Skip to content

Commit 8d10570

Browse files
authored
Merge pull request #47850 from v-alje/bulk-fix-numbered-lists-1
Fixing numbered lists for LOC 1 of 7
2 parents 7eec9ec + 425a3be commit 8d10570

File tree

99 files changed

+2597
-2597
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

99 files changed

+2597
-2597
lines changed

articles/active-directory/saas-apps/amazon-web-service-tutorial.md

Lines changed: 47 additions & 47 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
---
1+
---
22
title: 'Tutorial: Azure Active Directory integration with Amazon Web Services (AWS) | Microsoft Docs'
33
description: Learn how to configure single sign-on between Azure Active Directory and Amazon Web Services (AWS).
44
services: active-directory
@@ -50,7 +50,7 @@ In this tutorial, you test Azure AD single sign-on in a test environment.
5050
The scenario outlined in this tutorial consists of two main building blocks:
5151

5252
1. Adding Amazon Web Services (AWS) from the gallery
53-
2. Configuring and testing Azure AD single sign-on
53+
1. Configuring and testing Azure AD single sign-on
5454

5555
## Adding Amazon Web Services (AWS) from the gallery
5656
To configure the integration of Amazon Web Services (AWS) into Azure AD, you need to add Amazon Web Services (AWS) from the gallery to your list of managed SaaS apps.
@@ -61,15 +61,15 @@ To configure the integration of Amazon Web Services (AWS) into Azure AD, you nee
6161

6262
![The Azure Active Directory button][1]
6363

64-
2. Navigate to **Enterprise applications**. Then go to **All applications**.
64+
1. Navigate to **Enterprise applications**. Then go to **All applications**.
6565

6666
![The Enterprise applications blade][2]
6767

68-
3. To add new application, click **New application** button on the top of dialog.
68+
1. To add new application, click **New application** button on the top of dialog.
6969

7070
![The New application button][3]
7171

72-
4. In the search box, type **Amazon Web Services (AWS)**, select **Amazon Web Services (AWS)** from result panel then click **Add** button to add the application.
72+
1. In the search box, type **Amazon Web Services (AWS)**, select **Amazon Web Services (AWS)** from result panel then click **Add** button to add the application.
7373

7474
![Amazon Web Services (AWS) in the results list](./media/amazon-web-service-tutorial/tutorial_amazonwebservices(aws)_addfromgallery.png)
7575

@@ -84,10 +84,10 @@ In Amazon Web Services (AWS), assign the value of the **user name** in Azure AD
8484
To configure and test Azure AD single sign-on with Amazon Web Services (AWS), you need to complete the following building blocks:
8585

8686
1. **[Configure Azure AD Single Sign-On](#configure-azure-ad-single-sign-on)** - to enable your users to use this feature.
87-
2. **[Create an Azure AD test user](#create-an-azure-ad-test-user)** - to test Azure AD single sign-on with Britta Simon.
88-
3. **[Create an Amazon Web Services (AWS) test user](#create-an-amazon-web-services-aws-test-user)** - to have a counterpart of Britta Simon in Amazon Web Services (AWS) that is linked to the Azure AD representation of user.
89-
4. **[Assign the Azure AD test user](#assign-the-azure-ad-test-user)** - to enable Britta Simon to use Azure AD single sign-on.
90-
5. **[Test single sign-on](#test-single-sign-on)** - to verify whether the configuration works.
87+
1. **[Create an Azure AD test user](#create-an-azure-ad-test-user)** - to test Azure AD single sign-on with Britta Simon.
88+
1. **[Create an Amazon Web Services (AWS) test user](#create-an-amazon-web-services-aws-test-user)** - to have a counterpart of Britta Simon in Amazon Web Services (AWS) that is linked to the Azure AD representation of user.
89+
1. **[Assign the Azure AD test user](#assign-the-azure-ad-test-user)** - to enable Britta Simon to use Azure AD single sign-on.
90+
1. **[Test single sign-on](#test-single-sign-on)** - to verify whether the configuration works.
9191

9292
### Configure Azure AD single sign-on
9393

@@ -99,19 +99,19 @@ In this section, you enable Azure AD single sign-on in the Azure portal and conf
9999

