Skip to content

Commit 6a2e48d

Browse files
authored
Merge pull request #105264 from v-hagamp/shiphazmat
Product Backlog Item 930088: SaaS App Tutorial: ShipHazmat Update
2 parents dc8ff13 + 7ca9e11 commit 6a2e48d

File tree

1 file changed

+18
-4
lines changed

1 file changed

+18
-4
lines changed

articles/active-directory/saas-apps/shiphazmat-tutorial.md

Lines changed: 18 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -12,9 +12,8 @@ ms.service: active-directory
1212
ms.subservice: saas-app-tutorial
1313
ms.workload: identity
1414
ms.tgt_pltfrm: na
15-
ms.devlang: na
1615
ms.topic: tutorial
17-
ms.date: 10/17/2019
16+
ms.date: 02/24/2020
1817
ms.author: jeedes
1918

2019
ms.collection: M365-identity-device-management
@@ -28,7 +27,7 @@ In this tutorial, you'll learn how to integrate ShipHazmat with Azure Active Dir
2827
* Enable your users to be automatically signed-in to ShipHazmat with their Azure AD accounts.
2928
* Manage your accounts in one central location - the Azure portal.
3029

31-
To learn more about SaaS app integration with Azure AD, see [What is application access and single sign-on with Azure Active Directory](https://docs.microsoft.com/azure/active-directory/active-directory-appssoaccess-whatis).
30+
To learn more about SaaS app integration with Azure AD, see [What is application access and single sign-on with Azure Active Directory](https://docs.microsoft.com/azure/active-directory/manage-apps/what-is-single-sign-on).
3231

3332
## Prerequisites
3433

@@ -43,6 +42,8 @@ In this tutorial, you configure and test Azure AD SSO in a test environment.
4342

4443
* ShipHazmat supports **IDP** initiated SSO
4544
* ShipHazmat supports **Just In Time** user provisioning
45+
* Once you configure ShipHazmat you can enforce session control, which protects exfiltration and infiltration of your organization’s sensitive data in real time. Session control extends from Conditional Access. [Learn how to enforce session control with Microsoft Cloud App Security](https://docs.microsoft.com/cloud-app-security/proxy-deployment-any-app).
46+
4647

4748
## Adding ShipHazmat from the gallery
4849

@@ -90,6 +91,17 @@ Follow these steps to enable Azure AD SSO in the Azure portal.
9091
> [!NOTE]
9192
> These values are not real. Update these values with the actual Identifier and Reply URL. Contact [ShipHazmat Client support team](mailto:[email protected]) to get these values. You can also refer to the patterns shown in the **Basic SAML Configuration** section in the Azure portal.
9293

94+
1. ShipHazmat application expects the SAML assertions in a specific format, which requires you to add custom attribute mappings to your SAML token attributes configuration. The following screenshot shows the list of default attributes.
95+
96+
![image](common/default-attributes.png)
97+
98+
1. In addition to above, ShipHazmat application expects few more attributes to be passed back in SAML response which are shown below. These attributes are also pre populated but you can review them as per your requirements.
99+
100+
| Name | Source Attribute|
101+
| ------------ | --------- |
102+
| city | user.city |
103+
| state | user.state |
104+
93105
1. On the **Set up single sign-on with SAML** page, In the **SAML Signing Certificate** section, click copy button to copy **App Federation Metadata Url** and save it on your computer.
94106

95107
![The Certificate download link](common/copy-metadataurl.png)
@@ -142,8 +154,10 @@ When you click the ShipHazmat tile in the Access Panel, you should be automatica
142154

143155
- [ List of Tutorials on How to Integrate SaaS Apps with Azure Active Directory ](https://docs.microsoft.com/azure/active-directory/active-directory-saas-tutorial-list)
144156

145-
- [What is application access and single sign-on with Azure Active Directory? ](https://docs.microsoft.com/azure/active-directory/active-directory-appssoaccess-whatis)
157+
- [What is application access and single sign-on with Azure Active Directory? ](https://docs.microsoft.com/azure/active-directory/what-is-single-sign-on)
146158

147159
- [What is conditional access in Azure Active Directory?](https://docs.microsoft.com/azure/active-directory/conditional-access/overview)
148160

149161
- [Try ShipHazmat with Azure AD](https://aad.portal.azure.com/)
162+
163+
- [What is session control in Microsoft Cloud App Security?](https://docs.microsoft.com/cloud-app-security/proxy-intro-aad)

0 commit comments

Comments
 (0)