You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/active-directory/fundamentals/8-secure-access-sensitivity-labels.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -63,7 +63,7 @@ As you plan the governance of external access to your content, consider content,
63
63
64
64
To define High, Medium, or Low Business Impact (HBI, MBI, LBI) for data, sites, and groups, consider the effect on your organization if the wrong content types are shared.
65
65
66
-
* Credit card, passport, national-ID numbers
66
+
* Credit card, passport, national/regional ID numbers
67
67
*[Apply a sensitivity label to content automatically](/microsoft-365/compliance/apply-sensitivity-label-automatically?view=o365-worldwide&preserve-view=true)
68
68
* Content created by corporate officers: compliance, finance, executive, etc.
69
69
* Strategic or financial data in libraries or sites.
title: Azure Active Directory SSO integration with Cisco Unity Connection
3
+
description: Learn how to configure single sign-on between Azure Active Directory and Cisco Unity Connection.
4
+
services: active-directory
5
+
author: jeevansd
6
+
manager: CelesteDG
7
+
ms.reviewer: CelesteDG
8
+
ms.service: active-directory
9
+
ms.subservice: saas-app-tutorial
10
+
ms.workload: identity
11
+
ms.topic: how-to
12
+
ms.date: 05/05/2023
13
+
ms.author: jeedes
14
+
15
+
---
16
+
17
+
# Azure Active Directory SSO integration with Cisco Unity Connection
18
+
19
+
In this article, you learn how to integrate Cisco Unity Connection with Azure Active Directory (Azure AD). Cisco Unity Connection is a robust unified messaging and voicemail solution that provides users with flexible message access options including support for voice commands, STT transcriptions etc. When you integrate Cisco Unity Connection with Azure AD, you can:
20
+
21
+
* Control in Azure AD who has access to Cisco Unity Connection.
22
+
* Enable your users to be automatically signed-in to Cisco Unity Connection with their Azure AD accounts.
23
+
* Manage your accounts in one central location - the Azure portal.
24
+
25
+
You configure and test Azure AD single sign-on for Cisco Unity Connection in a test environment. Cisco Unity Connection supports **SP** initiated single sign-on.
26
+
27
+
## Prerequisites
28
+
29
+
To integrate Azure Active Directory with Cisco Unity Connection, you need:
30
+
31
+
* An Azure AD user account. If you don't already have one, you can [Create an account for free](https://azure.microsoft.com/free/?WT.mc_id=A261C142F).
32
+
* One of the following roles: Global Administrator, Cloud Application Administrator, Application Administrator, or owner of the service principal.
33
+
* An Azure AD subscription. If you don't have a subscription, you can get a [free account](https://azure.microsoft.com/free/).
34
+
* Cisco Unity Connection single sign-on (SSO) enabled subscription.
35
+
36
+
## Add application and assign a test user
37
+
38
+
Before you begin the process of configuring single sign-on, you need to add the Cisco Unity Connection application from the Azure AD gallery. You need a test user account to assign to the application and test the single sign-on configuration.
39
+
40
+
### Add Cisco Unity Connection from the Azure AD gallery
41
+
42
+
Add Cisco Unity Connection from the Azure AD application gallery to configure single sign-on with Cisco Unity Connection. For more information on how to add application from the gallery, see the [Quickstart: Add application from the gallery](../manage-apps/add-application-portal.md).
43
+
44
+
### Create and assign Azure AD test user
45
+
46
+
Follow the guidelines in the [create and assign a user account](../manage-apps/add-application-portal-assign-users.md) article to create a test user account in the Azure portal called B.Simon.
47
+
48
+
Alternatively, you can also use the [Enterprise App Configuration Wizard](https://portal.office.com/AdminPortal/home?Q=Docs#/azureadappintegration). In this wizard, you can add an application to your tenant, add users/groups to the app, and assign roles. The wizard also provides a link to the single sign-on configuration pane in the Azure portal. [Learn more about Microsoft 365 wizards.](/microsoft-365/admin/misc/azure-ad-setup-guides).
49
+
50
+
## Configure Azure AD SSO
51
+
52
+
Complete the following steps to enable Azure AD single sign-on in the Azure portal.
53
+
54
+
1. In the Azure portal, on the **Cisco Unity Connection** application integration page, find the **Manage** section and select **single sign-on**.
55
+
1. On the **Select a single sign-on method** page, select **SAML**.
56
+
1. On the **Set up single sign-on with SAML** page, select the pencil icon for **Basic SAML Configuration** to edit the settings.
