You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
In this tutorial, you'll learn how to integrate NS1 SSO for Azure with Azure Active Directory (Azure AD). When you integrate NS1 SSO for Azure with Azure AD, you can:
25
25
26
26
* Control in Azure AD who has access to NS1 SSO for Azure.
27
-
* Enable your users to be automatically signed-in to NS1 SSO for Azure with their Azure AD accounts.
28
-
* Manage your accounts in one central location - the Azure portal.
27
+
* Enable your users to be automatically signedin to NS1 SSO for Azure with their Azure AD accounts.
28
+
* Manage your accounts in one central location, the Azure portal.
29
29
30
-
To learn more about SaaS app integration with Azure AD, see [What is application access and single sign-on with Azure Active Directory](https://docs.microsoft.com/azure/active-directory/manage-apps/what-is-single-sign-on).
30
+
To learn more about software as a service (SaaS) app integration with Azure AD, see [What is application access and single sign-on with Azure Active Directory](https://docs.microsoft.com/azure/active-directory/manage-apps/what-is-single-sign-on).
31
31
32
32
## Prerequisites
33
33
@@ -40,138 +40,142 @@ To get started, you need the following items:
40
40
41
41
In this tutorial, you configure and test Azure AD SSO in a test environment.
42
42
43
-
* NS1 SSO for Azure supports **SP and IDP** initiated SSO
44
-
*Once you configure NS1 SSO for Azure you can enforce session control, which protect exfiltration and infiltration of your organization’s sensitive data in real-time. Session control extend from Conditional Access. [Learn how to enforce session control with Microsoft Cloud App Security](https://docs.microsoft.com/cloud-app-security/proxy-deployment-any-app).
43
+
* NS1 SSO for Azure supports SP and IDP initiated SSO.
44
+
*After you configure NS1 SSO for Azure, you can enforce session control. This protects exfiltration and infiltration of your organization’s sensitive data in realtime. Session control extends from conditional access. [Learn how to enforce session control with Microsoft Cloud App Security](https://docs.microsoft.com/cloud-app-security/proxy-deployment-any-app).
45
45
46
46
47
-
## Adding NS1 SSO for Azure from the gallery
47
+
## Add NS1 SSO for Azure from the gallery
48
48
49
49
To configure the integration of NS1 SSO for Azure into Azure AD, you need to add NS1 SSO for Azure from the gallery to your list of managed SaaS apps.
50
50
51
-
1. Sign in to the [Azure portal](https://portal.azure.com) using either a work or school account, or a personal Microsoft account.
51
+
1. Sign in to the [Azure portal](https://portal.azure.com)by using either a work or school account, or a personal Microsoft account.
52
52
1. On the left navigation pane, select the **Azure Active Directory** service.
53
-
1.Navigate to **Enterprise Applications** and then select **All Applications**.
54
-
1. To add new application, select **New application**.
53
+
1.Go to **Enterprise Applications**, and then select **All Applications**.
54
+
1. To add a new application, select **New application**.
55
55
1. In the **Add from the gallery** section, type **NS1 SSO for Azure** in the search box.
56
-
1. Select **NS1 SSO for Azure** from results panel and then add the app. Wait a few seconds while the app is added to your tenant.
56
+
1. Select **NS1 SSO for Azure** from the results panel, and then add the app. Wait a few seconds while the app is added to your tenant.
57
57
58
58
59
59
## Configure and test Azure AD single sign-on for NS1 SSO for Azure
60
60
61
-
Configure and test Azure AD SSO with NS1 SSO for Azure using a test user called **B.Simon**. For SSO to work, you need to establish a link relationship between an Azure AD user and the related user in NS1 SSO for Azure.
61
+
Configure and test Azure AD SSO with NS1 SSO for Azure by using a test user called **B.Simon**. For SSO to work, establish a linked relationship between an Azure AD user and the related user in NS1 SSO for Azure.
62
62
63
-
To configure and test Azure AD SSO with NS1 SSO for Azure, complete the following building blocks:
63
+
Here are the general steps to configure and test Azure AD SSO with NS1 SSO for Azure:
64
64
65
-
1.**[Configure Azure AD SSO](#configure-azure-ad-sso)** - to enable your users to use this feature.
66
-
1.**[Create an Azure AD test user](#create-an-azure-ad-test-user)** - to test Azure AD single sign-on with B.Simon.
67
-
1.**[Assign the Azure AD test user](#assign-the-azure-ad-test-user)** - to enable B.Simon to use Azure AD single sign-on.
68
-
1.**[Configure NS1 SSO for Azure SSO](#configure-ns1-sso-for-azure-sso)** - to configure the single sign-on settings on application side.
69
-
1.**[Create NS1 SSO for Azure test user](#create-ns1-sso-for-azure-test-user)** - to have a counterpart of B.Simon in NS1 SSO for Azure that is linked to the Azure AD representation of user.
70
-
1.**[Test SSO](#test-sso)** - to verify whether the configuration works.
65
+
1.**[Configure Azure AD SSO](#configure-azure-ad-sso)** to enable your users to use this feature.
66
+
67
+
a. **[Create an Azure AD test user](#create-an-azure-ad-test-user)** to test Azure AD single sign-on with B.Simon.
68
+
69
+
b. **[Assign the Azure AD test user](#assign-the-azure-ad-test-user)** to enable B.Simon to use Azure AD single sign-on.
70
+
1.**[Configure NS1 SSO for Azure SSO](#configure-ns1-sso-for-azure-sso)** to configure the single sign-on settings on the application side.
71
+
72
+
a. **[Create an NS1 SSO for Azure test user](#create-an-ns1-sso-for-azure-test-user)** to have a counterpart of B.Simon in NS1 SSO for Azure. This counterpart is linked to the Azure AD representation of the user.
73
+
1.**[Test SSO](#test-sso)** to verify whether the configuration works.
71
74
72
75
## Configure Azure AD SSO
73
76
74
77
Follow these steps to enable Azure AD SSO in the Azure portal.
75
78
76
-
1. In the [Azure portal](https://portal.azure.com/), on the **NS1 SSO for Azure** application integration page, find the **Manage** section and select**single sign-on**.
79
+
1. In the [Azure portal](https://portal.azure.com/), on the **NS1 SSO for Azure** application integration page, find the **Manage** section. Select**single sign-on**.
77
80
1. On the **Select a single sign-on method** page, select **SAML**.
78
-
1. On the **Set up single sign-on with SAML** page, click the edit/pen icon for **Basic SAML Configuration** to edit the settings.
81
+
1. On the **Set up single sign-on with SAML** page, select the pencil icon for **Basic SAML Configuration** to edit the settings.

