You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
# Tutorial: Azure Active Directory integration with ServiceChannel
23
22
24
-
In this tutorial, you learn how to integrate ServiceChannel with Azure Active Directory (Azure AD).
25
-
Integrating ServiceChannel with Azure AD provides you with the following benefits:
23
+
# Tutorial: Integrate ServiceChannel with Azure Active Directory
26
24
27
-
* You can control in Azure AD who has access to ServiceChannel.
28
-
* You can enable your users to be automatically signed-in to ServiceChannel (Single Sign-On) with their Azure AD accounts.
29
-
* You can manage your accounts in one central location - the Azure portal.
25
+
In this tutorial, you'll learn how to integrate ServiceChannel with Azure Active Directory (Azure AD). When you integrate ServiceChannel with Azure AD, you can:
30
26
31
-
If you want to know more details about SaaS app integration with Azure AD, see [What is application access and single sign-on with Azure Active Directory](https://docs.microsoft.com/azure/active-directory/active-directory-appssoaccess-whatis).
32
-
If you don't have an Azure subscription, [create a free account](https://azure.microsoft.com/free/) before you begin.
27
+
* Control in Azure AD who has access to ServiceChannel.
28
+
* Enable your users to be automatically signed-in to ServiceChannel with their Azure AD accounts.
29
+
* Manage your accounts in one central location - the Azure portal.
30
+
31
+
To learn more about SaaS app integration with Azure AD, see [What is application access and single sign-on with Azure Active Directory](https://docs.microsoft.com/azure/active-directory/active-directory-appssoaccess-whatis).
33
32
34
33
## Prerequisites
35
34
36
-
To configure Azure AD integration with ServiceChannel, you need the following items:
35
+
To get started, you need the following items:
37
36
38
-
* An Azure AD subscription. If you don't have an Azure AD environment, you can get a [free account](https://azure.microsoft.com/free/)
39
-
* ServiceChannel single sign-on enabled subscription
37
+
* An Azure AD subscription. If you don't have a subscription, you can get a [free account](https://azure.microsoft.com/free/).
38
+
* ServiceChannel single sign-on (SSO) enabled subscription.
40
39
41
40
## Scenario description
42
41
43
-
In this tutorial, you configure and test Azure AD single sign-on in a test environment.
42
+
In this tutorial, you configure and test Azure AD SSO in a test environment.
44
43
45
44
* ServiceChannel supports **IDP** initiated SSO
46
45
* ServiceChannel supports **Just In Time** user provisioning
@@ -49,61 +48,40 @@ In this tutorial, you configure and test Azure AD single sign-on in a test envir
49
48
50
49
To configure the integration of ServiceChannel into Azure AD, you need to add ServiceChannel from the gallery to your list of managed SaaS apps.
51
50
52
-
**To add ServiceChannel from the gallery, perform the following steps:**
53
-
54
-
1. In the **[Azure portal](https://portal.azure.com)**, on the left navigation panel, click **Azure Active Directory** icon.
55
-
56
-

57
-
58
-
2. Navigate to **Enterprise Applications** and then select the **All Applications** option.
3. To add new application, click **New application** button on the top of dialog.
63
-
64
-

65
-
66
-
4. In the search box, type **ServiceChannel**, select **ServiceChannel** from result panel then click **Add** button to add the application.
51
+
1. Sign in to the [Azure portal](https://portal.azure.com) using either a work or school account, or a personal Microsoft account.
52
+
1. On the left navigation pane, select the **Azure Active Directory** service.
53
+
1. Navigate to **Enterprise Applications** and then select **All Applications**.
54
+
1. To add new application, select **New application**.
55
+
1. In the **Add from the gallery** section, type **ServiceChannel** in the search box.
56
+
1. Select **ServiceChannel** from results panel and then add the app. Wait a few seconds while the app is added to your tenant.
67
57
68
-

