You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/active-directory/saas-apps/keylight-tutorial.md
+38-38Lines changed: 38 additions & 38 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,6 +1,6 @@
1
1
---
2
-
title: 'Tutorial: Azure Active Directory integration with LockPath Keylight | Microsoft Docs'
3
-
description: Learn how to configure single sign-on between Azure Active Directory and LockPath Keylight.
2
+
title: 'Tutorial: Azure Active Directory integration with NAVEX IRM (Lockpath/Keylight) | Microsoft Docs'
3
+
description: Learn how to configure single sign-on between Azure Active Directory and NAVEX IRM (Lockpath/Keylight).
4
4
services: active-directory
5
5
author: jeevansd
6
6
manager: CelesteDG
@@ -9,53 +9,53 @@ ms.service: active-directory
9
9
ms.subservice: saas-app-tutorial
10
10
ms.workload: identity
11
11
ms.topic: tutorial
12
-
ms.date: 06/11/2021
12
+
ms.date: 09/09/2022
13
13
ms.author: jeedes
14
14
---
15
-
# Tutorial: Azure Active Directory integration with LockPath Keylight
15
+
# Tutorial: Azure Active Directory integration with NAVEX IRM (Lockpath/Keylight)
16
16
17
-
In this tutorial, you'll learn how to integrate LockPath Keylight with Azure Active Directory (Azure AD). When you integrate LockPath Keylight with Azure AD, you can:
17
+
In this tutorial, you'll learn how to integrate NAVEX IRM (Lockpath/Keylight) with Azure Active Directory (Azure AD). When you integrate NAVEX IRM (Lockpath/Keylight) with Azure AD, you can:
18
18
19
-
* Control in Azure AD who has access to LockPath Keylight.
20
-
* Enable your users to be automatically signed-in to LockPath Keylight with their Azure AD accounts.
19
+
* Control in Azure AD who has access to NAVEX IRM (Lockpath/Keylight).
20
+
* Enable your users to be automatically signed-in to NAVEX IRM (Lockpath/Keylight) with their Azure AD accounts.
21
21
* Manage your accounts in one central location - the Azure portal.
22
22
23
23
## Prerequisites
24
24
25
-
To configure Azure AD integration with LockPath Keylight, you need the following items:
25
+
To configure Azure AD integration with NAVEX IRM (Lockpath/Keylight), you need the following items:
26
26
27
27
* An Azure AD subscription. If you don't have an Azure AD environment, you can get a [free account](https://azure.microsoft.com/free/).
28
-
*LockPath Keylight single sign-on enabled subscription.
28
+
*NAVEX IRM (Lockpath/Keylight) single sign-on enabled subscription.
29
29
30
30
## Scenario description
31
31
32
32
In this tutorial, you configure and test Azure AD single sign-on in a test environment.
33
33
34
-
*LockPath Keylight supports **SP** initiated SSO.
35
-
*LockPath Keylight supports **Just In Time** user provisioning.
*NAVEX IRM (Lockpath/Keylight) supports **Just In Time** user provisioning.
36
36
37
-
## Add LockPath Keylight from the gallery
37
+
## Add NAVEX IRM (Lockpath/Keylight) from the gallery
38
38
39
-
To configure the integration of LockPath Keylight into Azure AD, you need to add LockPath Keylight from the gallery to your list of managed SaaS apps.
39
+
To configure the integration of NAVEX IRM (Lockpath/Keylight) into Azure AD, you need to add NAVEX IRM (Lockpath/Keylight) from the gallery to your list of managed SaaS apps.
40
40
41
41
1. Sign in to the Azure portal using either a work or school account, or a personal Microsoft account.
42
42
1. On the left navigation pane, select the **Azure Active Directory** service.
43
43
1. Navigate to **Enterprise Applications** and then select **All Applications**.
44
44
1. To add new application, select **New application**.
45
-
1. In the **Add from the gallery** section, type **LockPath Keylight** in the search box.
46
-
1. Select **LockPath Keylight** from results panel and then add the app. Wait a few seconds while the app is added to your tenant.
45
+
1. In the **Add from the gallery** section, type **NAVEX IRM (Lockpath/Keylight)** in the search box.
46
+
1. Select **NAVEX IRM (Lockpath/Keylight)** from results panel and then add the app. Wait a few seconds while the app is added to your tenant.
47
47
48
-
## Configure and test Azure AD SSO for LockPath Keylight
48
+
## Configure and test Azure AD SSO for NAVEX IRM (Lockpath/Keylight)
49
49
50
-
Configure and test Azure AD SSO with LockPath Keylight using a test user called **B.Simon**. For SSO to work, you need to establish a link relationship between an Azure AD user and the related user in LockPath Keylight.
50
+
Configure and test Azure AD SSO with NAVEX IRM (Lockpath/Keylight) using a test user called **B.Simon**. For SSO to work, you need to establish a link relationship between an Azure AD user and the related user in NAVEX IRM (Lockpath/Keylight).
