Skip to content

Commit d6c402c

Browse files
authored
Merge pull request #189298 from bhavana-129/tutorial-to-update-152
SaaS App Tutorial: TutorialtoUpdate152
2 parents ee15c0e + ee1df05 commit d6c402c

File tree

9 files changed

+85
-144
lines changed

9 files changed

+85
-144
lines changed
56.7 KB
Loading
9.25 KB
Loading
21.6 KB
Loading
49.1 KB
Loading
19.7 KB
Loading

articles/active-directory/saas-apps/shiphazmat-tutorial.md

Lines changed: 21 additions & 38 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
---
2-
title: 'Tutorial: Azure Active Directory single sign-on (SSO) integration with ShipHazmat | Microsoft Docs'
2+
title: 'Tutorial: Azure AD SSO integration with ShipHazmat'
33
description: Learn how to configure single sign-on between Azure Active Directory and ShipHazmat.
44
services: active-directory
55
author: jeevansd
@@ -9,20 +9,18 @@ ms.service: active-directory
99
ms.subservice: saas-app-tutorial
1010
ms.workload: identity
1111
ms.topic: tutorial
12-
ms.date: 02/24/2020
12+
ms.date: 02/22/2022
1313
ms.author: jeedes
1414
---
1515

16-
# Tutorial: Azure Active Directory single sign-on (SSO) integration with ShipHazmat
16+
# Tutorial: Azure AD SSO integration with ShipHazmat
1717

1818
In this tutorial, you'll learn how to integrate ShipHazmat with Azure Active Directory (Azure AD). When you integrate ShipHazmat with Azure AD, you can:
1919

2020
* Control in Azure AD who has access to ShipHazmat.
2121
* Enable your users to be automatically signed-in to ShipHazmat with their Azure AD accounts.
2222
* Manage your accounts in one central location - the Azure portal.
2323

24-
To learn more about SaaS app integration with Azure AD, see [What is application access and single sign-on with Azure Active Directory](../manage-apps/what-is-single-sign-on.md).
25-
2624
## Prerequisites
2725

2826
To get started, you need the following items:
@@ -34,49 +32,46 @@ To get started, you need the following items:
3432

3533
In this tutorial, you configure and test Azure AD SSO in a test environment.
3634

37-
* ShipHazmat supports **IDP** initiated SSO
38-
* ShipHazmat supports **Just In Time** user provisioning
39-
* Once you configure ShipHazmat you can enforce session control, which protects exfiltration and infiltration of your organization's sensitive data in real time. Session control extends from Conditional Access. [Learn how to enforce session control with Microsoft Defender for Cloud Apps](/cloud-app-security/proxy-deployment-any-app).
40-
35+
* ShipHazmat supports **IDP** initiated SSO.
36+
* ShipHazmat supports **Just In Time** user provisioning.
4137

42-
## Adding ShipHazmat from the gallery
38+
## Add ShipHazmat from the gallery
4339

4440
To configure the integration of ShipHazmat into Azure AD, you need to add ShipHazmat from the gallery to your list of managed SaaS apps.
4541

46-
1. Sign in to the [Azure portal](https://portal.azure.com) using either a work or school account, or a personal Microsoft account.
42+
1. Sign in to the Azure portal using either a work or school account, or a personal Microsoft account.
4743
1. On the left navigation pane, select the **Azure Active Directory** service.
4844
1. Navigate to **Enterprise Applications** and then select **All Applications**.
4945
1. To add new application, select **New application**.
5046
1. In the **Add from the gallery** section, type **ShipHazmat** in the search box.
5147
1. Select **ShipHazmat** from results panel and then add the app. Wait a few seconds while the app is added to your tenant.
5248

53-
54-
## Configure and test Azure AD single sign-on for ShipHazmat
49+
## Configure and test Azure AD SSO for ShipHazmat
5550

