I have an ASP.NET MVC website. Locally, and when deployed to Azure, it authenticates users in our organization with Azure Active Directory. Once authenticated, User.Identity is a System.Security.Claims.ClaimsIdentity.
I can query Dynamics CRM (hosted in the cloud, so Dynamics 365 CRM online) by embedding a username and password into the connection string and using Microsoft.Xrm.Tooling.Connector.CrmServiceClient namespace. The connection string looks like:
"Url=https://organization.crm.dynamics.com; Username=user@organizationURL.com; Password=passwordhere; authtype=Office365"
...but I want to avoid creating an application user account and I'd prefer to use the ambient security identity to connect to CRM as the authenticated user. How can I do this? Am I using the wrong SDK or package? I'm having a hard time finding a modern example or documentation that is intended for programmers rather than IT configuration.
When registering the website in Azure, I indicated that the user will need grant permission to interact with Dynamics CRM on their behalf, and I was prompted for this permission when I logged in, but as the programmer, I'm not sure how to actually use this permission.