Skip to content

Commit 38e8dc8

Browse files
committed
Merge branch 'master' of https://github.com/MicrosoftDocs/azure-docs-pr into use-geo-ai-dsvm
2 parents f05d7c6 + b19a081 commit 38e8dc8

File tree

47 files changed

+881
-2588
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

47 files changed

+881
-2588
lines changed

.openpublishing.redirection.json

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -38903,6 +38903,16 @@
3890338903
"redirect_url": "https://github.com/Microsoft/Cognitive-Vision-Python",
3890438904
"redirect_document_id": false
3890538905
},
38906+
{
38907+
"source_path": "articles/cognitive-services/Computer-vision/Tutorials/java-tutorial.md",
38908+
"redirect_url": "https://github.com/Azure-Samples/cognitive-services-java-computer-vision-tutorial",
38909+
"redirect_document_id": false
38910+
},
38911+
{
38912+
"source_path": "articles/cognitive-services/Computer-vision/Tutorials/javascript-tutorial.md",
38913+
"redirect_url": "https://github.com/Azure-Samples/cognitive-services-javascript-computer-vision-tutorial",
38914+
"redirect_document_id": false
38915+
},
3890638916
{
3890738917
"source_path": "articles/media-services/previous/media-services-hyperlapse-content.md",
3890838918
"redirect_url": "/azure/media-services/previous/media-services-analytics-overview",

articles/active-directory/saas-apps/adpfederatedsso-tutorial.md

Lines changed: 39 additions & 63 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
---
2-
title: 'Tutorial: Azure Active Directory integration with ADP | Microsoft Docs'
2+
title: 'Tutorial: Azure Active Directory single sign-on (SSO) integration with ADP | Microsoft Docs'
33
description: Learn how to configure single sign-on between Azure Active Directory and ADP.
44
services: active-directory
55
documentationCenter: na
@@ -14,13 +14,13 @@ ms.workload: identity
1414
ms.tgt_pltfrm: na
1515
ms.devlang: na
1616
ms.topic: tutorial
17-
ms.date: 07/25/2019
17+
ms.date: 08/26/2019
1818
ms.author: jeedes
1919

2020
ms.collection: M365-identity-device-management
2121
---
2222

23-
# Tutorial: Integrate ADP with Azure Active Directory
23+
# Tutorial: Azure Active Directory single sign-on (SSO) integration with ADP
2424

2525
In this tutorial, you'll learn how to integrate ADP with Azure Active Directory (Azure AD). When you integrate ADP with Azure AD, you can:
2626

@@ -43,6 +43,9 @@ In this tutorial, you configure and test Azure AD SSO in a test environment.
4343

4444
* ADP supports **IDP** initiated SSO
4545

46+
> [!NOTE]
47+
> Identifier of this application is a fixed string value so only one instance can be configured in one tenant.
48+
4649
## Adding ADP from the gallery
4750

4851
To configure the integration of ADP into Azure AD, you need to add ADP from the gallery to your list of managed SaaS apps.
@@ -54,21 +57,20 @@ To configure the integration of ADP into Azure AD, you need to add ADP from the
5457
1. In the **Add from the gallery** section, type **ADP** in the search box.
5558
1. Select **ADP** from results panel and then add the app. Wait a few seconds while the app is added to your tenant.
5659

57-
58-
## Configure and test Azure AD single sign-on
60+
## Configure and test Azure AD single sign-on for ADP
5961

6062
Configure and test Azure AD SSO with ADP using a test user called **B.Simon**. For SSO to work, you need to establish a link relationship between an Azure AD user and the related user in ADP.
6163