5651
Configure and test Azure AD SSO with ShipHazmat using a test user called **B.Simon**. For SSO to work, you need to establish a link relationship between an Azure AD user and the related user in ShipHazmat.
5752

58-
To configure and test Azure AD SSO with ShipHazmat, complete the following building blocks:
53+
To configure and test Azure AD SSO with ShipHazmat, perform the following steps:
5954

6055
1. **[Configure Azure AD SSO](#configure-azure-ad-sso)** - to enable your users to use this feature.
61-
* **[Create an Azure AD test user](#create-an-azure-ad-test-user)** - to test Azure AD single sign-on with B.Simon.
62-
* **[Assign the Azure AD test user](#assign-the-azure-ad-test-user)** - to enable B.Simon to use Azure AD single sign-on.
56+
1. **[Create an Azure AD test user](#create-an-azure-ad-test-user)** - to test Azure AD single sign-on with B.Simon.
57+
1. **[Assign the Azure AD test user](#assign-the-azure-ad-test-user)** - to enable B.Simon to use Azure AD single sign-on.
6358
1. **[Configure ShipHazmat SSO](#configure-shiphazmat-sso)** - to configure the single sign-on settings on application side.
64-
* **[Create ShipHazmat test user](#create-shiphazmat-test-user)** - to have a counterpart of B.Simon in ShipHazmat that is linked to the Azure AD representation of user.
59+
1. **[Create ShipHazmat test user](#create-shiphazmat-test-user)** - to have a counterpart of B.Simon in ShipHazmat that is linked to the Azure AD representation of user.
6560
1. **[Test SSO](#test-sso)** - to verify whether the configuration works.
6661

6762
## Configure Azure AD SSO
6863

6964
Follow these steps to enable Azure AD SSO in the Azure portal.
7065

71-
1. In the [Azure portal](https://portal.azure.com/), on the **ShipHazmat** application integration page, find the **Manage** section and select **single sign-on**.
66+
1. In the Azure portal, on the **ShipHazmat** application integration page, find the **Manage** section and select **single sign-on**.
7267
1. On the **Select a single sign-on method** page, select **SAML**.
73-
1. On the **Set up single sign-on with SAML** page, click the edit/pen icon for **Basic SAML Configuration** to edit the settings.
68+
1. On the **Set up single sign-on with SAML** page, click the pencil icon for **Basic SAML Configuration** to edit the settings.
7469

7570
![Edit Basic SAML Configuration](common/edit-urls.png)
7671

77-
1. On the **Set up single sign-on with SAML** page, enter the values for the following fields:
72+
1. On the **Basic SAML Configuration** section, perform the following steps:
7873

79-
a. In the **Identifier** text box, type a URL using the following pattern:
74+
a. In the **Identifier** text box, type a value using the following pattern:
8075
`ShipHazmat<CustomOrganization>Sso`
8176

8277
b. In the **Reply URL** text box, type a URL using the following pattern:
@@ -119,13 +114,7 @@ In this section, you'll enable B.Simon to use Azure single sign-on by granting a
119114
1. In the Azure portal, select **Enterprise Applications**, and then select **All applications**.
120115
1. In the applications list, select **ShipHazmat**.
121116
1. In the app's overview page, find the **Manage** section and select **Users and groups**.
122-
123-
![The "Users and groups" link](common/users-groups-blade.png)
124-
125117
1. Select **Add user**, then select **Users and groups** in the **Add Assignment** dialog.
126-
127-
![The Add User link](common/add-assign-user.png)
128-
129118
1. In the **Users and groups** dialog, select **B.Simon** from the Users list, then click the **Select** button at the bottom of the screen.
130119
1. If you're expecting any role value in the SAML assertion, in the **Select Role** dialog, select the appropriate role for the user from the list and then click the **Select** button at the bottom of the screen.
131120
1. In the **Add Assignment** dialog, click the **Assign** button.
@@ -140,18 +129,12 @@ In this section, a user called B.Simon is created in ShipHazmat. ShipHazmat supp
140129

