You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/active-directory/saas-apps/purecloud-by-genesys-tutorial.md
+63-63Lines changed: 63 additions & 63 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -16,73 +16,73 @@ ms.devlang: na
16
16
ms.topic: tutorial
17
17
ms.date: 10/03/2019
18
18
ms.author: jeedes
19
-
20
19
ms.collection: M365-identity-device-management
20
+
21
21
---
22
22
23
23
# Tutorial: Azure Active Directory single sign-on (SSO) integration with PureCloud by Genesys
24
24
25
-
In this tutorial, you'll learn how to integrate PureCloud by Genesys with Azure Active Directory (Azure AD). When you integrate PureCloud by Genesys with Azure AD, you can:
25
+
In this tutorial, you'll learn how to integrate PureCloud by Genesys with Azure Active Directory (Azure AD). After you do that, you can:
26
26
27
-
*Control in Azure AD who has access to PureCloud by Genesys.
27
+
*Use Azure AD to control which users can access PureCloud by Genesys.
28
28
* Enable your users to be automatically signed-in to PureCloud by Genesys with their Azure AD accounts.
29
-
* Manage your accounts in one central location - the Azure portal.
29
+
* Manage your accounts in one central location: the Azure portal.
30
30
31
31
To learn more about SaaS app integration with Azure AD, see [What is application access and single sign-on with Azure Active Directory](https://docs.microsoft.com/azure/active-directory/active-directory-appssoaccess-whatis).
32
32
33
33
## Prerequisites
34
34
35
35
To get started, you need the following items:
36
36
37
-
* An Azure AD subscription. If you don't have a subscription, you can get a [free account](https://azure.microsoft.com/free/).
38
-
* PureCloud by Genesys single sign-on (SSO)enabled subscription.
37
+
* An Azure AD subscription. If you don't have one, you can get a [free account](https://azure.microsoft.com/free/).
38
+
*A PureCloud by Genesys single sign-on (SSO)–enabled subscription.
39
39
40
40
## Scenario description
41
41
42
42
In this tutorial, you configure and test Azure AD SSO in a test environment.
43
43
44
-
* PureCloud by Genesys supports **SP and IDP**initiated SSO
44
+
* PureCloud by Genesys supports **SP and IDP**–initiated SSO.
45
45
46
46
> [!NOTE]
47
-
> Identifier of this application is a fixedstring value so only one instance can be configured in one tenant.
47
+
> Because the ID for this application is a fixed-string value, only one instance can be configured in one tenant.
48
48
49
49
## Adding PureCloud by Genesys from the gallery
50
50
51
-
To configure the integration of PureCloud by Genesys into Azure AD, you need to add PureCloud by Genesys from the gallery to your list of managed SaaS apps.
51
+
To configure integration of PureCloud by Genesys into Azure AD, you must add PureCloud by Genesys from the gallery to your list of managed SaaS apps. To do this, follow these steps:
52
52
53
-
1. Sign in to the [Azure portal](https://portal.azure.com) using either a work or school account, or a personal Microsoft account.
53
+
1. Sign in to the [Azure portal](https://portal.azure.com)by using a work or school account or by using a personal Microsoft account.
54
54
1. On the left navigation pane, select the **Azure Active Directory** service.
55
-
1.Navigate to **Enterprise Applications** and then select **All Applications**.
55
+
1.Go to **Enterprise Applications** and then select **All Applications**.
56
56
1. To add new application, select **New application**.
57
57
1. In the **Add from the gallery** section, type **PureCloud by Genesys** in the search box.
58
-
1. Select **PureCloud by Genesys** from results panel and then add the app. Wait a few seconds while the app is added to your tenant.
58
+
1. Select **PureCloud by Genesys** from the results panel and then add the app. Wait a few seconds while the app is added to your tenant.
59
59
60
60
## Configure and test Azure AD single sign-on for PureCloud by Genesys
61
61
62
-
Configure and test Azure AD SSO with PureCloud by Genesys using a test user called**B.Simon**. For SSO to work, you need to establish a link relationship between an Azure AD user and the related user in PureCloud by Genesys.
62
+
Configure and test Azure AD SSO with PureCloud by Genesys using a test user named**B.Simon**. For SSO to work, you must establish a link relationship between an Azure AD user and the related user in PureCloud by Genesys.
63
63
64
64
To configure and test Azure AD SSO with PureCloud by Genesys, complete the following building blocks:
65
65
66
-
1.**[Configure Azure AD SSO](#configure-azure-ad-sso)**- to enable your users to use this feature.
67
-
1.**[Create an Azure AD test user](#create-an-azure-ad-test-user)**- to test Azure AD single sign-on with B.Simon.
68
-
1.**[Assign the Azure AD test user](#assign-the-azure-ad-test-user)**- to enable B.Simon to use Azure AD single sign-on.
69
-
1.**[Configure PureCloud by Genesys SSO](#configure-purecloud-by-genesys-sso)**- to configure the single sign-on settings on application side.
70
-
1.**[Create PureCloud by Genesys test user](#create-purecloud-by-genesys-test-user)**- to have a counterpart of B.Simon in PureCloud by Genesys that is linked to the Azure AD representation of user.
71
-
1.**[Test SSO](#test-sso)**- to verify whether the configuration works.
66
+
1.**[Configure Azure AD SSO](#configure-azure-ad-sso)** to enable your users to use this feature.
67
+
1.**[Create an Azure AD test user](#create-an-azure-ad-test-user)** to test Azure AD single sign-on with B.Simon.
68
+
1.**[Assign the Azure AD test user](#assign-the-azure-ad-test-user)** to enable B.Simon to use Azure AD single sign-on.
69
+
1.**[Configure PureCloud by Genesys SSO](#configure-purecloud-by-genesys-sso)** to configure the single sign-on settings on application side.
70
+
1.**[Create a PureCloud by Genesys test user](#create-purecloud-by-genesys-test-user)** to have a counterpart of B.Simon in PureCloud by Genesys that's linked to the Azure AD representation of user.
71
+
1.**[Test SSO](#test-sso)** to verify whether the configuration works.
72
72
73
73
## Configure Azure AD SSO
74
74
75
-
Follow these steps to enable Azure AD SSO in the Azure portal.
75
+
To enable Azure AD SSO in the Azure portal, follow these steps:
76
76
77
77
1. In the [Azure portal](https://portal.azure.com/), on the **PureCloud by Genesys** application integration page, find the **Manage** section and select **single sign-on**.
78
-
1. On the **Select a single sign-on method** page, select **SAML**.
79
-
1. On the **Set up single sign-on with SAML** page, click the edit/pen icon for **Basic SAML Configuration** to edit the settings.
78
+
1. On the **Select a Single Sign-On method** page, select **SAML**.
79
+
1. On the **Set up Single Sign-On with SAML** page, select the pen icon for **Basic SAML Configuration** to edit the settings.
1.On the **Basic SAML Configuration** section, if you wish to configure the application in **IDP**initiated mode, enter the values for the following fields:
83
+
1.In the **Basic SAML Configuration** section, if you want to configure the application in **IDP**-initiated mode, enter the values for the following fields:
84
84
85
-
a. In the **Identifier**text box, type a URL as per your region:
85
+
a. In the **Identifier** box, enter a URL that corresponds to your region:
86
86
87
87
| |
88
88
|--|
@@ -92,7 +92,7 @@ Follow these steps to enable Azure AD SSO in the Azure portal.
92
92
| `https://login.mypurecloud.ie/saml` |
93
93
| `https://login.mypurecloud.au/saml` |
94
94
95
-
b. In the **Reply URL** text box, type a URL as per your region:
95
+
b. In the **Reply URL** box, enter a URL that corresponds to your region:
96
96
97
97
| |
98
98
|--|
@@ -102,9 +102,9 @@ Follow these steps to enable Azure AD SSO in the Azure portal.
102
102
| `https://login.mypurecloud.ie/saml` |
103
103
| `https://login.mypurecloud.com.au/saml`|
104
104
105
-
1.Click**Set additional URLs** and perform the following step if you wish to configure the application in **SP** initiated mode:
105
+
1.Select**Set additional URLs** and take the following step if you want to configure the application in **SP** initiated mode:
106
106
107
-
In the **Sign-on URL**text box, type a URL as per your region:
107
+
In the **Sign-on URL** box, enter a URL that corresponds to your region:
108
108
109
109
| |
110
110
|--|
@@ -114,117 +114,117 @@ Follow these steps to enable Azure AD SSO in the Azure portal.
114
114
| `https://login.mypurecloud.ie` |
115
115
| `https://login.mypurecloud.com.au` |
116
116
117
-
1. PureCloud by Genesys application expects the SAML assertions in a specific format, which requires you to add custom attribute mappings to your SAML token attributes configuration. The following screenshot shows the list of default attributes.
117
+
1. PureCloud by Genesys application expects the SAML assertions in a specific format, which requires you to add custom attribute mappings to your SAML token attributes configuration. The following screenshot shows the list of default attributes:
118
118
119
119