81
84
82
-
1.On the **Basic SAML Configuration** section, if you wish to configure the application in **IDP** initiated mode, enter the values for the following fields:
85
+
1.In the **Basic SAML Configuration** section, if you want to configure the application in **IDP** initiated mode, enter the values for the following fields:
83
86
84
-
a. In the **Identifier** text box, type the URL:
87
+
a. In the **Identifier** text box, type the following URL:
85
88
`https://api.nsone.net/saml/metadata`
86
89
87
-
b. In the **Reply URL** text box, type a URL using the following pattern:
90
+
b. In the **Reply URL** text box, type a URL that uses the following pattern:
88
91
`https://api.nsone.net/saml/sso/<ssoid>`
89
92
90
-
1.Click**Set additional URLs** and perform the following step if you wish to configure the application in **SP** initiated mode:
93
+
1.Select**Set additional URLs**, and perform the following step if you want to configure the application in **SP** initiated mode:
91
94
92
-
In the **Sign-on URL** text box, type the URL:
95
+
In the **Sign-on URL** text box, type the following URL:
93
96
`https://my.nsone.net/#/login/sso`
94
97
95
98
> [!NOTE]
96
-
> The Reply URL value is not real. Update Reply URL value with the actual Reply URL. Contact [NS1 SSO for Azure Client support team](mailto:[email protected]) to get the value. You can also refer to the patterns shown in the **Basic SAML Configuration** section in the Azure portal.
99
+
> The Reply URL value isn't real. Update Reply URL value with the actual Reply URL. Contact the [NS1 SSO for Azure Client support team](mailto:[email protected]) to get the value. You can also refer to the patterns shown in the **Basic SAML Configuration** section in the Azure portal.
97
100
98
-
1. NS1 SSO for Azure application expects the SAML assertions in a specific format. Configure the following claims for this application. You can manage the values of these attributes from the **User Attributes** section on application integration page. On the **Set up Single Sign-On with SAML** page, click **Edit** button to open **User Attributes** dialog.
101
+
1.The NS1 SSO for Azure application expects the SAML assertions in a specific format. Configure the following claims for this application. You can manage the values of these attributes from the **User Attributes & Claims** section on the application integration page. On the **Set up Single Sign-On with SAML** page, select the pencil icon to open the **User Attributes** dialog box.