100100
![Configure single sign-on link][4]
101101

102-
2. On the **Single sign-on** dialog, select **Mode** as **SAML-based Sign-on** to enable single sign-on.
102+
1. On the **Single sign-on** dialog, select **Mode** as **SAML-based Sign-on** to enable single sign-on.
103103

104104
![Single sign-on dialog box](./media/amazon-web-service-tutorial/tutorial_amazonwebservices(aws)_samlbase.png)
105105

106-
3. On the **Amazon Web Services (AWS) Domain and URLs** section, the user does not have to perform any steps as the app is already pre-integrated with Azure.
106+
1. On the **Amazon Web Services (AWS) Domain and URLs** section, the user does not have to perform any steps as the app is already pre-integrated with Azure.
107107

108108
![Amazon Web Services (AWS) Domain and URLs single sign-on information](./media/amazon-web-service-tutorial/tutorial_amazonwebservices(aws)_url.png)
109109

110-
4. The Amazon Web Services (AWS) Software application expects the SAML assertions in a specific format. Configure the following claims for this application. You can manage the values of these attributes from the "**User Attributes**" section on application integration page. The following screenshot shows an example for this.
110+
1. The Amazon Web Services (AWS) Software application expects the SAML assertions in a specific format. Configure the following claims for this application. You can manage the values of these attributes from the "**User Attributes**" section on application integration page. The following screenshot shows an example for this.
111111

112112
![Configure Single Sign-On attb](./media/amazon-web-service-tutorial/tutorial_amazonwebservices(aws)_attribute.png)
113113

114-
5. In the **User Attributes** section on the **Single sign-on** dialog, configure SAML token attribute as shown in the image above and perform the following steps:
114+
1. In the **User Attributes** section on the **Single sign-on** dialog, configure SAML token attribute as shown in the image above and perform the following steps:
115115

116116
| Attribute Name | Attribute Value | Namespace |
117117
| --------------- | --------------- | --------------- |
@@ -135,29 +135,29 @@ In this section, you enable Azure AD single sign-on in the Azure portal and conf
135135

136136
d. Click **Ok**.
137137

138-
6. On the **SAML Signing Certificate** section, click **Metadata XML** and then save the metadata file on your computer.
138+
1. On the **SAML Signing Certificate** section, click **Metadata XML** and then save the metadata file on your computer.
139139

140140
![The Certificate download link](./media/amazon-web-service-tutorial/tutorial_amazonwebservices(aws)_certificate.png)
141141

142-
7. Click **Save** button.
142+
1. Click **Save** button.
143143

144144
![Configure Single Sign-On Save button](./media/amazon-web-service-tutorial/tutorial_general_400.png)
145145

146-
8. In a different browser window, sign-on to your Amazon Web Services (AWS) company site as administrator.
146+
1. In a different browser window, sign-on to your Amazon Web Services (AWS) company site as administrator.
147147

148-
9. Click **AWS Home**.
148+
1. Click **AWS Home**.
149149

150150
![Configure Single Sign-On home][11]
151151

152-
10. Click **Identity and Access Management**.
152+
1. Click **Identity and Access Management**.
153153

154154
![Configure Single Sign-On Identity][12]
155155

156-
11. Click **Identity Providers**, and then click **Create Provider**.
156+
1. Click **Identity Providers**, and then click **Create Provider**.
157157

158158
![Configure Single Sign-On Provider][13]
159159

160-
12. On the **Configure Provider** dialog page, perform the following steps:
160+
1. On the **Configure Provider** dialog page, perform the following steps:
161161

162162
![Configure Single Sign-On dialog][14]
163163

@@ -169,15 +169,15 @@ In this section, you enable Azure AD single sign-on in the Azure portal and conf
169169

170170
d. Click **Next Step**.
171171

172-
13. On the **Verify Provider Information** dialog page, click **Create**.
172+
1. On the **Verify Provider Information** dialog page, click **Create**.
173173

174174
![Configure Single Sign-On Verify][15]
175175

176-
14. Click **Roles**, and then click **Create role**.
176+
1. Click **Roles**, and then click **Create role**.
177177