120
120
121
-
1.In addition to above, PureCloud by Genesys application expects few more attributes to be passed back in SAML response which are shown below. These attributes are also prepopulated but you can review them as per your requirements.
121
+
1.Additionally, PureCloud by Genesys application expects a few more attributes to be passed back in the SAML response, as shown in the following table. These attributes are also pre-populated, but you can review them as needed.
122
122
123
-
| Name | Source Attribute|
123
+
| Name | Source attribute|
124
124
| ---------------| --------------- |
125
125
| Email | user.userprinicipalname |
126
126
| OrganizationName | `Your organization name` |
127
127
128
-
1. On the **Set up single sign-on with SAML** page, in the **SAML Signing Certificate** section, find **Certificate (Base64)** and select **Download** to download the certificate and save it on your computer.
128
+
1. On the **Set up Single Sign-On with SAML** page, in the **SAML Signing Certificate** section, find **Certificate (Base64)** and select **Download** to download the certificate and save it on your computer.
1. Select the **Show password** check box, and then make note of the value that's displayed in the **Password** box.
146
+
1.Select**Create**.
147
147
148
148
### Assign the Azure AD test user
149
149
150
-
In this section, you'll enable B.Simon to use Azure single sign-on by granting access to PureCloud by Genesys.
150
+
In this section, you'll set up B.Simon to use Azure single sign-on by granting access to PureCloud by Genesys.
151
151
152
152
1. In the Azure portal, select **Enterprise Applications**, and then select **All applications**.
153
153
1. In the applications list, select **PureCloud by Genesys**.
154
154
1. In the app's overview page, find the **Manage** section and select **Users and groups**.
155
155
156
156