6264
To configure and test Azure AD SSO with ADP, complete the following building blocks:
6365

6466
1. **[Configure Azure AD SSO](#configure-azure-ad-sso)** - to enable your users to use this feature.
67+
1. **[Create an Azure AD test user](#create-an-azure-ad-test-user)** - to test Azure AD single sign-on with B.Simon.
68+
1. **[Assign the Azure AD test user](#assign-the-azure-ad-test-user)** - to enable B.Simon to use Azure AD single sign-on.
6569
2. **[Configure ADP SSO](#configure-adp-sso)** - to configure the Single Sign-On settings on application side.
66-
3. **[Create an Azure AD test user](#create-an-azure-ad-test-user)** - to test Azure AD single sign-on with B.Simon.
67-
4. **[Assign the Azure AD test user](#assign-the-azure-ad-test-user)** - to enable B.Simon to use Azure AD single sign-on.
68-
5. **[Create ADP test user](#create-adp-test-user)** - to have a counterpart of B.Simon in ADP that is linked to the Azure AD representation of user.
69-
6. **[Test SSO](#test-sso)** - to verify whether the configuration works.
70+
1. **[Create ADP test user](#create-adp-test-user)** - to have a counterpart of B.Simon in ADP that is linked to the Azure AD representation of user.
71+
3. **[Test SSO](#test-sso)** - to verify whether the configuration works.
7072

71-
### Configure Azure AD SSO
73+
## Configure Azure AD SSO
7274

7375
Follow these steps to enable Azure AD SSO in the Azure portal.
7476

@@ -95,42 +97,45 @@ Follow these steps to enable Azure AD SSO in the Azure portal.
9597
In the **Identifier (Entity ID)** text box, type a URL:
9698
`https://fed.adp.com`
9799

98-
5. ADP application expects the SAML assertions in a specific format, which requires you to add custom attribute mappings to your SAML token attributes configuration. The following screenshot shows the list of default attributes. Click **Edit** icon to open User Attributes dialog. The claim name will always be **PersonImmutableID** and the value of which we shown that to map with **employeeid**.
99-
100-
The user mapping from Azure AD to ADP will be done on the **employeeid** but you can map this to a different value based on your application settings. So please work with [ADP support team](https://www.adp.com/contact-us/overview.aspx) first to use the correct identifier of a user and map that value with the **PersonImmutableID** claim.
101-
102-
![image](common/edit-attribute.png)
100+
4. On the **Set up Single Sign-On with SAML** page, in the **SAML Signing Certificate** section, find **Federation Metadata XML** and select **Download** to download the certificate and save it on your computer.
103101

104-
6. In addition to above, ADP application expects few more attributes to be passed back in SAML response. In the User Claims section on the User Attributes dialog, perform the following steps to add SAML token attribute as shown in the below table:
102+
![The Certificate download link](common/metadataxml.png)
105103

106-
| Name | Source Attribute|
107-
| ---------------| --------- |
108-
| PersonImmutableID | user.employeeid |
104+
6. On the **Set up ADP** section, copy the appropriate URL(s) based on your requirement.
109105

110-
a. Click **Add new claim** to open the **Manage user claims** dialog.
106+
![Copy configuration URLs](common/copy-configuration-urls.png)
111107

112-
b. In the **Name** textbox, type the attribute name shown for that row.
108+
### Create an Azure AD test user
113109

114-
c. Leave the **Namespace** blank.
110+
In this section, you'll create a test user in the Azure portal called B.Simon.
115111

116-
d. Select Source as **Attribute**.
112+
1. From the left pane in the Azure portal, select **Azure Active Directory**, select **Users**, and then select **All users**.
113+
1. Select **New user** at the top of the screen.
114+
1. In the **User** properties, follow these steps:
115+
1. In the **Name** field, enter `B.Simon`.
116+
1. In the **User name** field, enter the [email protected]. For example, `[email protected]`.
117+
1. Select the **Show password** check box, and then write down the value that's displayed in the **Password** box.
118+
1. Click **Create**.
117119

118-
e. From the **Source attribute** list, type the attribute value shown for that row.
120+
### Assign the Azure AD test user
119121

120-
f. Click **Save**.
122+
In this section, you'll enable B.Simon to use Azure single sign-on by granting access to ADP.
121123

122-
> [!NOTE]
123-
> Before you can configure the SAML assertion, you need to contact your [ADP support team](https://www.adp.com/contact-us/overview.aspx) and request the value of the unique user identifier attribute for your tenant. You need this value to configure the custom claim for your application.
124+
1. In the Azure portal, select **Enterprise Applications**, and then select **All applications**.
125+
1. In the applications list, select **ADP**.
126+
1. In the app's overview page, find the **Manage** section and select **Users and groups**.
124127

