You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
title: Azure Active Directory SSO integration with Document360
3
-
description: Learn how to configure single sign-on between Azure Active Directory and Document360.
3
+
description: Learn how to configure Single Sign-On (SSO) between Azure Active Directory (AD) and Document360.
4
4
services: active-directory
5
5
author: jeevansd
6
6
manager: CelesteDG
@@ -9,116 +9,141 @@ ms.service: active-directory
9
9
ms.subservice: saas-app-tutorial
10
10
ms.workload: identity
11
11
ms.topic: how-to
12
-
ms.date: 04/27/2023
12
+
ms.date: 08/21/2023
13
13
ms.author: jeedes
14
-
15
14
---
16
15
17
16
# Azure Active Directory SSO integration with Document360
18
17
19
-
In this article, you learn how to integrate Document360 with Azure Active Directory (Azure AD). Document360 is an online self-service knowledge base software. When you integrate Document360 with Azure AD, you can:
18
+
This article teaches you how to integrate Document360 with Azure AD. Document360 is an online self-service knowledge base software. When you integrate Document360 with Azure AD, you can:
20
19
21
20
* Control in Azure AD who has access to Document360.
22
-
* Enable your users to be automatically signed-in to Document360 with their Azure AD accounts.
21
+
* Enable your users to be automatically signedin to Document360 with their Azure AD accounts.
23
22
* Manage your accounts in one central location - the Azure portal.
24
23
25
-
You configure and test Azure AD single sign-on for Document360 in a test environment. Document360 supports **SP** and **IDP** initiated single sign-on.
24
+
You configure and test Azure AD single sign-on for Document360 in a test environment. Document360 supports **Service Provider (SP)** and **Identity Provider (IdP)** initiated SSO.
26
25
27
26
> [!NOTE]
28
-
> Identifier of this application is a fixed string value so only one instance can be configured in one tenant.
27
+
> Identifier of this application is a fixed string value, so only one instance can be configured in one tenant.
29
28
30
29
## Prerequisites
31
30
32
-
To integrate Azure Active Directory with Document360, you need:
31
+
To integrate Azure AD with Document360, you need the following:
33
32
34
33
* An Azure AD user account. If you don't already have one, you can [Create an account for free](https://azure.microsoft.com/free/?WT.mc_id=A261C142F).
35
34
* One of the following roles: Global Administrator, Cloud Application Administrator, Application Administrator, or owner of the service principal.
36
-
* An Azure AD subscription. If you don't have a subscription, you can get a [free account](https://azure.microsoft.com/free/).
37
-
* Document360 single sign-on (SSO) enabledsubscription.
35
+
* An Azure AD subscription. If you don't have a subscription, you can [get a free account](https://azure.microsoft.com/free/).
36
+
* Document360 subscription with SSO enabled. If you don't have a subscription, you can [Sign up for a new account](https://document360.com/signup/).
38
37
39
38
## Add application and assign a test user
40
39
41
-
Before you begin the process of configuring single sign-on, you need to add the Document360 application from the Azure AD gallery. You need a test user account to assign to the application and test the single sign-on configuration.
40
+
Before configuring SSO, add the Document360 application from the Azure AD gallery. You need a test user account to assign to the application and test the SSO configuration.
42
41
43
42
### Add Document360 from the Azure AD gallery
44
43
45
-
Add Document360 from the Azure AD application gallery to configure single sign-on with Document360. For more information on how to add application from the gallery, see the [Quickstart: Add application from the gallery](../manage-apps/add-application-portal.md).
44
+
Add Document360 from the Azure AD application gallery to configure SSO with Document360. For more information on adding an application from the gallery, see the [Quickstart: Add application from the gallery](../manage-apps/add-application-portal.md).
46
45
47
46
### Create and assign Azure AD test user
48
47
49
48
Follow the guidelines in the [create and assign a user account](../manage-apps/add-application-portal-assign-users.md) article to create a test user account in the Azure portal called B.Simon.