57
+
58
+

59
+
60
+
1. On the **Basic SAML Configuration** section, if you have **Service Provider metadata file** then perform the following steps:
61
+
62
+
a. Click **Upload metadata file**.
63
+
64
+

65
+
66
+
b. Click on **folder logo** to select the metadata file and click **Upload**.
67
+
68
+

69
+
70
+
c. After the metadata file is successfully uploaded, the **Identifier** and **Reply URL** values get auto populated in Basic SAML Configuration section.
71
+
72
+
d. In the **Sign on URL** textbox, type a URL using the following pattern:
73
+
`https://<FQDN_CUC_node>`
74
+
75
+
> [!Note]
76
+
> You will get the **Service Provider metadata file** from the [Cisco Unity Connection support team](mailto:[email protected]). If the **Identifier** and **Reply URL** values do not get auto populated, then fill the values manually according to your requirement.
77
+
78
+
1. Cisco Unity Connection application expects the SAML assertions in a specific format, which requires you to add custom attribute mappings to your SAML token attributes configuration. The following screenshot shows the list of default attributes.
79
+
80
+

81
+
82
+
1. In addition to above, Cisco Unity Connection application expects few more attributes to be passed back in SAML response which are shown below. These attributes are also pre populated but you can review them as per your requirements.
83
+
84
+
| Name | Source Attribute|
85
+
| ---------------| --------- |
86
+
| uid | user.onpremisessamaccountname |
87
+
88
+
1. On the **Set-up single sign-on with SAML** page, in the **SAML Signing Certificate** section, find **Federation Metadata XML** and select **Download** to download the certificate and save it on your computer.
89
+
90
+

91
+
92
+
1. On the **Set up Cisco Unity Connection** section, copy the appropriate URL(s) based on your requirement.
93
+
94
+

95
+
96
+
## Configure Cisco Unity Connection SSO
97
+
98
+
To configure single sign-on on **Cisco Unity Connection** side, you need to send the downloaded **Federation Metadata XML** and appropriate copied URLs from Azure portal to [Cisco Unity Connection support team](mailto:[email protected]). They set this setting to have the SAML SSO connection set properly on both sides.
99
+
100
+
### Create Cisco Unity Connection test user
101
+
102
+
In this section, you create a user called Britta Simon in Cisco Unity Connection. Work with [Cisco Unity Connection support team](mailto:[email protected]) to add the users in the Cisco Unity Connection platform. Users must be created and activated before you use single sign-on.
103
+
104
+
## Test SSO
105
+
106
+
In this section, you test your Azure AD single sign-on configuration with following options.
107
+
108
+
* Click on **Test this application** in Azure portal. This will redirect to Cisco Unity Connection Sign-on URL where you can initiate the login flow.
109
+
110
+
* Go to Cisco Unity Connection Sign-on URL directly and initiate the login flow from there.
111
+
112
+
* You can use Microsoft My Apps. When you click the Cisco Unity Connection tile in the My Apps, this will redirect to Cisco Unity Connection Sign-on URL. For more information about the My Apps, see [Introduction to the My Apps](../user-help/my-apps-portal-end-user-access.md).
113
+
114
+
## Additional resources
115
+
116
+
*[What is single sign-on with Azure Active Directory?](../manage-apps/what-is-single-sign-on.md)
117
+
*[Plan a single sign-on deployment](../manage-apps/plan-sso-deployment.md).
118
+
119
+
## Next steps
120
+
121
+
Once you configure Cisco Unity Connection you can enforce session control, which protects exfiltration and infiltration of your organization’s sensitive data in real time. Session control extends from Conditional Access. [Learn how to enforce session control with Microsoft Cloud App Security](/cloud-app-security/proxy-deployment-aad).
Copy file name to clipboardExpand all lines: articles/aks/deploy-marketplace.md
+78-10Lines changed: 78 additions & 10 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,14 +1,14 @@
1
1
---
2
-
title: Deploy an Azure container offer from Azure Marketplace
3
-
description: Learn how to deploy Azure container offers from Azure Marketplace on an Azure Kubernetes Service (AKS) cluster.
2
+
title: Deploy a Kubernetes application from Azure Marketplace
3
+
description: Learn how to deploy Kubernetes applications from Azure Marketplace on an Azure Kubernetes Service (AKS) cluster.