113
116
114
117
1. Select **ExactMailPrefix()** as **Transformation**.
115
118
116
119
1. Select **user.userprincipalname** as **Parameter 1**.
117
120
118
-
1.Click on**Add**.
121
+
1.Select**Add**.
119
122
120
-
1.Click on **Save**
123
+
1.Select **Save**.
121
124
122
-
1. On the **Set up single sign-on with SAML** page, In the **SAML Signing Certificate** section, click copy button to copy **App Federation Metadata Url** and save it on your computer.
125
+
1. On the **Set up single sign-on with SAML** page, in the **SAML Signing Certificate** section, select the copy button. This copies the **App Federation Metadata Url** and saves it on your computer.
1. Select the **Show password** check box, and then write down the value that's displayed in the **Password**box.
136
-
1.Click**Create**.
139
+
1. Select the **Show password** check box, and then write down the value that's shown in the **Password**field.
140
+
1.Select**Create**.
137
141
138
142
### Assign the Azure AD test user
139
143
140
-
In this section, you'll enable B.Simon to use Azure single sign-on by granting access to NS1 SSO for Azure.
144
+
In this section, you enable B.Simon to use Azure single sign-on by granting access to NS1 SSO for Azure.
141
145
142
-
1. In the Azure portal, select **Enterprise Applications**, and then select**All applications**.
146
+
1. In the Azure portal, select **Enterprise Applications** >**All applications**.
143
147
1. In the applications list, select **NS1 SSO for Azure**.
144
-
1. In the app's overview page, find the **Manage** section and select **Users and groups**.
148
+
1. In the app's overview page, find the **Manage** section, and select **Users and groups**.
145
149
146
-

150
+

147
151
148
-
1. Select **Add user**, then select**Users and groups**in the **Add Assignment** dialog.
152
+
1. Select **Add user**. In the**Add Assignment**dialog box, select **Users and groups**.
149
153
150
-

154
+

151
155
152
-
1. In the **Users and groups** dialog, select **B.Simon** from the Users list, then click the **Select** button at the bottom of the screen.
153
-
1. If you're expecting any role value in the SAML assertion, in the **Select Role** dialog, select the appropriate role for the user from the list and then click the **Select** button at the bottom of the screen.
154
-
1. In the **Add Assignment** dialog, click the **Assign** button.
156
+
1. In the **Users and groups** dialog box, select **B.Simon** from the users list. Then choose the **Select** button at the bottom of the screen.
157
+
1. If you're expecting any role value in the SAML assertion, in the **Select Role** dialog box, select the appropriate role for the user from the list. Then choose the **Select** button at the bottom of the screen.
158
+
1. In the **Add Assignment** dialog box, select **Assign**.
155
159
156
160
## Configure NS1 SSO for Azure SSO
157
161
158
-
To configure single sign-on on **NS1 SSO for Azure** side, you need to send the **App Federation Metadata Url** to [NS1 SSO for Azure support team](mailto:[email protected]). They set this setting to have the SAML SSO connection set properly on both sides.
162
+
To configure single sign-on on the NS1 SSO for Azure side, you need to send the App Federation Metadata URL to the [NS1 SSO for Azure support team](mailto:[email protected]). They configure this setting to have the SAML SSO connection set properly on both sides.
159
163
160
-
### Create NS1 SSO for Azure test user
164
+
### Create an NS1 SSO for Azure test user
161
165
162
-
In this section, you create a user called B.Simon in NS1 SSO for Azure. Work with NS1 SSO for Azure support team to add the users in the NS1 SSO for Azure platform. Users must be created and activated before you use single sign-on.
166
+
In this section, you create a user called B.Simon in NS1 SSO for Azure. Work with the NS1 SSO for Azure support team to add the users in the NS1 SSO for Azure platform. You can't use single sign-on until you create and activate users.
163
167
164
168
## Test SSO
165
169
166
-
In this section, you test your Azure AD single sign-on configuration using the Access Panel.
170
+
In this section, you test your Azure AD single sign-on configuration by using Access Panel.
167
171
168
-
When you click the NS1 SSO for Azure tile in the Access Panel, you should be automatically signed in to the NS1 SSO for Azure for which you set up SSO. For more information about the Access Panel, see [Introduction to the Access Panel](https://docs.microsoft.com/azure/active-directory/active-directory-saas-access-panel-introduction).
172
+
When you select the NS1 SSO for Azure tile in Access Panel, you should be automatically signed in to the NS1 SSO for Azure for which you set up SSO. For more information, see [Introduction to Access Panel](https://docs.microsoft.com/azure/active-directory/active-directory-saas-access-panel-introduction).
169
173
170
174
## Additional resources
171
175
172
-
-[ List of Tutorials on How to Integrate SaaS Apps with Azure Active Directory](https://docs.microsoft.com/azure/active-directory/active-directory-saas-tutorial-list)
176
+
-[Tutorials for integrating SaaS applications with Azure Active Directory](https://docs.microsoft.com/azure/active-directory/active-directory-saas-tutorial-list)
173
177
174
-
-[What is application access and single sign-on with Azure Active Directory?](https://docs.microsoft.com/azure/active-directory/manage-apps/what-is-single-sign-on)
178
+
-[What is application access and single sign-on with Azure Active Directory?](https://docs.microsoft.com/azure/active-directory/manage-apps/what-is-single-sign-on)
175
179
176
180
-[What is conditional access in Azure Active Directory?](https://docs.microsoft.com/azure/active-directory/conditional-access/overview)
0 commit comments