50
49
51
-
Alternatively, you can also use the [Enterprise App Configuration Wizard](https://portal.office.com/AdminPortal/home?Q=Docs#/azureadappintegration). In this wizard, you can add an application to your tenant, add users/groups to the app, and assign roles. The wizard also provides a link to the single sign-on configuration pane in the Azure portal. [Learn more about Microsoft 365 wizards.](/microsoft-365/admin/misc/azure-ad-setup-guides).
50
+
Alternatively, you can use the [Enterprise App Configuration Wizard](https://portal.office.com/AdminPortal/home?Q=Docs#/azureadappintegration). In this wizard, you can add an application to your tenant, add users/groups to the app, and assign roles. The wizard also provides a link to the single sign-on configuration pane in the Azure portal. [Learn more about Microsoft 365 wizards.](/microsoft-365/admin/misc/azure-ad-setup-guides).
52
51
53
52
## Configure Azure AD SSO
54
53
55
54
Complete the following steps to enable Azure AD single sign-on in the Azure portal.
56
55
57
56
1. In the Azure portal, on the **Document360** application integration page, find the **Manage** section and select **single sign-on**.
58
-
1. On the **Select a single sign-on method** page, select **SAML**.
59
-
1. On the **Set up single sign-on with SAML** page, select the pencil icon for **Basic SAML Configuration** to edit the settings.
57
+
2. On the **Select a single sign-on method** page, select **SAML**.
58
+
3. On the **Set up single sign-on with SAML** page, select the pencil icon for **Basic SAML Configuration** to edit the settings.
60
59
61
60

62
61
63
-
1. On the **Basic SAML Configuration** section, perform the following steps:
62
+
4. On the **Basic SAML Configuration** section, perform the following steps. Choose any one of the Identifiers, Reply URL, and Sign on URL based on your Data center region.
64
63
65
-
a. In the **Identifier** textbox, type one of the following URLs:
64
+
a. In the **Identifier** textbox, type/copy & paste one of the following URLs:
66
65
67
66
|**Identifier**|
68
67
|-----------|
69
68
|`https://identity.document360.io/saml`|
69
+
|**(or)**|
70
70
|`https://identity.us.document360.io/saml`|
71
71
72
-
b. In the **Reply URL** textbox, type a URL using one of the following patterns:
72
+
b. In the **Reply URL** textbox, type/copy & paste a URL using one of the following patterns:
1. If you wish to configure the application in **SP** initiated mode, then perform the following step:
80
+
5. If you wish to configure the application in **SP** initiated mode, then perform the following step:
80
81
81
-
In the **Sign on URL** textbox, type one of the following URLs:
82
+
In the **Sign on URL** textbox, type/copy & paste one of the following URLs:
82
83
83
84
|**Sign on URL**|
84
85
|-----------|
85
86
|`https://identity.document360.io `|
87
+
|**(or)**|
86
88
|`https://identity.us.document360.io`|
87
89
88
90
> [!NOTE]
89
-
> The Reply URL is not real. Update this value with the actual Reply URL. Contact [Document360 Client support team](mailto:[email protected]) to get the value. You can also refer to the patterns shown in the **Basic SAML Configuration** section in the Azure portal.
91
+
> The Reply URL is not real. Update this value with the actual Reply URL. You can also refer to the patterns shown in the Azure portal's **Basic SAML Configuration** section.
90
92
91
-
1. On the **Set-up single sign-on with SAML** page, in the **SAML Signing Certificate** section, find **Certificate (Raw)** and select **Download** to download the certificate and save it on your computer.
93
+
6. On the **Set-up single sign-on with SAML** page, in the **SAML Signing Certificate** section, find **Certificate (Base64)** and select **Download** to download the certificate and save it on your computer.
92
94
93
-

95
+

94
96
95
-
1. On the **Set up Document360** section, copy the appropriate URL(s) based on your requirement.
97
+
7. On the **Set up Document360** section, copy the appropriate URL(s) based on your requirement.
96
98
97
99

98
100
99
101
## Configure Document360 SSO
100
102
101
-
To configure single sign-on on **Document360** side, you need to send the downloaded **Certificate (Raw)** and appropriate copied URLs from Azure portal to [Document360 support team](mailto:[email protected]). They set this setting to have the SAML SSO connection set properly on both sides.