141130
## Test SSO
142131

143-
In this section, you test your Azure AD single sign-on configuration using the Access Panel.
144-
145-
When you click the ShipHazmat tile in the Access Panel, you should be automatically signed in to the ShipHazmat for which you set up SSO. For more information about the Access Panel, see [Introduction to the Access Panel](https://support.microsoft.com/account-billing/sign-in-and-start-apps-from-the-my-apps-portal-2f3b1bae-0e5a-4a86-a33e-876fbd2a4510).
146-
147-
## Additional resources
148-
149-
- [ List of Tutorials on How to Integrate SaaS Apps with Azure Active Directory ](./tutorial-list.md)
132+
In this section, you test your Azure AD single sign-on configuration with following options.
150133

151-
- [What is application access and single sign-on with Azure Active Directory? ](../manage-apps/what-is-single-sign-on.md)
134+
* Click on Test this application in Azure portal and you should be automatically signed in to the ShipHazmat for which you set up the SSO.
152135

153-
- [What is conditional access in Azure Active Directory?](../conditional-access/overview.md)
136+
* You can use Microsoft My Apps. When you click the ShipHazmat tile in the My Apps, you should be automatically signed in to the ShipHazmat for which you set up the SSO. For more information about the My Apps, see [Introduction to the My Apps](../user-help/my-apps-portal-end-user-access.md).
154137

155-
- [Try ShipHazmat with Azure AD](https://aad.portal.azure.com/)
138+
## Next steps
156139

157-
- [What is session control in Microsoft Defender for Cloud Apps?](/cloud-app-security/proxy-intro-aad)
140+
Once you configure ShipHazmat you can enforce session control, which protects exfiltration and infiltration of your organization’s sensitive data in real time. Session control extends from Conditional Access. [Learn how to enforce session control with Microsoft Cloud App Security](/cloud-app-security/proxy-deployment-aad).

articles/active-directory/saas-apps/skysite-tutorial.md

Lines changed: 24 additions & 37 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
---
2-
title: 'Tutorial: Azure Active Directory single sign-on (SSO) integration with SKYSITE | Microsoft Docs'
2+
title: 'Tutorial: Azure AD SSO integration with SKYSITE'
33
description: Learn how to configure single sign-on between Azure Active Directory and SKYSITE.
44
services: active-directory
55
author: jeevansd
@@ -9,20 +9,18 @@ ms.service: active-directory
99
ms.subservice: saas-app-tutorial
1010
ms.workload: identity
1111
ms.topic: tutorial
12-
ms.date: 08/27/2019
12+
ms.date: 02/22/2022
1313
ms.author: jeedes
1414
---
1515

16-
# Tutorial: Azure Active Directory single sign-on (SSO) integration with SKYSITE
16+
# Tutorial: Azure AD SSO integration with SKYSITE
1717

1818
In this tutorial, you'll learn how to integrate SKYSITE with Azure Active Directory (Azure AD). When you integrate SKYSITE with Azure AD, you can:
1919

2020
* Control in Azure AD who has access to SKYSITE.
2121
* Enable your users to be automatically signed-in to SKYSITE with their Azure AD accounts.
2222
* Manage your accounts in one central location - the Azure portal.
2323

24-
To learn more about SaaS app integration with Azure AD, see [What is application access and single sign-on with Azure Active Directory](../manage-apps/what-is-single-sign-on.md).
25-
2624
## Prerequisites
2725

2826
To get started, you need the following items:
@@ -34,27 +32,26 @@ To get started, you need the following items:
3432

3533
In this tutorial, you configure and test Azure AD SSO in a test environment.
3634

37-
* SKYSITE supports **IDP** initiated SSO
35+
* SKYSITE supports **IDP** initiated SSO.
3836

