You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
> These values are not real. Update these values with the actual Identifier, Reply URL and Sign on URL. Contact [LMS and Education Management System Leaf support team](mailto:[email protected]) to get these values. You can also refer to the patterns shown in the **Basic SAML Configuration** section in the Azure portal.
88
87
88
+
1. Your LMS and Education Management System Leaf application expects the SAML assertions in a specific format, which requires you to add custom attribute mappings to your SAML token attributes configuration. The following screenshot shows an example for this. The default value of **Unique User Identifier** is **user.userprincipalname** but LMS and Education Management System Leaf expects this to be mapped with the user's email address. For that you can use **user.mail** attribute from the list or use the appropriate attribute value based on your organization configuration.
89
+
90
+

91
+
89
92
1. On the **Set-up single sign-on with SAML** page, in the **SAML Signing Certificate** section, find **Federation Metadata XML** and select **Download** to download the certificate and save it on your computer.
90
93
91
94

@@ -124,7 +127,30 @@ To configure single sign-on on **LMS and Education Management System Leaf** side
124
127
125
128
### Create LMS and Education Management System Leaf test user
126
129
127
-
In this section, a user called B.Simon is created in LMS and Education Management System Leaf. LMS and Education Management System Leaf supports just-in-time user provisioning, which is enabled by default. There is no action item for you in this section. If a user doesn't already exist in LMS and Education Management System Leaf, a new one is created after authentication.
130
+
1. Log in as the Leaf system administrator user. From the **User tab** of **Master Maintenance**, create a user with a login ID of `leaftest`.
131
+
2. From the User tab of Master Maintenance, click the **SSO Information Bulk Registration** button.
132
+
3. Click the **Registration CSV** button to download the registration CSV.
133
+
4. Open the downloaded CSV, enter (Leaf) login ID, nameID format, authentication server, and save.
134
+
135
+

136
+
137
+

138
+
139
+
a. Please enter `leaftest` in the **(Leaf) Login ID** column.
140
+
141
+
b. In the Authentication Server column, enter the value corresponding to the Authentication Server in the above figure.
142
+
143
+
c. In the NameID format column, enter the value corresponding to **NameID format**.
144
+
145
+
d.Enter **leaftest@company。.extension** in the [NameID] column.
146
+
147
+
5. Click the **Select File** button and select the CSV you edited earlier.
148
+
6. Click the **Upload** button.
149
+
150
+
> [!NOTE]
151
+
> As a way to associate with Leaf, the login ID (user) on which Leaf is linked with the NameID (user)
152
+
and NameID format (format) on which IdP (authentication server) is specified.
153
+
128
154
129
155
## Test SSO
130
156
@@ -138,4 +164,4 @@ In this section, you test your Azure AD single sign-on configuration with follow
138
164
139
165
## Next steps
140
166
141
-
Once you configure LMS and Education Management System Leaf you can enforce session control, which protects exfiltration and infiltration of your organization’s sensitive data in real time. Session control extends from Conditional Access. [Learn how to enforce session control with Microsoft Cloud App Security](/cloud-app-security/proxy-deployment-aad).
167
+
Once you configure LMS and Education Management System Leaf you can enforce session control, which protects exfiltration and infiltration of your organization’s sensitive data in real time. Session control extends from Conditional Access. [Learn how to enforce session control with Microsoft Cloud App Security](/cloud-app-security/proxy-deployment-aad).
0 commit comments