Skip to content

Commit 7271da1

Browse files
authored
Update eab-navigate-tutorial.md
1 parent 7003a11 commit 7271da1

File tree

1 file changed

+15
-31
lines changed

1 file changed

+15
-31
lines changed

articles/active-directory/saas-apps/eab-navigate-tutorial.md

Lines changed: 15 additions & 31 deletions
Original file line numberDiff line numberDiff line change
@@ -42,7 +42,8 @@ In this tutorial, you configure and test Azure AD SSO in a test environment.
4242

4343
* EAB Navigate supports **SP** initiated SSO
4444

45-
* Once you configure the EAB Navigate you can enforce session controls, which protect exfiltration and infiltration of your organization’s sensitive data in real-time. Session controls extend from Conditional Access. [Learn how to enforce session control with Microsoft Cloud App Security](https://docs.microsoft.com/cloud-app-security/proxy-deployment-any-app).
45+
> [!NOTE]
46+
> Identifier of this application is a fixed string value so only one instance can be configured in one tenant.
4647
4748
## Adding EAB Navigate from the gallery
4849

@@ -55,7 +56,6 @@ To configure the integration of EAB Navigate into Azure AD, you need to add EAB
5556
1. In the **Add from the gallery** section, type **EAB Navigate** in the search box.
5657
1. Select **EAB Navigate** from results panel and then add the app. Wait a few seconds while the app is added to your tenant.
5758

58-
5959
## Configure and test Azure AD single sign-on for EAB Navigate
6060

6161
Configure and test Azure AD SSO with EAB Navigate using a test user called **B.Simon**. For SSO to work, you need to establish a link relationship between an Azure AD user and the related user in EAB Navigate.
@@ -65,8 +65,8 @@ To configure and test Azure AD SSO with EAB Navigate, complete the following bui
6565
1. **[Configure Azure AD SSO](#configure-azure-ad-sso)** - to enable your users to use this feature.
6666
* **[Create an Azure AD test user](#create-an-azure-ad-test-user)** - to test Azure AD single sign-on with B.Simon.
6767
* **[Assign the Azure AD test user](#assign-the-azure-ad-test-user)** - to enable B.Simon to use Azure AD single sign-on.
68-
1. **[Configure EAB Navigate SSO](#configure-eab-navigate-sso)** - to configure the single sign-on settings on application side.
69-
* **[Create EAB Navigate test user](#create-eab-navigate-test-user)** - to have a counterpart of B.Simon in EAB Navigate that is linked to the Azure AD representation of user.
68+
1. **[Configure EAB Navigate SSO](#configure-eab-navigate-impl-sso)** - to configure the single sign-on settings on application side.
69+
* **[Create EAB Navigate test user](#create-eab-navigate-impl-test-user)** - to have a counterpart of B.Simon in EAB Navigate that is linked to the Azure AD representation of user.
7070
1. **[Test SSO](#test-sso)** - to verify whether the configuration works.
7171

7272
## Configure Azure AD SSO
@@ -79,33 +79,17 @@ Follow these steps to enable Azure AD SSO in the Azure portal.
7979

8080
![Edit Basic SAML Configuration](common/edit-urls.png)
8181

82-
1. On the **Basic SAML Configuration** section, if you have **Service Provider metadata file**, perform the following steps:
83-
84-
a. Click **Upload metadata file**.
85-
86-
![Upload metadata file](common/upload-metadata.png)
87-
88-
b. Click on **folder logo** to select the metadata file and click **Upload**.
89-
90-
![choose metadata file](common/browse-upload-metadata.png)
91-
92-
c. After the metadata file is successfully uploaded, the **Identifier** value gets auto populated in Basic SAML Configuration section.
93-
94-
![EAB Navigate Domain and URLs single sign-on information](common/sp-identifier.png)
95-
96-
In the **Sign-on URL** text box, type a URL using the following pattern:
97-
`https://<SUBDOMAIN>.navigate.eab.com`
98-
99-
> [!Note]
100-
> If the **Identifier** value does not get auto polulated, then please fill in the value manually according to your requirement. The Sign-on URL value is not real. Update this value with the actual Sign-on URL. Contact [EAB Navigate Client support team](mailto:[email protected]) to get this value. You can also refer to the patterns shown in the **Basic SAML Configuration** section in the Azure portal.
82+
1. On the **Basic SAML Configuration** section, enter the values for the following fields:
10183

102-
1. On the **Set up single sign-on with SAML** page, in the **SAML Signing Certificate** section, find **Certificate (Raw)** and select **Download** to download the certificate and save it on your computer.
84+
In the **Sign-on URL** text box, type a URL using the following pattern:
85+
`https://<SUBDOMAIN>.navigate.impl.eab.com/`
10386

104-
![The Certificate download link](common/certificateraw.png)
87+
> [!NOTE]
88+
> The value is not real. Update the value with the actual Sign-On URL. Contact [EAB Navigate Client support team](mailto:[email protected]) to get the value. You can also refer to the patterns shown in the **Basic SAML Configuration** section in the Azure portal.
10589

106-
1. On the **Set up EAB Navigate** section, copy the appropriate URL(s) based on your requirement.
90+
1. On the **Set up single sign-on with SAML** page, In the **SAML Signing Certificate** section, click copy button to copy **App Federation Metadata Url** and save it on your computer.
10791

108-
![Copy configuration URLs](common/copy-configuration-urls.png)
92+
![The Certificate download link](common/copy-metadataurl.png)
10993

11094
### Create an Azure AD test user
11195

@@ -139,13 +123,13 @@ In this section, you'll enable B.Simon to use Azure single sign-on by granting a
139123

140124
## Configure EAB Navigate SSO
141125

142-
To configure single sign-on on **EAB Navigate** side, you need to send the downloaded **Certificate (Raw)** and appropriate copied URLs from Azure portal to [EAB Navigate support team](mailto:jmahoney@eab.com). They set this setting to have the SAML SSO connection set properly on both sides.
126+
To configure single sign-on on **EAB Navigate** side, you need to send the **App Federation Metadata Url** to [EAB Navigate support team](mailto:EABTechSupport@eab.com). They set this setting to have the SAML SSO connection set properly on both sides.
143127

144128
### Create EAB Navigate test user
145129

146-
In this section, you create a user called B.Simon in EAB Navigate. Work with [EAB Navigate support team](mailto:jmahoney@eab.com) to add the users in the EAB Navigate platform. Users must be created and activated before you use single sign-on.
130+
In this section, you create a user called B.Simon in EAB Navigate. Work with [EAB Navigate support team](mailto:EABTechSupport@eab.com) to add the users in the EAB Navigate platform. Users must be created and activated before you use single sign-on.
147131

148-
## Test SSO
132+
## Test SSO
149133

150134
In this section, you test your Azure AD single sign-on configuration using the Access Panel.
151135

@@ -163,4 +147,4 @@ When you click the EAB Navigate tile in the Access Panel, you should be automati
163147

164148
- [What is session control in Microsoft Cloud App Security?](https://docs.microsoft.com/cloud-app-security/proxy-intro-aad)
165149

166-
- [How to protect EAB Navigate with advanced visibility and controls](https://docs.microsoft.com/cloud-app-security/proxy-intro-aad)
150+
- [How to protect EAB Navigate with advanced visibility and controls](https://docs.microsoft.com/cloud-app-security/proxy-intro-aad)

0 commit comments

Comments
 (0)