity Connection, do the following procedure: Procedure Step 1 In Cisco Unity Connection Administration, expand System Setting and select Authz Server. The Search Authz Server page appears displaying the currently configured Authz servers. Step 2 Configure an Authz server (For more information on each field, see Help> This Page): • To add an Authz server : a. Select Add New. The New Authz Server page appears. b. Enter the required information in the field. c. Select Save. System Administration Guide 240 System Settings Configuring an Authz Server in Unity Connection