You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/active-directory/saas-apps/sharepoint-on-premises-tutorial.md
+29-39Lines changed: 29 additions & 39 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -12,68 +12,56 @@ ms.service: active-directory
12
12
ms.subservice: saas-app-tutorial
13
13
ms.workload: identity
14
14
ms.tgt_pltfrm: na
15
-
ms.devlang: na
16
15
ms.topic: tutorial
17
-
ms.date: 04/25/2019
16
+
ms.date: 03/19/2020
18
17
ms.author: jeedes
19
18
20
19
---
21
-
# Tutorial: Azure Active Directory integration with SharePoint on-premises
20
+
# Tutorial: Azure Active Directory single sign-on (SSO) integration with SharePoint on-premises
22
21
23
-
In this tutorial, you learn how to integrate SharePoint on-premises with Azure Active Directory (Azure AD).
24
-
Integrating SharePoint on-premises with Azure AD provides you with the following benefits:
22
+
In this tutorial, you'll learn how to integrate SharePoint on-premises with Azure Active Directory (Azure AD). When you integrate SharePoint on-premises with Azure AD, you can:
25
23
26
-
*You can control in Azure AD who has access to SharePoint on-premises.
27
-
*You can enable your users to be automatically signed-in to SharePoint on-premises (Single Sign-On) with their Azure AD accounts.
28
-
*You can manage your accounts in one central location - the Azure portal.
24
+
*Control in Azure AD who has access to SharePoint on-premises.
25
+
*Enable your users to be automatically signed-in to SharePoint on-premises with their Azure AD accounts.
26
+
*Manage your accounts in one central location - the Azure portal.
29
27
30
-
If you want to know more details about SaaS app integration with Azure AD, see [What is application access and single sign-on with Azure Active Directory](https://docs.microsoft.com/azure/active-directory/active-directory-appssoaccess-whatis).
31
-
If you don't have an Azure subscription, [create a free account](https://azure.microsoft.com/free/) before you begin.
28
+
To learn more about SaaS app integration with Azure AD, see [What is application access and single sign-on with Azure Active Directory](https://docs.microsoft.com/azure/active-directory/manage-apps/what-is-single-sign-on).
32
29
33
30
## Prerequisites
34
31
35
-
To configure Azure AD integration with SharePoint on-premises, you need the following items:
32
+
To get started, you need the following items:
36
33
37
-
* An Azure AD subscription. If you don't have an Azure AD environment, you can get a [free account](https://azure.microsoft.com/free/)
38
-
* SharePoint on-premises single sign-on enabled subscription
34
+
* An Azure AD subscription. If you don't have a subscription, you can get a [free account](https://azure.microsoft.com/free/).
35
+
* SharePoint on-premises single sign-on (SSO) enabled subscription.
39
36
40
37
## Scenario description
41
38
42
-
In this tutorial, you configure and test Azure AD single sign-on in a test environment.
39
+
In this tutorial, you configure and test Azure AD SSO in a test environment.
* Once you configure SharePoint on-premises you can enforce session controls, which protect exfiltration and infiltration of your organization’s sensitive data in real-time. Session control extend from Conditional Access. [Learn how to enforce session control with Microsoft Cloud App Security](https://docs.microsoft.com/cloud-app-security/proxy-deployment-any-app).
43
+
* Please refer this [Link](https://docs.microsoft.com/archive/blogs/kaevans/sharepoint-2013-user-profile-sync-for-claims-users) to learn how to sync User Profiles from SharePoint On-Premise to Azure AD
45
44
46
45
## Adding SharePoint on-premises from the gallery
47
46
48
47
To configure the integration of SharePoint on-premises into Azure AD, you need to add SharePoint on-premises from the gallery to your list of managed SaaS apps.
49
48
50
-
**To add SharePoint on-premises from the gallery, perform the following steps:**
49
+
1. Sign in to the [Azure portal](https://portal.azure.com) using either a work or school account, or a personal Microsoft account.
50
+
1. On the left navigation pane, select the **Azure Active Directory** service.
51
51
52
-
1. In the **[Azure portal](https://portal.azure.com)**, on the left navigation panel, click **Azure Active Directory** icon.
53
-
54
-

55
-
56
-
> [!NOTE]
57
-
> If the element should not be available, it can also be opened through the fixed **All services** link at the top of the left navigation panel. In the following overview, the **Azure Active Directory** link is located in the **Identity** section or it can be searched for by using the filter text box.
58
-
59
-
2. Navigate to **Enterprise Applications** and then select the **All Applications** option.
3. To add new application, click **New application** button on the top of dialog.
64
-
65
-

