You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/active-directory/saas-apps/insite-lms-provisioning-tutorial.md
+39-34Lines changed: 39 additions & 34 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,6 +1,6 @@
1
1
---
2
2
title: 'Tutorial: Configure Insite LMS for automatic user provisioning with Azure Active Directory'
3
-
description: Learn how to automatically provision and de-provision user accounts from Azure AD to Insite LMS.
3
+
description: Learn how to automatically provision and deprovision user accounts from Azure AD to Insite LMS.
4
4
services: active-directory
5
5
author: twimmers
6
6
writer: twimmers
@@ -16,7 +16,7 @@ ms.author: thwimmer
16
16
17
17
# Tutorial: Configure Insite LMS for automatic user provisioning
18
18
19
-
This tutorial describes the steps you need to do in both Insite LMS and Azure Active Directory (Azure AD) to configure automatic user provisioning. When configured, Azure AD automatically provisions and de-provisions users and groups to [Insite LMS](https://www.insite-it.net/) using the Azure AD Provisioning service. For important details on what this service does, how it works, and frequently asked questions, see [Automate user provisioning and deprovisioning to SaaS applications with Azure Active Directory](../app-provisioning/user-provisioning.md).
19
+
This tutorial describes the steps you need to do in both Insite LMS and Azure Active Directory (Azure AD) to configure automatic user provisioning. When configured, Azure AD automatically provisions and deprovisions users and groups to [Insite LMS](https://www.insite-it.net/) using the Azure AD Provisioning service. For important details on what this service does, how it works, and frequently asked questions, see [Automate user provisioning and deprovisioning to SaaS applications with Azure Active Directory](../app-provisioning/user-provisioning.md).
20
20
21
21
22
22
## Capabilities Supported
@@ -37,90 +37,95 @@ The scenario outlined in this tutorial assumes that you already have the followi
37
37
## Step 1. Plan your provisioning deployment
38
38
39
39
1. Learn about [how the provisioning service works](../app-provisioning/user-provisioning.md).
40
-
1. Determine who will be in [scope for provisioning](../app-provisioning/define-conditional-rules-for-provisioning-user-accounts.md).
40
+
1. Determine who is in [scope for provisioning](../app-provisioning/define-conditional-rules-for-provisioning-user-accounts.md).
41
41
1. Determine what data to [map between Azure AD and Insite LMS](../app-provisioning/customize-application-attributes.md).
42
42
43
43
## Step 2. Configure Insite LMS to support provisioning with Azure AD
44
+
To generate the Secret Token
44
45
45
-
1. Navigate to `https://portal.insitelms.net/<OrganizationName>`.
46
-
1. Download and install the Desktop Client.
47
-
1. Log in with your Admin Account and Navigate to **Users** Module.
48
-
1. Select the User `[email protected]` and press the button **Generate Access Token**. If you can't find the scim-User, contact the Support-Team
49
-
1. Choose **AzureAdScimProvisioning** and press **generate**
50
-
1. Copy the **AccessToken**
51
-
1. The **Tenant Url** is `https://web.insitelms.net/<OrganizationName>/api/scim`.
46
+
1. Login to [Insite LMS Admin Console](https://portal.insitelms.net/organization/applications).
47
+
1. Navigate to **Self Hosted Jobs**. You find a job named “SCIM”.
48
+
49
+

50
+
51
+
1. Click on **Generate Api Key**.
52
+
Copy and save the **Api Key**. This value is entered in the **Secret Token** field in the Provisioning tab of your Insite LMS application in the Azure portal.
53
+
54
+
>[!NOTE]
55
+
>The Access Token is only valid for 1 year.
52
56
53
57
## Step 3. Add Insite LMS from the Azure AD application gallery
54
58
55
59
Add Insite LMS from the Azure AD application gallery to start managing provisioning to Insite LMS. If you have previously setup Insite LMS for SSO, you can use the same application. However it's recommended that you create a separate app when testing out the integration initially. Learn more about adding an application from the gallery [here](../manage-apps/add-application-portal.md).
56
60
57
-
## Step 4. Define who will be in scope for provisioning
61
+
## Step 4. Define who is in scope for provisioning
58
62
59
-
The Azure AD provisioning service allows you to scope who will be provisioned based on assignment to the application and or based on attributes of the user / group. If you choose to scope who will be provisioned to your app based on assignment, you can use the following [steps](../manage-apps/assign-user-or-group-access-portal.md) to assign users and groups to the application. If you choose to scope who will be provisioned based solely on attributes of the user or group, you can use a scoping filter as described [here](../app-provisioning/define-conditional-rules-for-provisioning-user-accounts.md).
63
+
The Azure AD provisioning service allows you to scope who is provisioned based on assignment to the application and or based on attributes of the user / group. If you choose to scope who is provisioned to your app based on assignment, you can use the following [steps](../manage-apps/assign-user-or-group-access-portal.md) to assign users and groups to the application. If you choose to scope who is provisioned based solely on attributes of the user or group, you can use a scoping filter as described [here](../app-provisioning/define-conditional-rules-for-provisioning-user-accounts.md).
60
64
61
65
* Start small. Test with a small set of users and groups before rolling out to everyone. When scope for provisioning is set to assigned users and groups, you can control this by assigning one or two users or groups to the app. When scope is set to all users and groups, you can specify an [attribute based scoping filter](../app-provisioning/define-conditional-rules-for-provisioning-user-accounts.md).
62
66
63
-
* If you need additional roles, you can [update the application manifest](../develop/howto-add-app-roles-in-azure-ad-apps.md) to add new roles.
67
+
* If you need more roles, you can [update the application manifest](../develop/howto-add-app-roles-in-azure-ad-apps.md) to add new roles.
64
68
65
69
66
-
## Step 5. Configure automatic user provisioning to Insite LMS
70
+
## Step 5. Configure automatic user provisioning to Insite LMS
67
71
68
72
This section guides you through the steps to configure the Azure AD provisioning service to create, update, and disable users and/or groups in Insite LMS app based on user and group assignments in Azure AD.
69
73
70
74
### To configure automatic user provisioning for Insite LMS in Azure AD:
71
75
72
76
1. Sign in to the [Azure portal](https://portal.azure.com). Select **Enterprise Applications**, then select **All applications**.

