You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/active-directory/saas-apps/phenom-txm-tutorial.md
+32-36Lines changed: 32 additions & 36 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -9,14 +9,14 @@ ms.service: active-directory
9
9
ms.subservice: saas-app-tutorial
10
10
ms.workload: identity
11
11
ms.topic: tutorial
12
-
ms.date: 11/21/2022
12
+
ms.date: 02/08/2023
13
13
ms.author: jeedes
14
14
15
15
---
16
16
17
17
# Tutorial: Azure AD SSO integration with Phenom TXM
18
18
19
-
In this tutorial, you'll learn how to integrate Phenom TXM with Azure Active Directory (Azure AD). When you integrate Phenom TXM with Azure AD, you can:
19
+
In this tutorial, you will learn how to integrate Phenom TXM with Azure Active Directory (Azure AD). When you integrate Phenom TXM with Azure AD, you can:
20
20
21
21
* Control in Azure AD who has access to Phenom TXM.
22
22
* Enable your users to be automatically signed-in to Phenom TXM with their Azure AD accounts.
@@ -27,7 +27,7 @@ In this tutorial, you'll learn how to integrate Phenom TXM with Azure Active Dir
27
27
To get started, you need the following items:
28
28
29
29
* An Azure AD subscription. If you don't have a subscription, you can get a [free account](https://azure.microsoft.com/free/).
30
-
* Phenom TXM single sign-on (SSO) enabled subscription.
30
+
* Phenom TXM single sign-on (SSO) enabled subscription and a user account with the Client Admin role in Service Hub.
31
31
* Along with Cloud Application Administrator, Application Administrator can also add or manage applications in Azure AD.
32
32
For more information, see [Azure built-in roles](../roles/permissions-reference.md).
33
33
@@ -48,11 +48,11 @@ To configure the integration of Phenom TXM into Azure AD, you need to add Phenom
48
48
1. In the **Add from the gallery** section, type **Phenom TXM** in the search box.
49
49
1. Select **Phenom TXM** from results panel and then add the app. Wait a few seconds while the app is added to your tenant.
50
50
51
-
Alternatively, you can also use the [Enterprise App Configuration Wizard](https://portal.office.com/AdminPortal/home?Q=Docs#/azureadappintegration). In this wizard, you can add an application to your tenant, add users/groups to the app, assign roles, as well as walk through the SSO configuration as well. [Learn more about Microsoft 365 wizards.](/microsoft-365/admin/misc/azure-ad-setup-guides)
51
+
Alternatively, you can also use the [Enterprise App Configuration Wizard](https://portal.office.com/AdminPortal/home?Q=Docs#/azureadappintegration). In this wizard, you can add an application to your tenant, add users/groups to the app, assign roles, and walk through the SSO configuration as well. [Learn more about Microsoft 365 wizards.](/microsoft-365/admin/misc/azure-ad-setup-guides)
52
52
53
53
## Configure and test Azure AD SSO for Phenom TXM
54
54
55
-
Configure and test Azure AD SSO with Phenom TXM using a test user called **B.Simon**. For SSO to work, you need to establish a link relationship between an Azure AD user and the related user in Phenom TXM.
55
+
Configure and test Azure AD SSO with Phenom TXM using a test user called **B.Simon**. For SSO to work, you need to establish an assignment relationship between an Azure AD user or group and the related Phenom TXM application, ensuring that Azure AD passes the user's email address to Phenom TXM as a user identifier.
56
56
57
57
To configure and test Azure AD SSO with Phenom TXM, perform the following steps:
58
58
@@ -75,39 +75,33 @@ Follow these steps to enable Azure AD SSO in the Azure portal.
75
75
76
76
1. On the **Basic SAML Configuration** section, perform the following steps:
77
77
78
-
a. In the **Identifier** text box, type a URL using one of the following patterns:
78
+
a. In the **Identifier** text box, enter the **ENTITY ID** copied from Service Hub.
b. In the **Reply URL** text box, enter the **Redirect URI (ACS URL)** copied from Service Hub.
84
81
85
-
b. In the **Reply URL** text box, type a URL using one of the following patterns:
82
+
1. In the first **Reply URL** text box, enter the **Redirect URI (ACS URL)** copied from Service Hub and set the Index value to **0**.
86
83
87
-
| Reply URL |
88
-
|--------------|
89
-
|`https://<SUBDOMAIN>.phenompro.com/auth/<ID>`|
90
-
|`https://<SUBDOMAIN>.phenom.com/auth/<ID>`|
84
+
1. In the second **Reply URL** text box, enter the **Redirect URI (ACS URL) SP Initiated Flow** copied from Service Hub and set the Index value to **1**
91
85
92
-
1. Click **Set additional URLs** and perform the following step if you wish to configure the application in **SP** initiated mode:
93
-
94
-
In the **Sign-on URL** text box, type a URL using one of the following patterns:
86
+
> [!Note]
87
+
> Ensure that the first **Reply URL** is set as the **Default** using the checkbox.
95
88
96
-
| Sign-on URL |
97
-
|--------------|
98
-
|`https://<SUBDOMAIN>.phenompro.com`|
99
-
|`https://<SUBDOMAIN>.phenom.com`|
89
+
1. Perform the following step if you wish to configure the application in **SP** initiated mode:
90
+
91
+
In the **Sign on URL** text box, type one of the following URLs:
100
92
101
-
> [!NOTE]
102
-
> These values are not real. Update these values with the actual Identifier, Reply URL and Sign-on URL. Contact [Phenom TXM Client support team](mailto:[email protected]) to get these values. You can also refer to the patterns shown in the **Basic SAML Configuration** section in the Azure portal.