157
157
158
-
1. Select **Add user**, then select **Users and groups** in the **Add Assignment** dialog.
158
+
1. Select **Add user**, and then select **Users and groups** in the **Add Assignment** dialog box.
159
159
160
160

161
161
162
-
1. In the **Users and groups** dialog, select **B.Simon** from the Users list, then click the **Select** button at the bottom of the screen.
163
-
1. If you're expecting any role value in the SAML assertion, in the **Select Role** dialog, select the appropriate role for the user from the list and then click the **Select** button at the bottom of the screen.
164
-
1. In the **Add Assignment** dialog, click the **Assign** button.
162
+
1. In the **Users and groups** dialog box, select **B.Simon** from the Users list, and then choose the **Select** button at the bottom of the screen.
163
+
1. If you're expecting any role value in the SAML assertion, in the **Select Role** dialog box, select the appropriate role for the user from the list, and then choose the **Select** button at the bottom of the screen.
164
+
1. In the **Add Assignment** dialog box, select the **Assign** button.
165
165
166
166
## Configure PureCloud by Genesys SSO
167
167
168
-
1. In a different web browser window, sign in to PureCloud by Genesys as an Administrator.
168
+
1. In a different web browser window, sign in to PureCloud by Genesys as an administrator.
169
169
170
-
1.Click on **Admin**on the top and navigate to **Single Sign-on** under **Integrations**.
170
+
1.Select **Admin**at the top and then go to **Single Sign-on** under **Integrations**.
171
171
172
172

173
173
174
-
1. Switch to **ADFS/Azure AD(Premium)** tab, and perform the following steps:
174
+
1. Switch to the **ADFS/Azure AD(Premium)** tab, and then follow these steps:
175
175
176
176

