You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/active-directory/saas-apps/workplacebyfacebook-tutorial.md
+26-16Lines changed: 26 additions & 16 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -14,7 +14,7 @@ ms.workload: identity
14
14
ms.tgt_pltfrm: na
15
15
ms.devlang: na
16
16
ms.topic: tutorial
17
-
ms.date: 08/13/2019
17
+
ms.date: 10/21/2019
18
18
ms.author: jeedes
19
19
20
20
ms.collection: M365-identity-device-management
@@ -60,18 +60,17 @@ To configure the integration of Workplace by Facebook into Azure AD, you need to
60
60
1. In the **Add from the gallery** section, type **Workplace by Facebook** in the search box.
61
61
1. Select **Workplace by Facebook** from results panel and then add the app. Wait a few seconds while the app is added to your tenant.
62
62
63
-
64
63
## Configure and test Azure AD SSO for Workplace by Facebook
65
64
66
65
Configure and test Azure AD SSO with Workplace by Facebook using a test user called **B.Simon**. For SSO to work, you need to establish a link relationship between an Azure AD user and the related user in Workplace by Facebook.
67
66
68
67
To configure and test Azure AD SSO with Workplace by Facebook, complete the following building blocks:
69
68
70
69
1.**[Configure Azure AD SSO](#configure-azure-ad-sso)** - to enable your users to use this feature.
71
-
1. **[Create an Azure AD test user](#create-an-azure-ad-test-user)** - to test Azure AD single sign-on with B.Simon.
72
-
1. **[Assign the Azure AD test user](#assign-the-azure-ad-test-user)** - to enable B.Simon to use Azure AD single sign-on.
70
+
* **[Create an Azure AD test user](#create-an-azure-ad-test-user)** - to test Azure AD single sign-on with B.Simon.
71
+
* **[Assign the Azure AD test user](#assign-the-azure-ad-test-user)** - to enable B.Simon to use Azure AD single sign-on.
73
72
2.**[Configure Workplace by Facebook SSO](#configure-workplace-by-facebook-sso)** - to configure the Single Sign-On settings on application side.
74
-
1. **[Create Workplace by Facebook test user](#create-workplace-by-facebook-test-user)** - to have a counterpart of B.Simon in Workplace by Facebook that is linked to the Azure AD representation of user.
73
+
* **[Create Workplace by Facebook test user](#create-workplace-by-facebook-test-user)** - to have a counterpart of B.Simon in Workplace by Facebook that is linked to the Azure AD representation of user.
75
74
3.**[Test SSO](#test-sso)** - to verify whether the configuration works.
76
75
77
76
## Configure Azure AD SSO
@@ -95,11 +94,11 @@ Follow these steps to enable Azure AD SSO in the Azure portal.
95
94
> [!NOTE]
96
95
> These values are not the real. Update these values with the actual Sign-On URL and Identifier. See the Authentication page of the Workplace Company Dashboard for the correct values for your Workplace community.
97
96
98
-
4. On the **Set up Single Sign-On with SAML** page, in the **SAML Signing Certificate** section, find **Certificate (Base64)** and select **Download** to download the certificate and save it on your computer.
97
+
1. On the **Set up Single Sign-On with SAML** page, in the **SAML Signing Certificate** section, find **Certificate (Base64)** and select **Download** to download the certificate and save it on your computer.
@@ -135,24 +134,36 @@ In this section, you'll enable B.Simon to use Azure single sign-on by granting a
135
134
136
135
## Configure Workplace by Facebook SSO
137
136
138
-
1. In a different web browser window, login to your Workplace by Facebook company site as an administrator.
139
-
137
+
1. To automate the configuration within Workplace by Facebook, you need to install **My Apps Secure Sign-in browser extension** by clicking **Install the extension**.
1. After adding extension to the browser, click on **Set up Workplace by Facebook** will direct you to the Workplace by Facebook application. From there, provide the admin credentials to sign into Workplace by Facebook. The browser extension will automatically configure the application for you and automate steps 3-5.
142
+
143
+

144
+
145
+
1. If you want to setup Workplace by Facebook manually, open a new web browser window and sign into your Workplace by Facebook company site as an administrator and perform the following steps:
146
+
140
147
> [!NOTE]
141
148
> As part of the SAML authentication process, Workplace may utilize query strings of up to 2.5 kilobytes in size in order to pass parameters to Azure AD.
142
149
143
-
2. In the **Admin Panel**, go to the **Security** tab.
150
+
1. On the left navigation panel, navigate to **Security** > **Authentication** tab.
a. In **SAML URL** textbox, paste the value of **Login URL**, which you have copied from Azure portal.
162
+
a. In the **Name of the SSO Provider**, enter the SSO instance name like Azureadsso.
152
163
153
-
b. In **SAML Issuer URI textbox**, paste the value of **Azure AD Identifier**, which you have copied from Azure portal.
164
+
b. In **SAML URL** textbox, paste the value of **Login URL**, which you have copied from Azure portal.
154
165
155
-
c. In **SAML Logout Redirect** (Optional), paste the value of **Logout URL**, which you have copied from Azure portal.
166
+
c. In **SAML Issuer URL** textbox, paste the value of **Azure AD Identifier**, which you have copied from Azure portal.
156
167
157
168
d. Open your **base-64 encoded certificate** in notepad downloaded from Azure portal, copy the content of it into your clipboard, and then paste it to the **SAML Certificate** textbox.
158
169
@@ -168,7 +179,7 @@ In this section, you'll enable B.Simon to use Azure single sign-on by granting a
168
179
169
180
i. All users using Workplace will now be presented with Azure AD login page for authentication.
170
181
171
-
4.**SAML Logout Redirect (optional)** -
182
+
1.**SAML Logout Redirect (optional)** -
172
183
173
184
You can choose to optionally configure a SAML Logout Url, which can be used to point at Azure AD's logout page. When this setting is enabled and configured, the user will no longer be directed to the Workplace logout page. Instead, the user will be redirected to the url that was added in the SAML Logout Redirect setting.
174
185
@@ -229,4 +240,3 @@ When you click the Workplace by Facebook tile in the Access Panel, you should be
229
240
-[Configure User Provisioning](workplacebyfacebook-provisioning-tutorial.md)
230
241
231
242
-[Try Workplace by Facebook with Azure AD](https://aad.portal.azure.com)
0 commit comments