51
51
52
-
To configure and test Azure AD SSO with LockPath Keylight, perform the following steps:
52
+
To configure and test Azure AD SSO with NAVEX IRM (Lockpath/Keylight), perform the following steps:
53
53
54
54
1.**[Configure Azure AD SSO](#configure-azure-ad-sso)** - to enable your users to use this feature.
55
55
1.**[Create an Azure AD test user](#create-an-azure-ad-test-user)** - to test Azure AD single sign-on with B.Simon.
56
56
1.**[Assign the Azure AD test user](#assign-the-azure-ad-test-user)** - to enable B.Simon to use Azure AD single sign-on.
57
-
1.**[Configure LockPath Keylight SSO](#configure-lockpath-keylight-sso)** - to configure the single sign-on settings on application side.
58
-
1.**[Create LockPath Keylight test user](#create-lockpath-keylight-test-user)** - to have a counterpart of B.Simon in LockPath Keylight that is linked to the Azure AD representation of user.
57
+
1.**[Configure NAVEX IRM (Lockpath/Keylight) SSO](#configure-navex-irm-lockpathkeylight-sso)** - to configure the single sign-on settings on application side.
58
+
1.**[Create NAVEX IRM (Lockpath/Keylight) test user](#create-navex-irm-lockpathkeylight-test-user)** - to have a counterpart of B.Simon in NAVEX IRM (Lockpath/Keylight) that is linked to the Azure AD representation of user.
59
59
1.**[Test SSO](#test-sso)** - to verify whether the configuration works.
60
60
61
61
## Configure Azure AD SSO
@@ -64,7 +64,7 @@ In this section, you enable Azure AD single sign-on in the Azure portal.
64
64
65
65
Follow these steps to enable Azure AD SSO in the Azure portal.
66
66
67
-
1. In the Azure portal, on the **LockPath Keylight** application integration page, find the **Manage** section and select **single sign-on**.
67
+
1. In the Azure portal, on the **NAVEX IRM (Lockpath/Keylight)** application integration page, find the **Manage** section and select **single sign-on**.
68
68
1. On the **Select a single sign-on method** page, select **SAML**.
69
69
1. On the **Set up single sign-on with SAML** page, click the pencil icon for **Basic SAML Configuration** to edit the settings.
70
70
@@ -81,13 +81,13 @@ Follow these steps to enable Azure AD SSO in the Azure portal.
81
81
`https://<COMPANY_NAME>.keylightgrc.com/`
82
82
83
83
> [!NOTE]
84
-
> These values are not real. Update these values with the actual Identifier, Reply URL and Sign on URL. Contact [LockPath Keylight Client support team](https://www.lockpath.com/contact/) to get these values. You can also refer to the patterns shown in the **Basic SAML Configuration** section in the Azure portal.
84
+
> These values are not real. Update these values with the actual Identifier, Reply URL and Sign on URL. Contact [NAVEX IRM (Lockpath/Keylight) Client support team](https://www.lockpath.com/contact/) to get these values. You can also refer to the patterns shown in the **Basic SAML Configuration** section in the Azure portal.
85
85
86
86
5. On the **Set up Single Sign-On with SAML** page, in the **SAML Signing Certificate** section, click **Download** to download the **Certificate (Raw)** from the given options as per your requirement and save it on your computer.
@@ -105,29 +105,29 @@ In this section, you'll create a test user in the Azure portal called B.Simon.
105
105
106
106
### Assign the Azure AD test user
107
107
108
-
In this section, you'll enable B.Simon to use Azure single sign-on by granting access to LockPath Keylight.
108
+
In this section, you'll enable B.Simon to use Azure single sign-on by granting access to NAVEX IRM (Lockpath/Keylight).
109
109
110
110
1. In the Azure portal, select **Enterprise Applications**, and then select **All applications**.
111
-
1. In the applications list, select **LockPath Keylight**.
111
+
1. In the applications list, select **NAVEX IRM (Lockpath/Keylight)**.
112
112
1. In the app's overview page, find the **Manage** section and select **Users and groups**.
113
113
1. Select **Add user**, then select **Users and groups** in the **Add Assignment** dialog.
114
114
1. In the **Users and groups** dialog, select **B.Simon** from the Users list, then click the **Select** button at the bottom of the screen.
115
115
1. If you are expecting a role to be assigned to the users, you can select it from the **Select a role** dropdown. If no role has been set up for this app, you see "Default Access" role selected.
116
116
1. In the **Add Assignment** dialog, click the **Assign** button.
117
117
118
-
## Configure LockPath Keylight SSO
118
+
## Configure NAVEX IRM (Lockpath/Keylight) SSO
119
119
120
-
1. To enable SSO in LockPath Keylight, perform the following steps:
120
+
1. To enable SSO in NAVEX IRM (Lockpath/Keylight), perform the following steps:
121
121
122
-
a. Sign-on to your LockPath Keylight account as administrator.
