You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/active-directory/saas-apps/citi-program-tutorial.md
+23-11Lines changed: 23 additions & 11 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -9,7 +9,7 @@ ms.service: active-directory
9
9
ms.subservice: saas-app-tutorial
10
10
ms.workload: identity
11
11
ms.topic: how-to
12
-
ms.date: 03/26/2023
12
+
ms.date: 04/12/2023
13
13
ms.author: jeedes
14
14
15
15
---
@@ -46,7 +46,7 @@ Add CITI Program from the Azure AD application gallery to configure single sign-
46
46
47
47
### Create and assign Azure AD test user
48
48
49
-
Follow the guidelines in the [create and assign a user account](../manage-apps/add-application-portal-assign-users.md) article to create a test user account in the Azure portal called B.Simon.
49
+
Follow the guidelines in the [create and assign a user account](../manage-apps/add-application-portal-assign-users.md) article to create a test user account in the Azure portal.
50
50
51
51
Alternatively, you can also use the [Enterprise App Configuration Wizard](https://portal.office.com/AdminPortal/home?Q=Docs#/azureadappintegration). In this wizard, you can add an application to your tenant, add users/groups to the app, and assign roles. The wizard also provides a link to the single sign-on configuration pane in the Azure portal. [Learn more about Microsoft 365 wizards.](/microsoft-365/admin/misc/azure-ad-setup-guides).
52
52
@@ -76,17 +76,24 @@ Complete the following steps to enable Azure AD single sign-on in the Azure port
76
76
77
77
1. CITI Program application expects the SAML assertions in a specific format, which requires you to add custom attribute mappings to your SAML token attributes configuration. The following screenshot shows the list of default attributes.
78
78
79
-

79
+

80
80
81
-
1.In addition to above, CITI Program application expects few more attributes to be passed back in SAML response, which are shown below. These attributes are also prepopulated but you can review them as per your requirements.
81
+
1. CITI Program application expects urn:oid named attributes to be passed back in the SAML response, which are shown below. These attributes are also pre-populated but you can review them as per your requirements. These are all required.
1. On the **Set-up single sign-on with SAML** page, in the **SAML Signing Certificate** section, find **Federation Metadata XML** and select **Download** to download the certificate and save it on your computer.
91
98
92
99

@@ -97,11 +104,7 @@ Complete the following steps to enable Azure AD single sign-on in the Azure port
97
104
98
105
## Configure CITI Program SSO
99
106
100
-
To configure single sign-on on **CITI Program** side, you need to send the downloaded **Federation Metadata XML** and appropriate copied URLs from Azure portal to [CITI Program support team](mailto:[email protected]). They set this setting to have the SAML SSO connection set properly on both sides.
101
-
102
-
### Create CITI Program test user
103
-
104
-
In this section, a user called B.Simon is created in CITI Program. CITI Program supports just-in-time user provisioning, which is enabled by default. There's no action item for you in this section. If a user doesn't already exist in CITI Program, a new one is commonly created after authentication.
107
+
To configure single sign-on on **CITI Program** side, you need to send the downloaded **Federation Metadata XML** and appropriate copied URLs from Azure portal to [CITI Program support team](mailto:[email protected]). This is required to have the SAML SSO connection set properly on both sides.
105
108
106
109
## Test SSO
107
110
@@ -113,10 +116,19 @@ In this section, you test your Azure AD single sign-on configuration with follow
113
116
114
117
* You can use Microsoft My Apps. When you click the CITI Program tile in the My Apps, this will redirect to CITI Program Sign-on URL. For more information about the My Apps, see [Introduction to the My Apps](../user-help/my-apps-portal-end-user-access.md).
115
118
119
+
CITI Program supports just-in-time user provisioning. First time SSO users will be prompted to either:
120
+
121
+
* Link their existing CITI Program account, in the case that they already have one
122
+

123
+
124
+
* Or Create a new CITI Program account, which is automatically provisioned
125
+

126
+
116
127
## Additional resources
117
128
129
+
*[CITI Program SSO Technical Information](https://support.citiprogram.org/s/article/single-sign-on-sso-and-shibboleth-technical-specs#EntityInformation)
118
130
*[What is single sign-on with Azure Active Directory?](../manage-apps/what-is-single-sign-on.md)
119
-
*[Plan a single sign-on deployment](../manage-apps/plan-sso-deployment.md).
131
+
*[Plan a single sign-on deployment](../manage-apps/plan-sso-deployment.md)
0 commit comments