You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/active-directory/saas-apps/tanium-sso-provisioning-tutorial.md
+10-8Lines changed: 10 additions & 8 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -16,7 +16,7 @@ ms.author: thwimmer
16
16
17
17
# Tutorial: Configure Tanium SSO for automatic user provisioning
18
18
19
-
This tutorial describes the steps you need to perform in both Tanium SSO and Azure Active Directory (Azure AD) to configure automatic user provisioning. When configured, Azure AD automatically provisions and de-provisions users and groups to [Tanium SSO](https://www.tanium.com/) using the Azure AD Provisioning service. For important details on what this service does, how it works, and frequently asked questions, see [Automate user provisioning and deprovisioning to SaaS applications with Azure Active Directory](../app-provisioning/user-provisioning.md).
19
+
This tutorial describes the steps you need to perform in both Tanium SSO and Azure Active Directory (Azure AD) to configure automatic user provisioning. When configured, Azure AD automatically provisions and de-provisions users and groups to [Tanium SSO](https://www.tanium.com/) using the Azure AD Provisioning service. These capabilities are supported only for Tanium Cloud customers. For important details on what this service does, how it works, and frequently asked questions, see [Automate user provisioning and deprovisioning to SaaS applications with Azure Active Directory](../app-provisioning/user-provisioning.md).
20
20
21
21
22
22
## Supported capabilities
@@ -36,16 +36,19 @@ The scenario outlined in this tutorial assumes that you already have the followi
36
36
* A user account in Tanium SSO with Admin permissions.
37
37
38
38
## Step 1. Plan your provisioning deployment
39
+
39
40
1. Learn about [how the provisioning service works](../app-provisioning/user-provisioning.md).
40
41
1. Determine who will be in [scope for provisioning](../app-provisioning/define-conditional-rules-for-provisioning-user-accounts.md).
41
42
1. Determine what data to [map between Azure AD and Tanium SSO](../app-provisioning/customize-application-attributes.md).
42
43
43
-
## Step 2. Configure Tanium SSO to support provisioning with Azure AD
44
-
Contact Tanium SSO support to configure Tanium SSO to support provisioning with Azure AD.
44
+
## Step 2. Enable SCIM Provisioning in the Tanium Cloud Management Portal (CMP)
45
+
46
+
* Follow the steps in the [Tanium Cloud Deployment Guide: Configure SCIM Provisioning](https://docs.tanium.com/cloud/cloud/configuring_identity_providers.html#configure_scim) to enable automatic user provisioniong in Tanium Cloud.
47
+
* Retain the **Token** and **SCIM API URL** values for later use in configuring Tanium SSO. Copy the entire token string, formatted like `token-\<58 alphanumeric characters\>`.
45
48
46
49
## Step 3. Add Tanium SSO from the Azure AD application gallery
47
50
48
-
Add Tanium SSO from the Azure AD application gallery to start managing provisioning to Tanium SSO. If you have previously setup Tanium SSO for SSO you can use the same application. However it's recommended that you create a separate app when testing out the integration initially. Learn more about adding an application from the gallery [here](../manage-apps/add-application-portal.md).
51
+
Add Tanium SSO from the Azure AD application gallery to start managing provisioning to Tanium SSO. If you have previously setup Tanium SSO for SSO you can use the same application. However, it's recommended that you create a separate app when testing out the integration initially. Learn more about adding an application from the gallery [here](../manage-apps/add-application-portal.md).
49
52
50
53
## Step 4. Define who will be in scope for provisioning
51
54
@@ -55,10 +58,9 @@ The Azure AD provisioning service allows you to scope who will be provisioned ba
55
58
56
59
* If you need more roles, you can [update the application manifest](../develop/howto-add-app-roles-in-azure-ad-apps.md) to add new roles.
57
60
58
-
59
61
## Step 5. Configure automatic user provisioning to Tanium SSO
60
62
61
-
This section guides you through the steps to configure the Azure AD provisioning service to create, update, and disable users and/or groups in TestApp based on user and/or group assignments in Azure AD.
63
+
This section guides you through the steps to configure the Azure AD provisioning service to create, update, and disable users and/or groups in Tanium based on user and/or group assignments in Azure AD.
62
64
63
65
### To configure automatic user provisioning for Tanium SSO in Azure AD:
64
66
@@ -78,9 +80,9 @@ This section guides you through the steps to configure the Azure AD provisioning
78
80
79
81

80
82
81
-
1. Under the **Admin Credentials** section, input your Tanium SSO Tenant URL and Secret Token. Click **Test Connection** to ensure Azure AD can connect to Tanium SSO. If the connection fails, ensure your Tanium SSO account has Admin permissions and try again.
83
+
1. Under the **Admin Credentials** section, input your Tanium SSO **Tenant URL** and **Secret Token** that you previously retrieved from the Tanium CMP. Click **Test Connection** to ensure Azure AD can connect to Tanium SSO. If the connection fails, ensure that you entered the complete token value, including the `token-` prefix.
82
84
83
-

85
+

84
86
85
87
1. In the **Notification Email** field, enter the email address of a person or group who should receive the provisioning error notifications and select the **Send an email notification when a failure occurs** check box.
0 commit comments