39-
* SKYSITE supports **Just In Time** user provisioning
37+
* SKYSITE supports **Just In Time** user provisioning.
4038

41-
## Adding SKYSITE from the gallery
39+
## Add SKYSITE from the gallery
4240

4341
To configure the integration of SKYSITE into Azure AD, you need to add SKYSITE from the gallery to your list of managed SaaS apps.
4442

45-
1. Sign in to the [Azure portal](https://portal.azure.com) using either a work or school account, or a personal Microsoft account.
43+
1. Sign in to the Azure portal using either a work or school account, or a personal Microsoft account.
4644
1. On the left navigation pane, select the **Azure Active Directory** service.
4745
1. Navigate to **Enterprise Applications** and then select **All Applications**.
4846
1. To add new application, select **New application**.
4947
1. In the **Add from the gallery** section, type **SKYSITE** in the search box.
5048
1. Select **SKYSITE** from results panel and then add the app. Wait a few seconds while the app is added to your tenant.
5149

52-
53-
## Configure and test Azure AD single sign-on for SKYSITE
50+
## Configure and test Azure AD SSO for SKYSITE
5451

5552
Configure and test Azure AD SSO with SKYSITE using a test user called **B.Simon**. For SSO to work, you need to establish a link relationship between an Azure AD user and the related user in SKYSITE.
5653

57-
To configure and test Azure AD SSO with SKYSITE, complete the following building blocks:
54+
To configure and test Azure AD SSO with SKYSITE, perform the following steps:
5855

5956
1. **[Configure Azure AD SSO](#configure-azure-ad-sso)** - to enable your users to use this feature.
6057
1. **[Create an Azure AD test user](#create-an-azure-ad-test-user)** - to test Azure AD single sign-on with B.Simon.
@@ -67,15 +64,15 @@ To configure and test Azure AD SSO with SKYSITE, complete the following building
6764

6865
Follow these steps to enable Azure AD SSO in the Azure portal.
6966

70-
1. In the [Azure portal](https://portal.azure.com/), on the **SKYSITE** application integration page, click on **Properties tab** and perform the following step:
67+
1. In the Azure portal, on the **SKYSITE** application integration page, click on **Properties tab** and perform the following step:
7168

72-
![Single sign-on properties](./media/skysite-tutorial/config05.png)
69+
![Screenshot shows Single sign-on properties.](./media/skysite-tutorial/property.png)
7370

7471
* Copy the **User access URL** and you have to paste it in **Configure SKYSITE SSO section**, which is explained later in the tutorial.
7572

7673
1. On the **SKYSITE** application integration page, navigate to **single sign-on**.
7774
1. On the **Select a single sign-on method** page, select **SAML**.
78-
1. On the **Set up single sign-on with SAML** page, click the edit/pen icon for **Basic SAML Configuration** to edit the settings.
75+
1. On the **Set up single sign-on with SAML** page, click the pencil icon for **Basic SAML Configuration** to edit the settings.
7976

8077
![Edit Basic SAML Configuration](common/edit-urls.png)
8178

@@ -89,9 +86,9 @@ Follow these steps to enable Azure AD SSO in the Azure portal.
8986

9087
a. Click the **pen** next to **Groups returned in claim**.
9188

92-
![Screenshot shows User claims with the option to Add new claim.](./media/skysite-tutorial/config01.png)
89+
![Screenshot shows User claims with the option to Add new claim.](./media/skysite-tutorial/claims.png)
9390

94-
![Screenshot shows the Manage user claims dialog box where you can enter the values described.](./media/skysite-tutorial/config02.png)
91+
![Screenshot shows the Manage user claims dialog box where you can enter the values described.](./media/skysite-tutorial/groups.png)
9592

