Skip to content

Commit cd13774

Browse files
authored
Merge pull request #105420 from v-nagta/sharepoint
Product Backlog Item 938815: SaaS App Tutorial: SharePoint on-premise…
2 parents 358127d + 75946c1 commit cd13774

File tree

1 file changed

+29
-39
lines changed

1 file changed

+29
-39
lines changed

articles/active-directory/saas-apps/sharepoint-on-premises-tutorial.md

Lines changed: 29 additions & 39 deletions
Original file line numberDiff line numberDiff line change
@@ -12,68 +12,56 @@ ms.service: active-directory
1212
ms.subservice: saas-app-tutorial
1313
ms.workload: identity
1414
ms.tgt_pltfrm: na
15-
ms.devlang: na
1615
ms.topic: tutorial
17-
ms.date: 04/25/2019
16+
ms.date: 03/19/2020
1817
ms.author: jeedes
1918

2019
---
21-
# Tutorial: Azure Active Directory integration with SharePoint on-premises
20+
# Tutorial: Azure Active Directory single sign-on (SSO) integration with SharePoint on-premises
2221

23-
In this tutorial, you learn how to integrate SharePoint on-premises with Azure Active Directory (Azure AD).
24-
Integrating SharePoint on-premises with Azure AD provides you with the following benefits:
22+
In this tutorial, you'll learn how to integrate SharePoint on-premises with Azure Active Directory (Azure AD). When you integrate SharePoint on-premises with Azure AD, you can:
2523

26-
* You can control in Azure AD who has access to SharePoint on-premises.
27-
* You can enable your users to be automatically signed-in to SharePoint on-premises (Single Sign-On) with their Azure AD accounts.
28-
* You can manage your accounts in one central location - the Azure portal.
24+
* Control in Azure AD who has access to SharePoint on-premises.
25+
* Enable your users to be automatically signed-in to SharePoint on-premises with their Azure AD accounts.
26+
* Manage your accounts in one central location - the Azure portal.
2927

30-
If you want to know more details about SaaS app integration with Azure AD, see [What is application access and single sign-on with Azure Active Directory](https://docs.microsoft.com/azure/active-directory/active-directory-appssoaccess-whatis).
31-
If you don't have an Azure subscription, [create a free account](https://azure.microsoft.com/free/) before you begin.
28+
To learn more about SaaS app integration with Azure AD, see [What is application access and single sign-on with Azure Active Directory](https://docs.microsoft.com/azure/active-directory/manage-apps/what-is-single-sign-on).
3229

3330
## Prerequisites
3431

35-
To configure Azure AD integration with SharePoint on-premises, you need the following items:
32+
To get started, you need the following items:
3633

37-
* An Azure AD subscription. If you don't have an Azure AD environment, you can get a [free account](https://azure.microsoft.com/free/)
38-
* SharePoint on-premises single sign-on enabled subscription
34+
* An Azure AD subscription. If you don't have a subscription, you can get a [free account](https://azure.microsoft.com/free/).
35+
* SharePoint on-premises single sign-on (SSO) enabled subscription.
3936

4037
## Scenario description
4138

42-
In this tutorial, you configure and test Azure AD single sign-on in a test environment.
39+
In this tutorial, you configure and test Azure AD SSO in a test environment.
4340

4441
* SharePoint on-premises supports **SP** initiated SSO
42+
* Once you configure SharePoint on-premises you can enforce session controls, which protect exfiltration and infiltration of your organization’s sensitive data in real-time. Session control extend from Conditional Access. [Learn how to enforce session control with Microsoft Cloud App Security](https://docs.microsoft.com/cloud-app-security/proxy-deployment-any-app).
43+
* Please refer this [Link](https://docs.microsoft.com/archive/blogs/kaevans/sharepoint-2013-user-profile-sync-for-claims-users) to learn how to sync User Profiles from SharePoint On-Premise to Azure AD
4544

4645
## Adding SharePoint on-premises from the gallery
4746

4847
To configure the integration of SharePoint on-premises into Azure AD, you need to add SharePoint on-premises from the gallery to your list of managed SaaS apps.
4948

50-
**To add SharePoint on-premises from the gallery, perform the following steps:**
49+
1. Sign in to the [Azure portal](https://portal.azure.com) using either a work or school account, or a personal Microsoft account.
50+
1. On the left navigation pane, select the **Azure Active Directory** service.
5151

