Skip to content

Commit 93ebb19

Browse files
authored
Merge pull request #92577 from v-nagta/workplacebyfb
Product Backlog Item 836348: SaaS App Tutorial: Workplace by Facebook…
2 parents 7c3b81d + b62f329 commit 93ebb19

File tree

3 files changed

+26
-16
lines changed

3 files changed

+26
-16
lines changed
Loading
Loading

articles/active-directory/saas-apps/workplacebyfacebook-tutorial.md

Lines changed: 26 additions & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -14,7 +14,7 @@ ms.workload: identity
1414
ms.tgt_pltfrm: na
1515
ms.devlang: na
1616
ms.topic: tutorial
17-
ms.date: 08/13/2019
17+
ms.date: 10/21/2019
1818
ms.author: jeedes
1919

2020
ms.collection: M365-identity-device-management
@@ -60,18 +60,17 @@ To configure the integration of Workplace by Facebook into Azure AD, you need to
6060
1. In the **Add from the gallery** section, type **Workplace by Facebook** in the search box.
6161
1. Select **Workplace by Facebook** from results panel and then add the app. Wait a few seconds while the app is added to your tenant.
6262

63-
6463
## Configure and test Azure AD SSO for Workplace by Facebook
6564

6665
Configure and test Azure AD SSO with Workplace by Facebook using a test user called **B.Simon**. For SSO to work, you need to establish a link relationship between an Azure AD user and the related user in Workplace by Facebook.
6766

6867
To configure and test Azure AD SSO with Workplace by Facebook, complete the following building blocks:
6968

7069
1. **[Configure Azure AD SSO](#configure-azure-ad-sso)** - to enable your users to use this feature.
71-
1. **[Create an Azure AD test user](#create-an-azure-ad-test-user)** - to test Azure AD single sign-on with B.Simon.
72-
1. **[Assign the Azure AD test user](#assign-the-azure-ad-test-user)** - to enable B.Simon to use Azure AD single sign-on.
70+
* **[Create an Azure AD test user](#create-an-azure-ad-test-user)** - to test Azure AD single sign-on with B.Simon.
71+
* **[Assign the Azure AD test user](#assign-the-azure-ad-test-user)** - to enable B.Simon to use Azure AD single sign-on.
7372
2. **[Configure Workplace by Facebook SSO](#configure-workplace-by-facebook-sso)** - to configure the Single Sign-On settings on application side.
74-
1. **[Create Workplace by Facebook test user](#create-workplace-by-facebook-test-user)** - to have a counterpart of B.Simon in Workplace by Facebook that is linked to the Azure AD representation of user.
73+
* **[Create Workplace by Facebook test user](#create-workplace-by-facebook-test-user)** - to have a counterpart of B.Simon in Workplace by Facebook that is linked to the Azure AD representation of user.
7574
3. **[Test SSO](#test-sso)** - to verify whether the configuration works.
7675

7776
## Configure Azure AD SSO
@@ -95,11 +94,11 @@ Follow these steps to enable Azure AD SSO in the Azure portal.
9594
> [!NOTE]
9695
> These values are not the real. Update these values with the actual Sign-On URL and Identifier. See the Authentication page of the Workplace Company Dashboard for the correct values for your Workplace community.
9796

98-
4. On the **Set up Single Sign-On with SAML** page, in the **SAML Signing Certificate** section, find **Certificate (Base64)** and select **Download** to download the certificate and save it on your computer.
97+
1. On the **Set up Single Sign-On with SAML** page, in the **SAML Signing Certificate** section, find **Certificate (Base64)** and select **Download** to download the certificate and save it on your computer.
9998

10099
![The Certificate download link](common/certificatebase64.png)
101100

102-
6. On the **Set up Workplace by Facebook** section, copy the appropriate URL(s) based on your requirement.
101+
1. On the **Set up Workplace by Facebook** section, copy the appropriate URL(s) based on your requirement.
103102