69
58
70
-
## Configure and test Azure AD single sign-on
59
+
## Configure and test Azure AD single sign-on for ServiceChannel
71
60
72
-
In this section, you configure and test Azure AD single sign-on with ServiceChannel based on a test user called **Britta Simon**.
73
-
For single sign-on to work, a link relationship between an Azure AD user and the related user in ServiceChannel needs to be established.
61
+
Configure and test Azure AD SSO with ServiceChannel using a test user called **B.Simon**. For SSO to work, you need to establish a link relationship between an Azure AD user and the related user in ServiceChannel.
74
62
75
-
To configure and test Azure AD single sign-on with ServiceChannel, you need to complete the following building blocks:
63
+
To configure and test Azure AD SSO with ServiceChannel, complete the following building blocks:
76
64
77
-
1.**[Configure Azure AD Single Sign-On](#configure-azure-ad-single-sign-on)** - to enable your users to use this feature.
78
-
2.**[Configure ServiceChannel Single Sign-On](#configure-servicechannel-single-sign-on)** - to configure the Single Sign-On settings on application side.
79
-
3.**[Create an Azure AD test user](#create-an-azure-ad-test-user)** - to test Azure AD single sign-on with Britta Simon.
80
-
4.**[Assign the Azure AD test user](#assign-the-azure-ad-test-user)** - to enable Britta Simon to use Azure AD single sign-on.
81
-
5.**[Create ServiceChannel test user](#create-servicechannel-test-user)** - to have a counterpart of Britta Simon in ServiceChannel that is linked to the Azure AD representation of user.
82
-
6.**[Test single sign-on](#test-single-sign-on)** - to verify whether the configuration works.
65
+
1.**[Configure Azure AD SSO](#configure-azure-ad-sso)** - to enable your users to use this feature.
66
+
1. **[Create an Azure AD test user](#create-an-azure-ad-test-user)** - to test Azure AD single sign-on with B.Simon.
67
+
1. **[Assign the Azure AD test user](#assign-the-azure-ad-test-user)** - to enable B.Simon to use Azure AD single sign-on.
68
+
2.**[Configure ServiceChannel SSO](#configure-servicechannel-sso)** - to configure the Single Sign-On settings on application side.
69
+
1. **[Create ServiceChannel test user](#create-servicechannel-test-user)** - to have a counterpart of B.Simon in ServiceChannel that is linked to the Azure AD representation of user.
70
+
3.**[Test SSO](#test-sso)** - to verify whether the configuration works.
83
71
84
-
###Configure Azure AD single sign-on
72
+
## Configure Azure AD SSO
85
73
86
-
In this section, you enable Azure AD single sign-on in the Azure portal.
74
+
Follow these steps to enable Azure AD SSO in the Azure portal.
87
75
88
-
To configure Azure AD single sign-on with ServiceChannel, perform the following steps:
76
+
1. In the [Azure portal](https://portal.azure.com/), on the **ServiceChannel** application integration page, find the **Manage** section and select **Single sign-on**.
77
+
1. On the **Select a Single sign-on method** page, select **SAML**.
78
+
1. On the **Set up Single Sign-On with SAML** page, click the edit/pen icon for **Basic SAML Configuration** to edit the settings.
89
79
90
-
1. In the [Azure portal](https://portal.azure.com/), on the **ServiceChannel** application integration page, select **Single sign-on**.
4. On the **Set up Single Sign-On with SAML** page, perform the following steps:
103
-
104
-

105
-
106
-
a. In the **Identifier** text box, type the value as:
84
+
a. In the **Identifier** text box, type the value as:
107
85
`http://adfs.<domain>.com/adfs/service/trust`
108
86
109
87
b. In the **Reply URL** text box, type a URL using the following pattern:
@@ -114,12 +92,12 @@ To configure Azure AD single sign-on with ServiceChannel, perform the following
114
92
115
93
5. Your ServiceChannel application expects the SAML assertions in a specific format, which requires you to add custom attribute mappings to your SAML token attributes configuration. The following screenshot shows the list of default attributes, where as **nameidentifier** is mapped with **user.userprincipalname**. ServiceChannel application expects **nameidentifier** to be mapped with **user.mail**, so you need to edit the attribute mapping by clicking on **Edit** icon and change the attribute mapping.
116
94
117
-
You can refer ServiceChannel guide [here](https://servicechannel.zendesk.com/hc/en-us/articles/217514326-Azure-AD-Configuration-Example) for more guidance on claims.
95
+
You can refer ServiceChannel guide [here](https://servicechannel.zendesk.com/hc/articles/217514326-Azure-AD-Configuration-Example) for more guidance on claims.
118
96
119
97

