You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/active-directory/saas-apps/shiphazmat-tutorial.md
+18-4Lines changed: 18 additions & 4 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -12,9 +12,8 @@ ms.service: active-directory
12
12
ms.subservice: saas-app-tutorial
13
13
ms.workload: identity
14
14
ms.tgt_pltfrm: na
15
-
ms.devlang: na
16
15
ms.topic: tutorial
17
-
ms.date: 10/17/2019
16
+
ms.date: 02/24/2020
18
17
ms.author: jeedes
19
18
20
19
ms.collection: M365-identity-device-management
@@ -28,7 +27,7 @@ In this tutorial, you'll learn how to integrate ShipHazmat with Azure Active Dir
28
27
* Enable your users to be automatically signed-in to ShipHazmat with their Azure AD accounts.
29
28
* Manage your accounts in one central location - the Azure portal.
30
29
31
-
To learn more about SaaS app integration with Azure AD, see [What is application access and single sign-on with Azure Active Directory](https://docs.microsoft.com/azure/active-directory/active-directory-appssoaccess-whatis).
30
+
To learn more about SaaS app integration with Azure AD, see [What is application access and single sign-on with Azure Active Directory](https://docs.microsoft.com/azure/active-directory/manage-apps/what-is-single-sign-on).
32
31
33
32
## Prerequisites
34
33
@@ -43,6 +42,8 @@ In this tutorial, you configure and test Azure AD SSO in a test environment.
43
42
44
43
* ShipHazmat supports **IDP** initiated SSO
45
44
* ShipHazmat supports **Just In Time** user provisioning
45
+
* Once you configure ShipHazmat you can enforce session control, which protects exfiltration and infiltration of your organization’s sensitive data in real time. Session control extends from Conditional Access. [Learn how to enforce session control with Microsoft Cloud App Security](https://docs.microsoft.com/cloud-app-security/proxy-deployment-any-app).
46
+
46
47
47
48
## Adding ShipHazmat from the gallery
48
49
@@ -90,6 +91,17 @@ Follow these steps to enable Azure AD SSO in the Azure portal.
90
91
> [!NOTE]
91
92
> These values are not real. Update these values with the actual Identifier and Reply URL. Contact [ShipHazmat Client support team](mailto:[email protected]) to get these values. You can also refer to the patterns shown in the **Basic SAML Configuration** section in the Azure portal.
92
93
94
+
1. ShipHazmat application expects the SAML assertions in a specific format, which requires you to add custom attribute mappings to your SAML token attributes configuration. The following screenshot shows the list of default attributes.
95
+
96
+

97
+
98
+
1. In addition to above, ShipHazmat application expects few more attributes to be passed back in SAML response which are shown below. These attributes are also pre populated but you can review them as per your requirements.
99
+
100
+
| Name | Source Attribute|
101
+
| ------------ | --------- |
102
+
| city | user.city |
103
+
| state | user.state |
104
+
93
105
1. On the **Set up single sign-on with SAML** page, In the **SAML Signing Certificate** section, click copy button to copy **App Federation Metadata Url** and save it on your computer.
@@ -142,8 +154,10 @@ When you click the ShipHazmat tile in the Access Panel, you should be automatica
142
154
143
155
-[ List of Tutorials on How to Integrate SaaS Apps with Azure Active Directory ](https://docs.microsoft.com/azure/active-directory/active-directory-saas-tutorial-list)
144
156
145
-
-[What is application access and single sign-on with Azure Active Directory? ](https://docs.microsoft.com/azure/active-directory/active-directory-appssoaccess-whatis)
157
+
-[What is application access and single sign-on with Azure Active Directory? ](https://docs.microsoft.com/azure/active-directory/what-is-single-sign-on)
146
158
147
159
-[What is conditional access in Azure Active Directory?](https://docs.microsoft.com/azure/active-directory/conditional-access/overview)
148
160
149
161
-[Try ShipHazmat with Azure AD](https://aad.portal.azure.com/)
162
+
163
+
-[What is session control in Microsoft Cloud App Security?](https://docs.microsoft.com/cloud-app-security/proxy-intro-aad)
0 commit comments