122
+
a. Sign-on to your NAVEX IRM (Lockpath/Keylight) account as administrator.
123
123
124
-
b. In the menu on the top, click **Person**, and select **Keylight Setup**.
124
+
b. In the menu on the top, click **User Icon**, and select **Setup**.
125
125
126
126

127
127
128
128
c. In the treeview on the left, click **SAML**.
129
129
130
-

130
+

131
131
132
132
d. On the **SAML Settings** dialog, click **Edit**.
133
133
@@ -143,11 +143,11 @@ In this section, you'll enable B.Simon to use Azure single sign-on by granting a
143
143
144
144
c. In the **Identity Provider Logout URL** textbox, paste the **Logout URL** value which you have copied from the Azure portal.
145
145
146
-
d. Click **Choose File** to select your downloaded LockPath Keylight certificate, and then click **Open** to upload the certificate.
146
+
d. Click **Choose File** to select your downloaded NAVEX IRM (Lockpath/Keylight) certificate, and then click **Open** to upload the certificate.
147
147
148
148
e. Set **SAML User Id location** to **NameIdentifier element of the subject statement**.
149
149
150
-
f. Provide the **Keylight Service Provider** using the following pattern: `https://<CompanyName>.keylightgrc.com`.
150
+
f. Provide the **Service Provider Entity Id** using the following pattern: `https://<CompanyName>.keylightgrc.com`.
151
151
152
152
g. Set **Auto-provision users** to **Active**.
153
153
@@ -165,20 +165,20 @@ In this section, you'll enable B.Simon to use Azure single sign-on by granting a
165
165
166
166
n. Click **Save**.
167
167
168
-
### Create LockPath Keylight test user
168
+
### Create NAVEX IRM (Lockpath/Keylight) test user
169
169
170
-
In this section, a user called Britta Simon is created in LockPath Keylight. LockPath Keylight supports just-in-time user provisioning, which is enabled by default. There is no action item for you in this section. If a user doesn't already exist in LockPath Keylight, a new one is created after authentication. If you need to create a user manually, you need to contact the [LockPath Keylight Client support team](https://www.lockpath.com/contact/).
170
+
In this section, a user called Britta Simon is created in NAVEX IRM (Lockpath/Keylight). NAVEX IRM (Lockpath/Keylight) supports just-in-time user provisioning, which is enabled by default. There is no action item for you in this section. If a user doesn't already exist in NAVEX IRM (Lockpath/Keylight), a new one is created after authentication. If you need to create a user manually, you need to contact the [NAVEX IRM (Lockpath/Keylight) Customer support team](https://www.lockpath.com/contact/).
171
171
172
172
## Test SSO
173
173
174
174
In this section, you test your Azure AD single sign-on configuration with following options.
175
175
176
-
* Click on **Test this application** in Azure portal. This will redirect to LockPath Keylight Sign-on URL where you can initiate the login flow.
176
+
* Click on **Test this application** in Azure portal. This will redirect to NAVEX IRM (Lockpath/Keylight) Sign-on URL where you can initiate the login flow.
177
177
178
-
* Go to LockPath Keylight Sign-on URL directly and initiate the login flow from there.
178
+
* Go to NAVEX IRM (Lockpath/Keylight) Sign-on URL directly and initiate the login flow from there.
179
179
180
-
* You can use Microsoft My Apps. When you click the LockPath Keylight tile in the My Apps, this will redirect to LockPath Keylight Sign-on URL. For more information about the My Apps, see [Introduction to the My Apps](https://support.microsoft.com/account-billing/sign-in-and-start-apps-from-the-my-apps-portal-2f3b1bae-0e5a-4a86-a33e-876fbd2a4510).
180
+
* You can use Microsoft My Apps. When you click the NAVEX IRM (Lockpath/Keylight) tile in the My Apps, this will redirect to NAVEX IRM (Lockpath/Keylight) Sign-on URL. For more information about the My Apps, see [Introduction to the My Apps](https://support.microsoft.com/account-billing/sign-in-and-start-apps-from-the-my-apps-portal-2f3b1bae-0e5a-4a86-a33e-876fbd2a4510).
181
181
182
182
## Next steps
183
183
184
-
Once you configure LockPath Keylight you can enforce session control, which protects exfiltration and infiltration of your organization’s sensitive data in real time. Session control extends from Conditional Access. [Learn how to enforce session control with Microsoft Defender for Cloud Apps](/cloud-app-security/proxy-deployment-aad).
184
+
Once you configure NAVEX IRM (Lockpath/Keylight) you can enforce session control, which protects exfiltration and infiltration of your organization’s sensitive data in real time. Session control extends from Conditional Access. [Learn how to enforce session control with Microsoft Defender for Cloud Apps](/cloud-app-security/proxy-deployment-aad).
0 commit comments