4
4
author: nickomang
5
5
ms.author: nickoman
6
6
ms.topic: how-to
7
-
ms.date: 09/30/2022
7
+
ms.date: 05/01/2023
8
8
ms.custom: ignite-fall-2022, references_regions
9
9
---
10
10
11
-
# Deploy a container offer from Azure Marketplace (preview)
11
+
# Deploy a Kubernetes application from Azure Marketplace (preview)
12
12
13
13
[Azure Marketplace][azure-marketplace] is an online store that contains thousands of IT software applications and services built by industry-leading technology companies. In Azure Marketplace, you can find, try, buy, and deploy the software and services that you need to build new solutions and manage your cloud infrastructure. The catalog includes solutions for different industries and technical areas, free trials, and consulting services from Microsoft partners.
14
14
@@ -39,7 +39,7 @@ This feature is currently supported only in the following regions:
39
39
- Australia East
40
40
- Central India
41
41
42
-
Kubernetes application-based container offers cannot be deployed on AKS for Azure Stack HCI or AKS Edge Essentials.
42
+
Kubernetes application-based container offers can't be deployed on AKS for Azure Stack HCI or AKS Edge Essentials.
43
43
44
44
## Register resource providers
45
45
@@ -52,6 +52,32 @@ az provider register --namespace Microsoft.KubernetesConfiguration --wait
52
52
53
53
## Select and deploy a Kubernetes offer
54
54
55
+
### From the AKS portal screen
56
+
57
+
1. In the [Azure portal](https://portal.azure.com/), you can deploy a Kubernetes application from an existing cluster by navigating to **Marketplace** or selecting **Extensions + applications**, then selecting **+ Add**.
58
+
59
+
:::image type="content" source="./media/deploy-marketplace/add-inline.png" alt-text="The Azure portal page for the A K S cluster is shown. 'Extensions + Applications' is selected, and '+ Add' is highlighted." lightbox="./media/deploy-marketplace/add.png":::
60
+
61
+
1. You can search for an offer or publisher directly by name, or you can browse all offers.
62
+
63
+
:::image type="content" source="./media/deploy-marketplace/marketplace-view-inline.png" alt-text="Screenshot of Kubernetes offers in the Azure portal." lightbox="./media/deploy-marketplace/marketplace-view.png":::
64
+
65
+
1. After you decide on an application, select the offer.
66
+
67
+
1. On the **Plans + Pricing** tab, select an option. Ensure that the terms are acceptable, and then select **Create**.
68
+
69
+
:::image type="content" source="./media/deploy-marketplace/plan-pricing.png" alt-text="Screenshot of the offer purchasing page in the Azure portal, showing plan and pricing information.":::
70
+
71
+
1. Follow each page in the wizard, all the way through Review + Create. Fill in information for your resource group, your cluster, and any configuration options that the application requires. You can decide to deploy on a new AKS cluster or use an existing cluster.
72
+
73
+
:::image type="content" source="./media/deploy-marketplace/review-create.png" alt-text="Screenshot of the Azure portal wizard for deploying a new offer, with the selector for creating a cluster or using an existing one.":::
74
+
75
+
1. When the application is deployed, the portal shows your deployment in progress, along with details.
76
+
77
+
:::image type="content" source="./media/deploy-marketplace/deploying.png" alt-text="Screenshot of the Azure portal deployments screen, showing that the Kubernetes offer is currently being deployed.":::
78
+
79
+
### From the Marketplace portal screen
80
+
55
81
1. In the [Azure portal](https://portal.azure.com/), search for **Marketplace** on the top search bar. In the results, under **Services**, select **Marketplace**.
56
82
57
83
1. You can search for an offer or publisher directly by name, or you can browse all offers. To find Kubernetes application offers, on the left side under **Categories** select **Containers**.
@@ -61,9 +87,9 @@ az provider register --namespace Microsoft.KubernetesConfiguration --wait
61
87
> [!IMPORTANT]
62
88
> The **Containers** category includes both Kubernetes applications and standalone container images. This walkthrough is specific to Kubernetes applications. If you find that the steps to deploy an offer differ in some way, you're most likely trying to deploy a container image-based offer instead of a Kubernetes application-based offer.
63
89
64
-
1. You will see several Kubernetes application offers displayed on the page. To view all of the Kubernetes application offers, select **See more**.
90
+
1. You'll see several Kubernetes application offers displayed on the page. To view all of the Kubernetes application offers, select **See more**.