104103
![Copy configuration URLs](common/copy-configuration-urls.png)
105104

@@ -135,24 +134,36 @@ In this section, you'll enable B.Simon to use Azure single sign-on by granting a
135134

136135
## Configure Workplace by Facebook SSO
137136

138-
1. In a different web browser window, login to your Workplace by Facebook company site as an administrator.
139-
137+
1. To automate the configuration within Workplace by Facebook, you need to install **My Apps Secure Sign-in browser extension** by clicking **Install the extension**.
138+
139+
![My apps extension](common/install-myappssecure-extension.png)
140+
141+
1. After adding extension to the browser, click on **Set up Workplace by Facebook** will direct you to the Workplace by Facebook application. From there, provide the admin credentials to sign into Workplace by Facebook. The browser extension will automatically configure the application for you and automate steps 3-5.
142+
143+
![Setup configuration](common/setup-sso.png)
144+
145+
1. If you want to setup Workplace by Facebook manually, open a new web browser window and sign into your Workplace by Facebook company site as an administrator and perform the following steps:
146+
140147
> [!NOTE]
141148
> As part of the SAML authentication process, Workplace may utilize query strings of up to 2.5 kilobytes in size in order to pass parameters to Azure AD.
142149

143-
2. In the **Admin Panel**, go to the **Security** tab.
150+
1. On the left navigation panel, navigate to **Security** > **Authentication** tab.
144151

145152
![Admin Panel](./media/workplacebyfacebook-tutorial/tutorial-workplace-by-facebook-configure01.png)
146153

147-
3. Under **Authentication** tab, select **Single-Sign On (SSO)** and perform the following steps:
154+
a. Check the **Single-sign on(SSO)** option.
155+
156+
b. Click on **+Add new SSO Provider**.
157+
158+
1. Under **Authentication** tab, select **Single-Sign On (SSO)** and perform the following steps:
148159

149160
![Authentication Tab](./media/workplacebyfacebook-tutorial/tutorial-workplace-by-facebook-configure02.png)
150161

151-
a. In **SAML URL** textbox, paste the value of **Login URL**, which you have copied from Azure portal.
162+
a. In the **Name of the SSO Provider**, enter the SSO instance name like Azureadsso.
152163

153-
b. In **SAML Issuer URI textbox**, paste the value of **Azure AD Identifier**, which you have copied from Azure portal.
164+
b. In **SAML URL** textbox, paste the value of **Login URL**, which you have copied from Azure portal.
154165

155-
c. In **SAML Logout Redirect** (Optional), paste the value of **Logout URL**, which you have copied from Azure portal.
166+
c. In **SAML Issuer URL** textbox, paste the value of **Azure AD Identifier**, which you have copied from Azure portal.
156167

157168
d. Open your **base-64 encoded certificate** in notepad downloaded from Azure portal, copy the content of it into your clipboard, and then paste it to the **SAML Certificate** textbox.
158169

@@ -168,7 +179,7 @@ In this section, you'll enable B.Simon to use Azure single sign-on by granting a
168179

169180
i. All users using Workplace will now be presented with Azure AD login page for authentication.
170181

171-
4. **SAML Logout Redirect (optional)** -
182+
1. **SAML Logout Redirect (optional)** -
172183

173184
You can choose to optionally configure a SAML Logout Url, which can be used to point at Azure AD's logout page. When this setting is enabled and configured, the user will no longer be directed to the Workplace logout page. Instead, the user will be redirected to the url that was added in the SAML Logout Redirect setting.
174185

@@ -229,4 +240,3 @@ When you click the Workplace by Facebook tile in the Access Panel, you should be
229240
- [Configure User Provisioning](workplacebyfacebook-provisioning-tutorial.md)
230241

231242
- [Try Workplace by Facebook with Azure AD](https://aad.portal.azure.com)
232-

0 commit comments

Comments
 (0)