You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/active-directory/saas-apps/snowflake-tutorial.md
+22-21Lines changed: 22 additions & 21 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -9,7 +9,7 @@ ms.service: active-directory
9
9
ms.subservice: saas-app-tutorial
10
10
ms.workload: identity
11
11
ms.topic: tutorial
12
-
ms.date: 07/14/2022
12
+
ms.date: 08/16/2022
13
13
ms.author: jeedes
14
14
---
15
15
# Tutorial: Azure AD SSO integration with Snowflake
@@ -26,6 +26,8 @@ To configure Azure AD integration with Snowflake, you need the following items:
26
26
27
27
* An Azure AD subscription. If you don't have an Azure AD environment, you can get a [free account](https://azure.microsoft.com/free/).
28
28
* Snowflake single sign-on enabled subscription.
29
+
* Along with Cloud Application Administrator, Application Administrator can also add or manage applications in Azure AD.
30
+
For more information, see [Azure built-in roles](../roles/permissions-reference.md).
29
31
30
32
> [!NOTE]
31
33
> This integration is also available to use from Azure AD US Government Cloud environment. You can find this application in the Azure AD US Government Cloud Application Gallery and configure it in the same way as you do from public cloud.
@@ -69,17 +71,17 @@ Follow these steps to enable Azure AD SSO in the Azure portal.
69
71
1. On the **Select a single sign-on method** page, select **SAML**.
70
72
1. On the **Set up single sign-on with SAML** page, click the pencil icon for **Basic SAML Configuration** to edit the settings.
> These values are not real. Update these values with the actual Identifier, Reply URL and Sign-on URL. Contact [Snowflake Client support team](https://support.snowflake.net/s/) to get these values. You can also refer to the patterns shown in the **Basic SAML Configuration** section in the Azure portal.
93
+
> These values are not real. Update these values with the actual Identifier, Reply URL, Sign-on URL and Logout URL. Contact [Snowflake Client support team](https://support.snowflake.net/s/) to get these values. You can also refer to the patterns shown in the **Basic SAML Configuration** section in the Azure portal.
92
94
93
-
4. On the **Set up Single Sign-On with SAML** page, in the **SAML Signing Certificate** section, click **Download** to download the **Certificate (Base64)** from the given options as per your requirement and save it on your computer.
95
+
1. On the **Set up Single Sign-On with SAML** page, in the **SAML Signing Certificate** section, click **Download** to download the **Certificate (Base64)** from the given options as per your requirement and save it on your computer.
If you are using a new Snowflake URL with an organization name as the login URL, it is necessary to update the following parameters:
169
170
170
-
Alter the integration to add Snowflake Issuer URL and SAML2 Snowflake ACS URL, please follow the step-6 in [this](https://community.snowflake.com/s/article/HOW-TO-SETUP-SSO-WITH-ADFS-AND-THE-SNOWFLAKE-NEW-URL-FORMAT-OR-PRIVATELINK) article for more information.
171
+
Alter the integration to add Snowflake Issuer URL and SAML2 Snowflake ACS URL, please follow the step-6 in [this](https://community.snowflake.com/s/article/HOW-TO-SETUP-SSO-WITH-ADFS-AND-THE-SNOWFLAKE-NEW-URL-FORMAT-OR-PRIVATELINK) article for more information.
>Manually provisioning is uneccesary, if users and groups are provisioned with a SCIM integration. See how to enable auto provisioning for [Snowflake](snowflake-provisioning-tutorial.md).
207
+
>[!NOTE]
208
+
>Manually provisioning is uneccesary, if users and groups are provisioned with a SCIM integration. See how to enable auto provisioning for [Snowflake](snowflake-provisioning-tutorial.md).
208
209
209
210
## Test SSO
210
211
211
212
In this section, you test your Azure AD single sign-on configuration with following options.
212
213
213
214
#### SP initiated:
214
215
215
-
* Click on **Test this application** in Azure portal. This will redirect to Snowflake Signon URL where you can initiate the login flow.
216
+
* Click on **Test this application** in Azure portal. This will redirect to Snowflake Sign-on URL where you can initiate the login flow.
216
217
217
-
* Go to Snowflake Signon URL directly and initiate the login flow from there.
218
+
* Go to Snowflake Sign-on URL directly and initiate the login flow from there.
218
219
219
220
#### IDP initiated:
220
221
221
222
* Click on **Test this application** in Azure portal and you should be automatically signed in to the Snowflake for which you set up the SSO.
222
223
223
-
You can also use Microsoft My Apps to test the application in any mode. When you click the Snowflake tile in the My Apps, if configured in SP mode you would be redirected to the application Sign-on page for initiating the login flow and if configured in IDP mode, you should be automatically signed in to the Snowflake for which you set up the SSO. For more information about the My Apps, see [Introduction to the My Apps](../user-help/my-apps-portal-end-user-access.md).
224
+
You can also use Microsoft My Apps to test the application in any mode. When you click the Snowflake tile in the My Apps, if configured in SP mode you would be redirected to the application sign-on page for initiating the login flow and if configured in IDP mode, you should be automatically signed in to the Snowflake for which you set up the SSO. For more information about the My Apps, see [Introduction to the My Apps](../user-help/my-apps-portal-end-user-access.md).
0 commit comments