125-
4. On the **Set up Single Sign-On with SAML** page, in the **SAML Signing Certificate** section, find **Federation Metadata XML** and select **Download** to download the certificate and save it on your computer.
128+
![The "Users and groups" link](common/users-groups-blade.png)
126129

127-
![The Certificate download link](common/metadataxml.png)
130+
1. Select **Add user**, then select **Users and groups** in the **Add Assignment** dialog.
128131

129-
6. On the **Set up ADP** section, copy the appropriate URL(s) based on your requirement.
132+
![The Add User link](common/add-assign-user.png)
130133

131-
![Copy configuration URLs](common/copy-configuration-urls.png)
134+
1. In the **Users and groups** dialog, select **B.Simon** from the Users list, then click the **Select** button at the bottom of the screen.
135+
1. If you're expecting any role value in the SAML assertion, in the **Select Role** dialog, select the appropriate role for the user from the list and then click the **Select** button at the bottom of the screen.
136+
1. In the **Add Assignment** dialog, click the **Assign** button.
132137

133-
### Configure ADP SSO
138+
## Configure ADP SSO
134139

135140
To configure single sign-on on **ADP** side, you need to upload the downloaded **Metadata XML** on the [ADP website](https://adpfedsso.adp.com/public/login/index.fcc).
136141

@@ -203,41 +208,11 @@ Upon receipt of confirmation from your ADP representative, configure your ADP se
203208

204209
11. On confirmation of a successful test, assign the federated ADP service to individual users or user groups, which is explained later in the tutorial and roll it out to your employees.
205210

206-
### Create an Azure AD test user
207-
208-
In this section, you'll create a test user in the Azure portal called B.Simon.
209-
210-
1. From the left pane in the Azure portal, select **Azure Active Directory**, select **Users**, and then select **All users**.
211-
1. Select **New user** at the top of the screen.
212-
1. In the **User** properties, follow these steps:
213-
1. In the **Name** field, enter `B.Simon`.
214-
1. In the **User name** field, enter the [email protected]. For example, `[email protected]`.
215-
1. Select the **Show password** check box, and then write down the value that's displayed in the **Password** box.
216-
1. Click **Create**.
217-
218-
### Assign the Azure AD test user
219-
220-
In this section, you'll enable B.Simon to use Azure single sign-on by granting access to ADP.
221-
222-
1. In the Azure portal, select **Enterprise Applications**, and then select **All applications**.
223-
1. In the applications list, select **ADP**.
224-
1. In the app's overview page, find the **Manage** section and select **Users and groups**.
225-
226-
![The "Users and groups" link](common/users-groups-blade.png)
227-
228-
1. Select **Add user**, then select **Users and groups** in the **Add Assignment** dialog.
229-
230-
![The Add User link](common/add-assign-user.png)
231-
232-
1. In the **Users and groups** dialog, select **B.Simon** from the Users list, then click the **Select** button at the bottom of the screen.
233-
1. If you're expecting any role value in the SAML assertion, in the **Select Role** dialog, select the appropriate role for the user from the list and then click the **Select** button at the bottom of the screen.
234-
1. In the **Add Assignment** dialog, click the **Assign** button.
235-
236211
### Create ADP test user
237212

238213
The objective of this section is to create a user called B.Simon in ADP. Work with [ADP support team](https://www.adp.com/contact-us/overview.aspx) to add the users in the ADP account.
239214

240-
### Test SSO
215+
## Test SSO
241216

242217
In this section, you test your Azure AD single sign-on configuration using the Access Panel.
243218

@@ -251,3 +226,4 @@ When you click the ADP tile in the Access Panel, you should be automatically sig
251226

252227
- [What is conditional access in Azure Active Directory?](https://docs.microsoft.com/azure/active-directory/conditional-access/overview)
253228

229+
- [Try ADP with Azure AD](https://aad.portal.azure.com)

0 commit comments

Comments
 (0)