65
91
66
-
:::image type="content" source="./media/deploy-marketplace/see-more-inline.png" alt-text="Screenshot of Azure Marketplace K8s offers in the Azure portal" lightbox="./media/deploy-marketplace/see-more.png":::
92
+
:::image type="content" source="./media/deploy-marketplace/see-more-inline.png" alt-text="Screenshot of Azure Marketplace K8s offers in the Azure portal. 'See More' is highlighted." lightbox="./media/deploy-marketplace/see-more.png":::
67
93
68
94
1. After you decide on an application, select the offer.
69
95
@@ -79,22 +105,54 @@ az provider register --namespace Microsoft.KubernetesConfiguration --wait
79
105
80
106
:::image type="content" source="./media/deploy-marketplace/deployment-inline.png" alt-text="Screenshot of the Azure portal that shows a successful resource deployment to the cluster." lightbox="./media/deploy-marketplace/deployment-full.png":::
81
107
82
-
1. Verify the deployment by using the following command to list the extensions that are running on your cluster:
108
+
## Verify the deployment
109
+
110
+
### [Azure CLI](#tab/azure-cli)
111
+
112
+
Verify the deployment by using the following command to list the extensions that are running on your cluster:
83
113
84
114
```azurecli-interactive
85
115
az k8s-extension list --cluster-name <clusterName> --resource-group <resourceGroupName> --cluster-type managedClusters
86
116
```
87
117
118
+
### [Portal](#tab/azure-portal)
119
+
120
+
Verify the deployment navigating to the cluster you recently installed the extension on, then navigate to "Extensions + Applications", where you'll see the extension status:
121
+
122
+
:::image type="content" source="./media/deploy-marketplace/verify-inline.png" lightbox="./media/deploy-marketplace/verify.png" alt-text="The Azure portal page for the A K S cluster is shown. 'Extensions + Applications' is selected, and the deployed extension is listed.":::
123
+
124
+
---
125
+
88
126
## Manage the offer lifecycle
89
127
90
128
For lifecycle management, an Azure Kubernetes offer is represented as a cluster extension for AKS. For more information, see [Cluster extensions for AKS][cluster-extensions].
91
129
92
-
Purchasing an offer from Azure Marketplace creates a new instance of the extension on your AKS cluster. You can view the extension instance from the cluster by using the following command:
130
+
Purchasing an offer from Azure Marketplace creates a new instance of the extension on your AKS cluster.
131
+
132
+
### [Azure CLI](#tab/azure-cli)
133
+
134
+
You can view the extension instance from the cluster by using the following command:
93
135
94
136
```azurecli-interactive
95
137
az k8s-extension show --name <extension-name> --cluster-name <clusterName> --resource-group <resourceGroupName> --cluster-type managedClusters
96
138
```
97
139
140
+
### [Portal](#tab/azure-portal)
141
+
142
+
First, navigate to an existing cluster, then select "Extensions + applications":
143
+
144
+
:::image type="content" source="./media/deploy-marketplace/cluster-view.png" alt-text="The Azure portal page for the A K S cluster. 'Extensions + Applications' is highlighted.":::
145
+
146
+
You'll see your recently installed extensions listed:
147
+
148
+
:::image type="content" source="./media/deploy-marketplace/verify-inline.png" lightbox="./media/deploy-marketplace/verify.png" alt-text="The Azure portal page for the A K S cluster. 'Extensions + Applications' is selected, and deployed extensions are listed.":::
149
+
150
+
Select an extension name to navigate to a properties view where you're able to disable auto upgrades, check the provisioning state, delete the extension instance, or modify configuration settings as needed.
151
+
152
+
:::image type="content" source="./media/deploy-marketplace/properties.png" alt-text="The Azure portal page for extension properties.":::
153
+
154
+
---
155
+
98
156
## Monitor billing and usage information
99
157
100
158
To monitor billing and usage information for the offer that you deployed:
@@ -107,12 +165,22 @@ To monitor billing and usage information for the offer that you deployed:
107
165
108
166
## Remove an offer
109
167
110
-
You can delete a purchased plan for an Azure container offer by deleting the extension instance on the cluster. For example:
168
+
You can delete a purchased plan for an Azure container offer by deleting the extension instance on the cluster.
Select an application, then select the uninstall button to remove the extension from your cluster:
179
+
180
+
:::image type="content" source="./media/deploy-marketplace/uninstall-inline.png" alt-text="The Azure portal page for the A K S cluster is shown. The deployed extension is listed with the 'uninstall' button highlighted." lightbox="./media/deploy-marketplace/uninstall.png":::
181
+
182
+
---
183
+
116
184
## Troubleshooting
117
185
118
186
If you experience issues, see the [troubleshooting checklist for failed deployments of a Kubernetes offer][marketplace-troubleshoot].
0 commit comments