66
-
67
-
4. In the search box, type **SharePoint on-premises**, select **SharePoint on-premises** from result panel then click **Add** button to add the application.
52
+
> [!NOTE]
53
+
> If the element should not be available, it can also be opened through the fixed **All services** link at the top of the left navigation panel. In the following overview, the **Azure Active Directory** link is located in the **Identity** section or it can be searched for by using the filter text box.
68
54
69
-

55
+
1. Navigate to **Enterprise Applications** and then select **All Applications**.
56
+
1. To add new application, select **New application**.
57
+
1. In the **Add from the gallery** section, type **SharePoint on-premises** in the search box.
58
+
1. Select **SharePoint on-premises** from results panel and then add the app. Wait a few seconds while the app is added to your tenant.
70
59
71
-
## Configure and test Azure AD single sign-on
60
+
## Configure and test Azure AD single sign-on for SharePoint on-premises
72
61
73
-
In this section, you configure and test Azure AD single sign-on with SharePoint on-premises based on a test user called **Britta Simon**.
74
-
For single sign-on to work, a link relationship between an Azure AD user and the related user in SharePoint on-premises needs to be established.
62
+
Configure and test Azure AD SSO with SharePoint on-premises using a test user called **B.Simon**. For SSO to work, you need to establish a link relationship between an Azure AD user and the related user in SharePoint on-premises.
75
63
76
-
To configure and test Azure AD single sign-on with SharePoint on-premises, you need to complete the following building blocks:
64
+
To configure and test Azure AD SSO with SharePoint on-premises, complete the following building blocks:
77
65
78
66
1.**[Configure Azure AD Single Sign-On](#configure-azure-ad-single-sign-on)** - to enable your users to use this feature.
79
67
2.**[Configure SharePoint on-premises Single Sign-On](#configure-sharepoint-on-premises-single-sign-on)** - to configure the Single Sign-On settings on application side.
@@ -103,7 +91,6 @@ To configure Azure AD single sign-on with SharePoint on-premises, perform the fo
103
91
104
92
4. On the **Basic SAML Configuration** section, perform the following steps:
105
93
106
-

107
94
108
95
a. In the **Sign-on URL** text box, type a URL using the following pattern:
@@ -317,6 +304,7 @@ The configuration works for a single web application, but needs additional confi
317
304
$t.UseWReplyParameter=$true
318
305
$t.Update()
319
306
```
307
+
320
308
6. In Central Administration, go to the web application and enable the existing trusted identity provider. Remember to also configure the sign-in page URL as a custom sign in page `/_trust/`.
321
309
322
310
7. In Central Administration, click the web application and choose **User Policy**. Add a user with the appropriate permissions as demonstrated previously in this article.
@@ -358,7 +346,7 @@ To assist with this scenario, there is an open-source solution called [AzureCP](
358
346
359
347
### Create SharePoint on-premises test user
360
348
361
-
In this section, you create a user called Britta Simon in SharePoint on-premises. Work with[SharePoint on-premises support team](https://support.office.com/) to add the users in the SharePoint on-premises platform. Users must be created and activated before you use single sign-on.
349
+
In this section, you create a user called Britta Simon in SharePoint on-premises. Work with[SharePoint on-premises support team](https://support.office.com/) to add the users in the SharePoint on-premises platform. Users must be created and activated before you use single sign-on.
362
350
363
351
### Test single sign-on
364
352
@@ -370,6 +358,8 @@ When you click the SharePoint on-premises tile in the Access Panel, you should b
370
358
371
359
-[List of Tutorials on How to Integrate SaaS Apps with Azure Active Directory](https://docs.microsoft.com/azure/active-directory/active-directory-saas-tutorial-list)
372
360
373
-
-[What is application access and single sign-on with Azure Active Directory?](https://docs.microsoft.com/azure/active-directory/active-directory-appssoaccess-whatis)
361
+
-[What is application access and single sign-on with Azure Active Directory?](https://docs.microsoft.com/azure/active-directory/manage-apps/what-is-single-sign-on)
374
362
375
363
-[What is Conditional Access in Azure Active Directory?](https://docs.microsoft.com/azure/active-directory/conditional-access/overview)
364
+
365
+
-[What is session control in Microsoft Cloud App Security?](https://docs.microsoft.com/cloud-app-security/proxy-intro-aad)
0 commit comments