103
+
1. In a different web browser window, log in to your Document360 portal as an administrator.
104
+
105
+
1. To configure SSO on the **Document360** portal, you need to navigate to **Settings** → **Users & Security** → **SAML/OpenID** → **SAML** and perform the following steps:
106
+
107
+
[](./media/document360-tutorial/configuration.png#lightbox)
108
+
109
+
1. Click on the Edit icon in **SAML basic configuration** on the Document360 portal side and paste the values from Azure AD portal based on the below mentioned field associations.
110
+
111
+
| Document360 portal fields | Azure AD portal values |
112
+
| --- | --- |
113
+
| Email domains | Domains of emails you have under active directory |
114
+
| Sign On URL | Login URL |
115
+
| Entity ID | Azure AD identifier |
116
+
| Sign Out URL | Logout URL |
117
+
| SAML certificate | Download Certificate (Base64) from Azure AD side and upload in Document360 |
118
+
119
+
1. Click on the **Save** button when you’re done with the values.
120
+
102
121
103
122
### Create Document360 test user
104
123
105
-
In this section, you create a user called Britta Simon at Document360. Work with [Document360 support team](mailto:[email protected]) to add the users in the Document360 platform. Users must be created and activated before you use single sign-on.
124
+
1. In a different web browser window, log in to your Document360 portal as an administrator.
125
+
126
+
1. From the Document360 portal, go to **Settings → Users & Security → Team accounts & groups → Team account**. Click the **New team account** button and type in the required details, specify the roles, and follow the module steps to add a user to Document360.
127
+
128
+
[](./media/document360-tutorial/add-user.png#lightbox)
106
129
107
130
## Test SSO
108
131
109
-
In this section, you test your Azure AD single sign-on configuration with following options.
132
+
In this section, you test your Azure AD single sign-on configuration with the following options.
110
133
111
134
#### SP initiated:
112
135
113
-
* Click on **Test this application** in Azure portal. This will redirect to Document360 Sign-on URL where you can initiate the login flow.
136
+
* Click on **Test this application** in Azure portal. This will redirect to the Document360 Signon URL, where you can initiate the login flow.
114
137
115
-
* Go to Document360 Sign-on URL directly and initiate the login flow from there.
138
+
* Go to Document360 Sign-on URL directly and initiate the login flow.
116
139
117
140
#### IDP initiated:
118
141
119
-
* Click on **Test this application** in Azure portal and you should be automatically signed in to the Document360 for which you set up the SSO.
142
+
* Click on **Test this application** in the Azure portal, and you should be automatically signed in to the Document360 for which you set up the SSO.
143
+
144
+
You can also use Microsoft My Apps to test the application in any mode. When you click the Document360 tile in the My Apps if configured in SP mode, you will be redirected to the application sign-on page for initiating the login flow. If configured in IDP mode, you should be automatically signed in to the Document360 for which you set up the SSO.
120
145
121
-
You can also use Microsoft My Apps to test the application in any mode. When you click the Document360 tile in the My Apps, if configured in SP mode you would be redirected to the application sign-on page for initiating the login flow and if configured in IDP mode, you should be automatically signed in to the Document360 for which you set up the SSO. For more information about the My Apps, see [Introduction to the My Apps](../user-help/my-apps-portal-end-user-access.md).
146
+
For more information about the My Apps, see [Introduction to the My Apps](../user-help/my-apps-portal-end-user-access.md).
122
147
123
148
## Additional resources
124
149
@@ -127,4 +152,4 @@ You can also use Microsoft My Apps to test the application in any mode. When you
127
152
128
153
## Next steps
129
154
130
-
Once you configure Document360 you can enforce session control, which protects exfiltration and infiltration of your organization’s sensitive data in realtime. Session control extends from Conditional Access. [Learn how to enforce session control with Microsoft Cloud App Security](/cloud-app-security/proxy-deployment-aad).
155
+
Once you configure Document360, you can enforce session control, which protects the exfiltration and infiltration of your organization's sensitive data in real-time. Session control extends from Conditional Access. [Learn how to enforce session control with Microsoft Cloud App Security](/cloud-app-security/proxy-deployment-aad).
0 commit comments