52-
1. In the **[Azure portal](https://portal.azure.com)**, on the left navigation panel, click **Azure Active Directory** icon.
53-
54-
![The Azure Active Directory button](common/select-azuread.png)
55-
56-
> [!NOTE]
57-
> If the element should not be available, it can also be opened through the fixed **All services** link at the top of the left navigation panel. In the following overview, the **Azure Active Directory** link is located in the **Identity** section or it can be searched for by using the filter text box.
58-
59-
2. Navigate to **Enterprise Applications** and then select the **All Applications** option.
60-
61-
![The Enterprise applications blade](common/enterprise-applications.png)
62-
63-
3. To add new application, click **New application** button on the top of dialog.
64-
65-
![The New application button](common/add-new-app.png)
66-
67-
4. In the search box, type **SharePoint on-premises**, select **SharePoint on-premises** from result panel then click **Add** button to add the application.
52+
> [!NOTE]
53+
> If the element should not be available, it can also be opened through the fixed **All services** link at the top of the left navigation panel. In the following overview, the **Azure Active Directory** link is located in the **Identity** section or it can be searched for by using the filter text box.
6854
69-
![SharePoint on-premises in the results list](common/search-new-app.png)
55+
1. Navigate to **Enterprise Applications** and then select **All Applications**.
56+
1. To add new application, select **New application**.
57+
1. In the **Add from the gallery** section, type **SharePoint on-premises** in the search box.
58+
1. Select **SharePoint on-premises** from results panel and then add the app. Wait a few seconds while the app is added to your tenant.
7059

71-
## Configure and test Azure AD single sign-on
60+
## Configure and test Azure AD single sign-on for SharePoint on-premises
7261

73-
In this section, you configure and test Azure AD single sign-on with SharePoint on-premises based on a test user called **Britta Simon**.
74-
For single sign-on to work, a link relationship between an Azure AD user and the related user in SharePoint on-premises needs to be established.
62+
Configure and test Azure AD SSO with SharePoint on-premises using a test user called **B.Simon**. For SSO to work, you need to establish a link relationship between an Azure AD user and the related user in SharePoint on-premises.
7563

76-
To configure and test Azure AD single sign-on with SharePoint on-premises, you need to complete the following building blocks:
64+
To configure and test Azure AD SSO with SharePoint on-premises, complete the following building blocks:
7765

7866
1. **[Configure Azure AD Single Sign-On](#configure-azure-ad-single-sign-on)** - to enable your users to use this feature.
7967
2. **[Configure SharePoint on-premises Single Sign-On](#configure-sharepoint-on-premises-single-sign-on)** - to configure the Single Sign-On settings on application side.
@@ -103,7 +91,6 @@ To configure Azure AD single sign-on with SharePoint on-premises, perform the fo
10391

10492
4. On the **Basic SAML Configuration** section, perform the following steps:
10593

106-
![SharePoint on-premises Domain and URLs single sign-on information](common/sp-identifier-reply.png)
10794

10895
a. In the **Sign-on URL** text box, type a URL using the following pattern:
10996
`https://<YourSharePointServerURL>/_trust/default.aspx`
@@ -317,6 +304,7 @@ The configuration works for a single web application, but needs additional confi
317304
$t.UseWReplyParameter=$true
318305
$t.Update()
319306
```
307+
320308
6. In Central Administration, go to the web application and enable the existing trusted identity provider. Remember to also configure the sign-in page URL as a custom sign in page `/_trust/`.
321309

322310
7. In Central Administration, click the web application and choose **User Policy**. Add a user with the appropriate permissions as demonstrated previously in this article.
@@ -358,7 +346,7 @@ To assist with this scenario, there is an open-source solution called [AzureCP](
358346

359347
### Create SharePoint on-premises test user
360348

361-
In this section, you create a user called Britta Simon in SharePoint on-premises. Work with [SharePoint on-premises support team](https://support.office.com/) to add the users in the SharePoint on-premises platform. Users must be created and activated before you use single sign-on.
349+
In this section, you create a user called Britta Simon in SharePoint on-premises. Work with [SharePoint on-premises support team](https://support.office.com/) to add the users in the SharePoint on-premises platform. Users must be created and activated before you use single sign-on.
362350

363351
### Test single sign-on
364352

@@ -370,6 +358,8 @@ When you click the SharePoint on-premises tile in the Access Panel, you should b
370358

371359
- [List of Tutorials on How to Integrate SaaS Apps with Azure Active Directory](https://docs.microsoft.com/azure/active-directory/active-directory-saas-tutorial-list)
372360

373-
- [What is application access and single sign-on with Azure Active Directory?](https://docs.microsoft.com/azure/active-directory/active-directory-appssoaccess-whatis)
361+
- [What is application access and single sign-on with Azure Active Directory?](https://docs.microsoft.com/azure/active-directory/manage-apps/what-is-single-sign-on)
374362

375363
- [What is Conditional Access in Azure Active Directory?](https://docs.microsoft.com/azure/active-directory/conditional-access/overview)
364+
365+
- [What is session control in Microsoft Cloud App Security?](https://docs.microsoft.com/cloud-app-security/proxy-intro-aad)

0 commit comments

Comments
 (0)