87
91
88
-
1. In the **Admin Credentials** section, enter your Insite LMS **Tenant URL** and **Secret token** information. Select **Test Connection** to ensure that Azure AD can connect to Insite LMS. If the connection fails, ensure that your Insite LMS account has admin permissions and try again.
92
+
1. In the **Admin Credentials** section,
93
+
enter your Insite LMS **Tenant URL** as `https://api.insitelms.net/scim` and enter the **Secret token** generated in Step 2 above. Select **Test Connection** to ensure that Azure AD can connect to Insite LMS. If the connection fails, ensure that your Insite LMS account has admin permissions and try again.

91
96
92
97
1. In the **Notification Email** field, enter the email address of a person or group who should receive the provisioning error notifications. Select the **Send an email notification when a failure occurs** check box.

95
100
96
101
1. Select **Save**.
97
102
98
103
1. In the **Mappings** section, select **Synchronize Azure Active Directory Users to Insite LMS**.
99
104
100
-
1. Review the user attributes that are synchronized from Azure AD to Insite LMS in the **Attribute Mapping** section. The attributes selected as **Matching** properties are used to match the user accounts in Insite LMS for update operations. If you change the [matching target attribute](../app-provisioning/customize-application-attributes.md), you'll need to ensure that the Insite LMS API supports filtering users based on that attribute. Select **Save** to commit any changes.
105
+
1. Review the user attributes that are synchronized from Azure AD to Insite LMS in the **Attribute Mapping** section. The attributes selected as **Matching** properties are used to match the user accounts in Insite LMS for update operations. If you change the [matching target attribute](../app-provisioning/customize-application-attributes.md), you need to ensure that the Insite LMS API supports filtering users based on that attribute. Select **Save** to commit any changes.
101
106
102
-
|Attribute|Type|Supported for filtering|
103
-
|---|---|---|
104
-
|userName|String|✓|
105
-
|emails[type eq "work"].value|String|✓|
106
-
|active|Boolean|
107
-
|name.givenName|String|
108
-
|name.familyName|String|
109
-
|phoneNumbers[type eq "work"].value|String|
107
+
|Attribute|Type|Supported for filtering|Required by Insite LMS|
1. To configure scoping filters, see the instructions provided in the [Scoping filter tutorial](../app-provisioning/define-conditional-rules-for-provisioning-user-accounts.md).
112
117
113
118
1. To enable the Azure AD provisioning service for Insite LMS, change **Provisioning Status** to **On** in the **Settings** section.
114
119
115
-

120
+

116
121
117
122
1. Define the users or groups that you want to provision to Insite LMS by selecting the desired values in **Scope** in the **Settings** section.

124
129
125
130
This operation starts the initial synchronization cycle of all users and groups defined in **Scope** in the **Settings** section. The initial cycle takes longer to do than next cycles, which occur about every 40 minutes as long as the Azure AD provisioning service is running.
126
131
@@ -130,7 +135,7 @@ After you've configured provisioning, use the following resources to monitor you
130
135
131
136
* Use the [provisioning logs](../reports-monitoring/concept-provisioning-logs.md) to determine which users were provisioned successfully or unsuccessfully.
132
137
* Check the [progress bar](../app-provisioning/application-provisioning-when-will-provisioning-finish-specific-user.md) to see the status of the provisioning cycle and how close it's to completion.
133
-
* If the provisioning configuration seems to be in an unhealthy state, the application will go into quarantine. To learn more about quarantine states, see [Application provisioning status of quarantine](../app-provisioning/application-provisioning-quarantine-status.md).
138
+
* If the provisioning configuration seems to be in an unhealthy state, the application goes into quarantine. To learn more about quarantine states, see [Application provisioning status of quarantine](../app-provisioning/application-provisioning-quarantine-status.md).
0 commit comments