9693
b. Select **All Groups** from the radio list.
9794

@@ -126,28 +123,22 @@ In this section, you'll enable B.Simon to use Azure single sign-on by granting a
126123
1. In the Azure portal, select **Enterprise Applications**, and then select **All applications**.
127124
1. In the applications list, select **SKYSITE**.
128125
1. In the app's overview page, find the **Manage** section and select **Users and groups**.
129-
130-
![The "Users and groups" link](common/users-groups-blade.png)
131-
132126
1. Select **Add user**, then select **Users and groups** in the **Add Assignment** dialog.
133-
134-
![The Add User link](common/add-assign-user.png)
135-
136127
1. In the **Users and groups** dialog, select **B.Simon** from the Users list, then click the **Select** button at the bottom of the screen.
137128
1. If you're expecting any role value in the SAML assertion, in the **Select Role** dialog, select the appropriate role for the user from the list and then click the **Select** button at the bottom of the screen.
138129
1. In the **Add Assignment** dialog, click the **Assign** button.
139130

140-
### Configure SKYSITE SSO
131+
## Configure SKYSITE SSO
141132

142133
1. Open a new web browser window and sign into your SKYSITE company site as an administrator and perform the following steps:
143134

144-
4. Click on **Settings** on the top right side of page and then navigate to **Account setting**.
135+
1. Click on **Settings** on the top right side of page and then navigate to **Account setting**.
145136

146-
![Screenshot shows Account setting selected from Settings.](./media/skysite-tutorial/config03.png)
137+
![Screenshot shows Account setting selected from Settings.](./media/skysite-tutorial/settings.png)
147138

148-
5. Switch to **Single sign on (SSO)** tab, perform the following steps:
139+
1. Switch to **Single sign on (SSO)** tab, perform the following steps:
149140

150-
![Screenshot shows the Single sign on tab where you can enter the values described.](./media/skysite-tutorial/config04.png)
141+
![Screenshot shows the Single sign on tab where you can enter the values described.](./media/skysite-tutorial/certificate.png)
151142

152143
a. In the **Identity Provider sign in URL** text box, paste the value of **User access URL**, which you have copied from the **properties** tab in Azure portal.
153144

@@ -161,16 +152,12 @@ In this section, a user called Britta Simon is created in SKYSITE. SKYSITE suppo
161152

162153
## Test SSO
163154

164-
In this section, you test your Azure AD single sign-on configuration using the Access Panel.
165-
166-
When you click the SKYSITE tile in the Access Panel, you should be automatically signed in to the SKYSITE for which you set up SSO. For more information about the Access Panel, see [Introduction to the Access Panel](https://support.microsoft.com/account-billing/sign-in-and-start-apps-from-the-my-apps-portal-2f3b1bae-0e5a-4a86-a33e-876fbd2a4510).
167-
168-
## Additional resources
155+
In this section, you test your Azure AD single sign-on configuration with following options.
169156

170-
- [ List of Tutorials on How to Integrate SaaS Apps with Azure Active Directory ](./tutorial-list.md)
157+
* Click on Test this application in Azure portal and you should be automatically signed in to the SKYSITE for which you set up the SSO.
171158

172-
- [What is application access and single sign-on with Azure Active Directory? ](../manage-apps/what-is-single-sign-on.md)
159+
* You can use Microsoft My Apps. When you click the SKYSITE tile in the My Apps, you should be automatically signed in to the SKYSITE for which you set up the SSO. For more information about the My Apps, see [Introduction to the My Apps](../user-help/my-apps-portal-end-user-access.md).
173160

174-
- [What is conditional access in Azure Active Directory?](../conditional-access/overview.md)
161+
## Next steps
175162

176-
- [Try SKYSITE with Azure AD](https://aad.portal.azure.com/)
163+
Once you configure SKYSITE you can enforce session control, which protects exfiltration and infiltration of your organization’s sensitive data in real time. Session control extends from Conditional Access. [Learn how to enforce session control with Microsoft Cloud App Security](/cloud-app-security/proxy-deployment-aad).

0 commit comments

Comments
 (0)