178178
![Configure Single Sign-On Roles][16]
179179

180-
15. On the **Create role** page, perform the following steps:
180+
1. On the **Create role** page, perform the following steps:
181181

182182
![Configure Single Sign-On Trust][19]
183183

@@ -189,11 +189,11 @@ In this section, you enable Azure AD single sign-on in the Azure portal and conf
189189

190190
d. Click **Next: Permissions**.
191191

192-
16. On the **Attach Permissions Policies** dialog, you don't need to attach any policy. Click **Next: Review**.
192+
1. On the **Attach Permissions Policies** dialog, you don't need to attach any policy. Click **Next: Review**.
193193

194194
![Configure Single Sign-On Policy][33]
195195

196-
17. On the **Review** dialog, perform the following steps:
196+
1. On the **Review** dialog, perform the following steps:
197197

198198
![Configure Single Sign-On Review][34]
199199

@@ -205,21 +205,21 @@ In this section, you enable Azure AD single sign-on in the Azure portal and conf
205205

206206
d. Create as many roles as needed and map them to the Identity Provider.
207207

208-
18. Use AWS service account credentials for fetching the roles from AWS account in Azure AD User Provisioning. For this, open the AWS console home.
208+
1. Use AWS service account credentials for fetching the roles from AWS account in Azure AD User Provisioning. For this, open the AWS console home.
209209

210-
19. Click on **Services** -> **Security, Identity& Compliance** -> **IAM**.
210+
1. Click on **Services** -> **Security, Identity& Compliance** -> **IAM**.
211211

212212
![fetching the roles from AWS account](./media/amazon-web-service-tutorial/fetchingrole1.png)
213213

214-
20. Select the **Policies** tab in the IAM section.
214+
1. Select the **Policies** tab in the IAM section.
215215

216216
![fetching the roles from AWS account](./media/amazon-web-service-tutorial/fetchingrole2.png)
217217

218-
21. Create a new policy by clicking on **Create policy** for fetching the roles from AWS account in Azure AD User Provisioning.
218+
1. Create a new policy by clicking on **Create policy** for fetching the roles from AWS account in Azure AD User Provisioning.
219219

220220
![Creating new policy](./media/amazon-web-service-tutorial/fetchingrole3.png)
221221

222-
22. Create your own policy to fetch all the roles from AWS accounts by performing the following steps:
222+
1. Create your own policy to fetch all the roles from AWS accounts by performing the following steps:
223223

224224
![Creating new policy](./media/amazon-web-service-tutorial/policy1.png)
225225

@@ -259,7 +259,7 @@ In this section, you enable Azure AD single sign-on in the Azure portal and conf
259259

260260
![Define the new policy](./media/amazon-web-service-tutorial/policy5.png)
261261

262-
23. Define the **new policy** by performing the following steps:
262+
1. Define the **new policy** by performing the following steps:
263263

264264
![Define the new policy](./media/amazon-web-service-tutorial/policy2.png)
265265

@@ -269,7 +269,7 @@ In this section, you enable Azure AD single sign-on in the Azure portal and conf
269269

270270
c. Click on **“Create Policy”** button.
271271

272-
24. Create a new user account in the AWS IAM Service by performing the following steps:
272+
1. Create a new user account in the AWS IAM Service by performing the following steps:
273273

274274
a. Click on **Users** navigation in the AWS IAM console.
275275

@@ -289,7 +289,7 @@ In this section, you enable Azure AD single sign-on in the Azure portal and conf
289289

290290
* Click on the **Next Permissions** button in the bottom right corner.
291291

292-
25. Now create a new policy for this user by performing the following steps:
292+
1. Now create a new policy for this user by performing the following steps:
293293

294294
![Add user](./media/amazon-web-service-tutorial/adduser2.png)
295295

@@ -299,15 +299,15 @@ In this section, you enable Azure AD single sign-on in the Azure portal and conf
299299

300300
c. Select the **policy** and then click on the **Next: Review** button.
301301

302-
26. Review the policy to the attached user by performing following steps:
302+
1. Review the policy to the attached user by performing following steps:
303303

304304
![Add user](./media/amazon-web-service-tutorial/adduser3.png)
305305

306306
a. Review the user name, access type, and policy mapped to the user.
307307