177
177
178
-
a. Click **Browse** to upload the base-64 encoded certificate that you have downloaded from the Azure portal, into the **ADFS Certificate**.
178
+
a. Select **Browse** to upload the base-64 encoded certificate that you downloaded from the Azure portal into the **ADFS Certificate**.
179
179
180
-
b. In the **ADFS Issuer URI** textbox, paste the value of **Azure AD Identifier** which you have copied from the Azure portal.
180
+
b. In the **ADFS Issuer URI** box, paste the value of **Azure AD Identifier** that you copied from the Azure portal.
181
181
182
-
c. In the **Target URI** textbox, paste the value of **Login URL** which you have copied from the Azure portal.
182
+
c. In the **Target URI** box, paste the value of **Login URL** that you copied from the Azure portal.
183
183
184
-
d. For **Relying Party Identifier** value, you need to go to the Azure portal, on the **PureCloud by Genesys** application integration page, click on **Properties** tab and copy the **Application ID** value. Paste it in the **Relying Party Identifier** textbox.
184
+
d. For the **Relying Party Identifier** value, go to the Azure portal, and then on the **PureCloud by Genesys** application integration page, select the **Properties** tab and copy the **Application ID** value. Paste it into the **Relying Party Identifier** box.
185
185
186
186

187
187
188
-
e. Click **Save**
188
+
e. Select **Save**.
189
189
190
190
### Create PureCloud by Genesys test user
191
191
192
192
To enable Azure AD users to sign in to PureCloud by Genesys, they must be provisioned into PureCloud by Genesys. In PureCloud by Genesys, provisioning is a manual task.
193
193
194
-
**To provision a user account, perform the following steps:**
194
+
**To provision a user account, follow these steps:**
195
195
196
-
1. Log in to PureCloud by Genesys as an Administrator.
196
+
1. Log in to PureCloud by Genesys as an administrator.
197
197
198
-
1.Click on **Admin**on the top and navigate to **People** under **People & Permissions**.
198
+
1.Select **Admin**at the top and go to **People** under **People & Permissions**.
199
199
200
200

201
201
202
-
1. On the People page, click on**Add Person**.
202
+
1. On the **People** page, select**Add Person**.
203
203
204
204

205
205
206
-
1.On the **Add People to the Organization**pop-up, perform the following steps:
206
+
1.In the **Add People to the Organization**dialog box, follow these steps:
207
207
208
208

209
209
210
-
a. In **Full Name** text box, enter the name of user like **B.simon**.
210
+
a. In the **Full Name** box, enter the name of a user. For example: **B.simon**.
211
211
212
-
b. In **Email** text box, enter the email of user like **b.simon\@contoso.com**.
212
+
b. In the **Email** box, enter the email of the user. For example: **b.simon\@contoso.com**.
213
213
214
-
c. Click **Create**.
214
+
c. Select **Create**.
215
215
216
216
## Test SSO
217
217
218
-
In this section, you test your Azure AD single sign-on configuration using the Access Panel.
218
+
In this section, you test your Azure AD single sign-on configuration by using the Access Panel.
219
219
220
-
When you click the PureCloud by Genesys tile in the Access Panel, you should be automatically signed in to the PureCloud by Genesys for which you set up SSO. For more information about the Access Panel, see [Introduction to the Access Panel](https://docs.microsoft.com/azure/active-directory/active-directory-saas-access-panel-introduction).
220
+
When you select the **PureCloud by Genesys** tile in the Access Panel, you should be automatically signed in to the PureCloud by Genesys account that you set up SSO for. For more information about the Access Panel, see [Introduction to the Access Panel](https://docs.microsoft.com/azure/active-directory/active-directory-saas-access-panel-introduction).
221
221
222
222
## Additional resources
223
223
224
-
-[ List of Tutorials on How to Integrate SaaS Apps with Azure Active Directory](https://docs.microsoft.com/azure/active-directory/active-directory-saas-tutorial-list)
224
+
-[ List of tutorials about how to integrate SaaS apps with Azure AD](https://docs.microsoft.com/azure/active-directory/active-directory-saas-tutorial-list)
225
225
226
-
-[What is application access and single sign-on with Azure Active Directory? ](https://docs.microsoft.com/azure/active-directory/active-directory-appssoaccess-whatis)
226
+
-[What is application access and single sign-on with Azure AD?](https://docs.microsoft.com/azure/active-directory/active-directory-appssoaccess-whatis)
227
227
228
-
-[What is conditional access in Azure Active Directory?](https://docs.microsoft.com/azure/active-directory/conditional-access/overview)
228
+
-[What is conditional access in Azure AD?](https://docs.microsoft.com/azure/active-directory/conditional-access/overview)
229
229
230
230
-[Try PureCloud by Genesys with Azure AD](https://aad.portal.azure.com/)
0 commit comments