Skip to content

Commit 2e03370

Browse files
update
1 parent 49511df commit 2e03370

File tree

2 files changed

+10
-153
lines changed

2 files changed

+10
-153
lines changed

articles/active-directory/saas-apps/tanium-sso-provisioning-tutorial-updated.md

Lines changed: 0 additions & 145 deletions
This file was deleted.

articles/active-directory/saas-apps/tanium-sso-provisioning-tutorial.md

Lines changed: 10 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -16,7 +16,7 @@ ms.author: thwimmer
1616

1717
# Tutorial: Configure Tanium SSO for automatic user provisioning
1818

19-
This tutorial describes the steps you need to perform in both Tanium SSO and Azure Active Directory (Azure AD) to configure automatic user provisioning. When configured, Azure AD automatically provisions and de-provisions users and groups to [Tanium SSO](https://www.tanium.com/) using the Azure AD Provisioning service. For important details on what this service does, how it works, and frequently asked questions, see [Automate user provisioning and deprovisioning to SaaS applications with Azure Active Directory](../app-provisioning/user-provisioning.md).
19+
This tutorial describes the steps you need to perform in both Tanium SSO and Azure Active Directory (Azure AD) to configure automatic user provisioning. When configured, Azure AD automatically provisions and de-provisions users and groups to [Tanium SSO](https://www.tanium.com/) using the Azure AD Provisioning service. These capabilities are supported only for Tanium Cloud customers. For important details on what this service does, how it works, and frequently asked questions, see [Automate user provisioning and deprovisioning to SaaS applications with Azure Active Directory](../app-provisioning/user-provisioning.md).
2020

2121

2222
## Supported capabilities
@@ -36,16 +36,19 @@ The scenario outlined in this tutorial assumes that you already have the followi
3636
* A user account in Tanium SSO with Admin permissions.
3737

3838
## Step 1. Plan your provisioning deployment
39+
3940
1. Learn about [how the provisioning service works](../app-provisioning/user-provisioning.md).
4041
1. Determine who will be in [scope for provisioning](../app-provisioning/define-conditional-rules-for-provisioning-user-accounts.md).
4142
1. Determine what data to [map between Azure AD and Tanium SSO](../app-provisioning/customize-application-attributes.md).
4243

43-
## Step 2. Configure Tanium SSO to support provisioning with Azure AD
44-
Contact Tanium SSO support to configure Tanium SSO to support provisioning with Azure AD.
44+
## Step 2. Enable SCIM Provisioning in the Tanium Cloud Management Portal (CMP)
45+
46+
* Follow the steps in the [Tanium Cloud Deployment Guide: Configure SCIM Provisioning](https://docs.tanium.com/cloud/cloud/configuring_identity_providers.html#configure_scim) to enable automatic user provisioniong in Tanium Cloud.
47+
* Retain the **Token** and **SCIM API URL** values for later use in configuring Tanium SSO. Copy the entire token string, formatted like `token-\<58 alphanumeric characters\>`.
4548

4649
## Step 3. Add Tanium SSO from the Azure AD application gallery
4750

48-
Add Tanium SSO from the Azure AD application gallery to start managing provisioning to Tanium SSO. If you have previously setup Tanium SSO for SSO you can use the same application. However it's recommended that you create a separate app when testing out the integration initially. Learn more about adding an application from the gallery [here](../manage-apps/add-application-portal.md).
51+
Add Tanium SSO from the Azure AD application gallery to start managing provisioning to Tanium SSO. If you have previously setup Tanium SSO for SSO you can use the same application. However, it's recommended that you create a separate app when testing out the integration initially. Learn more about adding an application from the gallery [here](../manage-apps/add-application-portal.md).
4952

5053
## Step 4. Define who will be in scope for provisioning
5154

@@ -55,10 +58,9 @@ The Azure AD provisioning service allows you to scope who will be provisioned ba
5558

5659
* If you need more roles, you can [update the application manifest](../develop/howto-add-app-roles-in-azure-ad-apps.md) to add new roles.
5760

58-
5961
## Step 5. Configure automatic user provisioning to Tanium SSO
6062

61-
This section guides you through the steps to configure the Azure AD provisioning service to create, update, and disable users and/or groups in TestApp based on user and/or group assignments in Azure AD.
63+
This section guides you through the steps to configure the Azure AD provisioning service to create, update, and disable users and/or groups in Tanium based on user and/or group assignments in Azure AD.
6264

6365
### To configure automatic user provisioning for Tanium SSO in Azure AD:
6466

@@ -78,9 +80,9 @@ This section guides you through the steps to configure the Azure AD provisioning
7880

7981
![Screenshot of Provisioning tab automatic.](common/provisioning-automatic.png)
8082

81-
1. Under the **Admin Credentials** section, input your Tanium SSO Tenant URL and Secret Token. Click **Test Connection** to ensure Azure AD can connect to Tanium SSO. If the connection fails, ensure your Tanium SSO account has Admin permissions and try again.
83+
1. Under the **Admin Credentials** section, input your Tanium SSO **Tenant URL** and **Secret Token** that you previously retrieved from the Tanium CMP. Click **Test Connection** to ensure Azure AD can connect to Tanium SSO. If the connection fails, ensure that you entered the complete token value, including the `token-` prefix.
8284

83-
![Screenshot of Token.](common/provisioning-testconnection-tenanturltoken.png)
85+
![Screenshot of Token.](common/provisioning-testconnection-tenanturltoken.png)
8486

8587
1. In the **Notification Email** field, enter the email address of a person or group who should receive the provisioning error notifications and select the **Send an email notification when a failure occurs** check box.
8688

0 commit comments

Comments
 (0)