308308
b. Click on the **Create user** button at the bottom right corner to create the user.
309309

310-
27. Download the user credentials of a user by performing following steps:
310+
1. Download the user credentials of a user by performing following steps:
311311

312312
![Add user](./media/amazon-web-service-tutorial/adduser4.png)
313313

@@ -317,11 +317,11 @@ In this section, you enable Azure AD single sign-on in the Azure portal and conf
317317

318318
c. Click on **Close** button at the bottom.
319319

320-
28. Navigate to **User Provisioning** section of Amazon Web Services app in Azure AD Management Portal.
320+
1. Navigate to **User Provisioning** section of Amazon Web Services app in Azure AD Management Portal.
321321

322322
![Add user](./media/amazon-web-service-tutorial/provisioning.png)
323323

324-
29. Enter the **Access Key** and **Secret** in the **Client Secret** and **Secret Token** field respectively.
324+
1. Enter the **Access Key** and **Secret** in the **Client Secret** and **Secret Token** field respectively.
325325

326326
![Add user](./media/amazon-web-service-tutorial/provisioning1.png)
327327

@@ -333,7 +333,7 @@ In this section, you enable Azure AD single sign-on in the Azure portal and conf
333333

334334
d. Save the setting by clicking on the **Save** button at the top.
335335

336-
30. Now make sure that you enable the Provisioning Status **On** in the Settings section by making the switch on and then clicking on the **Save** button at the top.
336+
1. Now make sure that you enable the Provisioning Status **On** in the Settings section by making the switch on and then clicking on the **Save** button at the top.
337337

338338
![Add user](./media/amazon-web-service-tutorial/provisioning2.png)
339339

@@ -353,15 +353,15 @@ The objective of this section is to create a test user in the Azure portal calle
353353

354354
![The Azure Active Directory button](./media/amazon-web-service-tutorial/create_aaduser_01.png)
355355

356-
2. To display the list of users, go to **Users and groups**, and then click **All users**.
356+
1. To display the list of users, go to **Users and groups**, and then click **All users**.
357357

358358
![The "Users and groups" and "All users" links](./media/amazon-web-service-tutorial/create_aaduser_02.png)
359359

360-
3. To open the **User** dialog box, click **Add** at the top of the **All Users** dialog box.
360+
1. To open the **User** dialog box, click **Add** at the top of the **All Users** dialog box.
361361

362362
![The Add button](./media/amazon-web-service-tutorial/create_aaduser_03.png)
363363

364-
4. In the **User** dialog box, perform the following steps:
364+
1. In the **User** dialog box, perform the following steps:
365365

366366
![The User dialog box](./media/amazon-web-service-tutorial/create_aaduser_04.png)
367367

@@ -389,23 +389,23 @@ In this section, you enable Britta Simon to use Azure single sign-on by granting
389389

390390
![Assign User][201]
391391

392-
2. In the applications list, select **Amazon Web Services (AWS)**.
392+
1. In the applications list, select **Amazon Web Services (AWS)**.
393393

394394
![The Amazon Web Services (AWS) link in the Applications list](./media/amazon-web-service-tutorial/tutorial_amazonwebservices(aws)_app.png)
395395

396-
3. In the menu on the left, click **Users and groups**.
396+
1. In the menu on the left, click **Users and groups**.
397397

398398
![The "Users and groups" link][202]
399399

400-
4. Click **Add** button. Then select **Users and groups** on **Add Assignment** dialog.
400+
1. Click **Add** button. Then select **Users and groups** on **Add Assignment** dialog.
401401

402402
![The Add Assignment pane][203]
403403

404-
5. On **Users and groups** dialog, select **Britta Simon** in the Users list.
404+
1. On **Users and groups** dialog, select **Britta Simon** in the Users list.
405405

406-
6. Click **Select** button on **Users and groups** dialog.
406+
1. Click **Select** button on **Users and groups** dialog.
407407

408-
7. Click **Assign** button on **Add Assignment** dialog.
408+
1. Click **Assign** button on **Add Assignment** dialog.
409409

410410
### Test single sign-on
411411

0 commit comments

Comments
 (0)