93
+
| Environment | Sign on URL |
94
+
|--------------|-------------|
95
+
| Staging |`https://login-stg.phenompro.com`|
96
+
| Production |`https://login.phenom.com`|
103
97
104
98
1. On the **Set up single sign-on with SAML** page, In the **SAML Signing Certificate** section, click copy button to copy **App Federation Metadata Url** and save it on your computer.
105
99
106
100

107
101
108
102
### Create an Azure AD test user
109
103
110
-
In this section, you'll create a test user in the Azure portal called B.Simon.
104
+
In this section, you will create a test user in the Azure portal called B.Simon.
111
105
112
106
1. From the left pane in the Azure portal, select **Azure Active Directory**, select **Users**, and then select **All users**.
113
107
1. Select **New user** at the top of the screen.
@@ -119,19 +113,19 @@ In this section, you'll create a test user in the Azure portal called B.Simon.
119
113
120
114
### Assign the Azure AD test user
121
115
122
-
In this section, you'll enable B.Simon to use Azure single sign-on by granting access to Phenom TXM.
116
+
In this section, you will enable B.Simon to use Azure single sign-on by granting access to Phenom TXM.
123
117
124
118
1. In the Azure portal, select **Enterprise Applications**, and then select **All applications**.
125
119
1. In the applications list, select **Phenom TXM**.
126
120
1. In the app's overview page, find the **Manage** section and select **Users and groups**.
127
121
1. Select **Add user**, then select **Users and groups** in the **Add Assignment** dialog.
128
122
1. In the **Users and groups** dialog, select **B.Simon** from the Users list, then click the **Select** button at the bottom of the screen.
129
-
1. If you are expecting a role to be assigned to the users, you can select it from the **Select a role** dropdown. If no role has been set up for this app, you see "Default Access" role selected.
123
+
1. If you're expecting a role to be assigned to the users, you can select it from the **Select a role** dropdown. If no role has been set up for this app, you see "Default Access" role selected.
130
124
1. In the **Add Assignment** dialog, click the **Assign** button.
131
125
132
126
## Configure Phenom TXM SSO
133
127
134
-
1. Log in to your Phenom TXM company site as an administrator.
128
+
1. Log in to your Phenom TXM instance Service Hub as a user with the Client Admin role.
135
129
136
130
1. Go to **Settings** tab > **Identity Provider**.
137
131
@@ -141,21 +135,23 @@ In this section, you'll enable B.Simon to use Azure single sign-on by granting a
141
135
142
136

143
137
144
-
a. Enter a valid name in the **Display Name**textbox.
138
+
a. Choose **SAML**from the dropdown selector.
145
139
146
-
b. In the **Single SignOn URL** textbox, paste the **Login URL**value which you have copied from the Azure portal.
140
+
b. Enter a valid name in the **Display Name**textbox.
147
141
148
-
c. In the **Meta data URL** textbox, paste the **App Federation Metadata Url** value which you have copied from the Azure portal.
142
+
c. In the **Single SignOn URL** textbox, paste the **Login URL** value, which you've copied from the Azure portal.
149
143
150
-
d. Click **Save Changes**.
144
+
d. In the **Meta data URL** textbox, paste the **App Federation Metadata Url** value, which you've copied from the Azure portal.
151
145
152
146
e. Copy **Entity ID** value, paste this value into the **Identifier** text box in the **Basic SAML Configuration** section in the Azure portal.
153
147
154
-
f. Copy **Redirect URI (ACS URL)** value, paste this value into the **Reply URL** text box in the **Basic SAML Configuration** section in the Azure portal.
148
+
f. Copy **Redirect URI (ACS URL)** value, paste this value into the first **Reply URL** text box in the **Basic SAML Configuration** section in the Azure portal.
149
+
150
+
g. Copy **Redirect URI (ACS URL) SP Initiated Flow** value, paste this value into the second **Reply URL** text box in the **Basic SAML Configuration** section in the Azure portal.
155
151
156
152
### Create Phenom TXM test user
157
153
158
-
1. In a different web browser window, log into your Phenom TXM website as an administrator.
154
+
1. In a different web browser window, log in to your Phenom TXM website as an administrator.
159
155
160
156
1. Go to **Users** tab and click **Create Users** > **Create single new User**.
161
157
@@ -183,15 +179,15 @@ In this section, you test your Azure AD single sign-on configuration with follow
183
179
184
180
#### SP initiated:
185
181
186
-
* Click on **Test this application** in Azure portal. This will redirect to Phenom TXM Signon URL where you can initiate the login flow.
182
+
* Click on **Test this application** in Azure portal. This will redirect to Phenom TXM Sign-on URL where you can initiate the login flow.
187
183
188
184
* Go to Phenom TXM Sign-on URL directly and initiate the login flow from there.
189
185
190
186
#### IDP initiated:
191
187
192
188
* Click on **Test this application** in Azure portal and you should be automatically signed in to the Phenom TXM for which you set up the SSO.
193
189
194
-
You can also use Microsoft My Apps to test the application in any mode. When you click the Phenom TXM tile in the My Apps, if configured in SP mode you would be redirected to the application signon page for initiating the login flow and if configured in IDP mode, you should be automatically signed in to the Phenom TXM for which you set up the SSO. For more information about the My Apps, see [Introduction to the My Apps](../user-help/my-apps-portal-end-user-access.md).
190
+
You can also use Microsoft My Apps to test the application in any mode. When you click the Phenom TXM tile in the My Apps, if configured in SP mode you would be redirected to the application sign-on page for initiating the login flow and if configured in IDP mode, you should be automatically signed in to the Phenom TXM for which you set up the SSO. For more information about the My Apps, see [Introduction to the My Apps](../user-help/my-apps-portal-end-user-access.md).
0 commit comments