120
98
121
99
> [!NOTE]
122
-
> See [Manage access using RBAC and the Azure portal](../../role-based-access-control/role-assignments-portal.md) to learn how to configure **Role** in Azure AD.
100
+
> Refer this [link](https://docs.microsoft.com/azure/active-directory/develop/active-directory-enterprise-app-role-management) to learn how to configure **Role** in Azure AD.
123
101
124
102
6. In addition to above, if you are planning to enable Just In Time user provisioning, then you should add the following claims as shown below. **Role** claim needs to be mapped to **user.assignedroles** which contains the role of the user. In the **User Claims** section on the **User Attributes** dialog, perform the following steps to add SAML token attribute as shown in the below table:
125
103
@@ -145,89 +123,63 @@ To configure Azure AD single sign-on with ServiceChannel, perform the following
145
123
146
124
g. Click **Save**.
147
125
148
-
7. On the **Set up Single Sign-On with SAML** page, in the **SAML Signing Certificate** section, click **Download** to download the **Certificate (Base64)**from the given options as per your requirement and save it on your computer.
126
+
4. On the **Set up Single Sign-On with SAML** page, in the **SAML Signing Certificate** section, find **Certificate (Base64)**and select **Download** to download the certificate and save it on your computer.
To configure single sign-on on **ServiceChannel** side, you need to send the downloaded **Certificate (Base64)** and appropriate copied URLs from Azure portal to [ServiceChannel support team](https://servicechannel.zendesk.com/hc/en-us). They set this setting to have the SAML SSO connection set properly on both sides.
165
-
166
134
### Create an Azure AD test user
167
135
168
-
The objective of this section is to create a test user in the Azure portal called Britta Simon.
169
-
170
-
1. In the Azure portal, in the left pane, select **Azure Active Directory**, select **Users**, and then select **All users**.
171
-
172
-

173
-
174
-
2. Select **New user** at the top of the screen.
175
-
176
-

177
-
178
-
3. In the User properties, perform the following steps.
136
+
In this section, you'll create a test user in the Azure portal called B.Simon.
179
137
180
-

1. In the Azure portal, select **Enterprise Applications**, and then select **All applications**.
151
+
1. In the applications list, select **ServiceChannel**.
152
+
1. In the app's overview page, find the **Manage** section and select **Users and groups**.
198
153
199
-
2. In the applications list, select **ServiceChannel**.
154
+

200
155
201
-

156
+
1. Select **Add user**, then select **Users and groups**in the **Add Assignment** dialog.
202
157
203
-
3. In the menu on the left, select **Users and groups**.
158
+

204
159
205
-

160
+
1. In the **Users and groups** dialog, select **B.Simon** from the Users list, then click the **Select** button at the bottom of the screen.
161
+
1. If you're expecting any role value in the SAML assertion, in the **Select Role** dialog, select the appropriate role for the user from the list and then click the **Select** button at the bottom of the screen.
162
+
1. In the **Add Assignment** dialog, click the **Assign** button.
206
163
207
-
4. Click the **Add user** button, then select **Users and groups** in the **Add Assignment** dialog.
5. In the **Users and groups** dialog select **Britta Simon** in the Users list, then click the **Select** button at the bottom of the screen.
212
-
213
-
6. If you are expecting any role value in the SAML assertion then in the **Select Role** dialog select the appropriate role for the user from the list, then click the **Select** button at the bottom of the screen.
214
-
215
-
7. In the **Add Assignment** dialog click the **Assign** button.
166
+
To configure single sign-on on **ServiceChannel** side, you need to send the downloaded **Certificate (Base64)** and appropriate copied URLs from Azure portal to [ServiceChannel support team](https://servicechannel.zendesk.com/hc/). They set this setting to have the SAML SSO connection set properly on both sides.
216
167
217
168
### Create ServiceChannel test user
218
169
219
-
Application supports Just in time user provisioning and after authentication users will be created in the application automatically. For full user provisioning, please contact [ServiceChannel support team](https://servicechannel.zendesk.com/hc/en-us)
170
+
Application supports Just in time user provisioning and after authentication users will be created in the application automatically. For full user provisioning, please contact [ServiceChannel support team](https://servicechannel.zendesk.com/hc/).
220
171
221
-
###Test single sign-on
172
+
## Test SSO
222
173
223
174
In this section, you test your Azure AD single sign-on configuration using the Access Panel.
224
175
225
176
When you click the ServiceChannel tile in the Access Panel, you should be automatically signed in to the ServiceChannel for which you set up SSO. For more information about the Access Panel, see [Introduction to the Access Panel](https://docs.microsoft.com/azure/active-directory/active-directory-saas-access-panel-introduction).
226
177
227
178
## Additional Resources
228
179
229
-
-[List of Tutorials on How to Integrate SaaS Apps with Azure Active Directory](https://docs.microsoft.com/azure/active-directory/active-directory-saas-tutorial-list)
180
+
-[ List of Tutorials on How to Integrate SaaS Apps with Azure Active Directory ](https://docs.microsoft.com/azure/active-directory/active-directory-saas-tutorial-list)
181
+
182
+
-[What is application access and single sign-on with Azure Active Directory? ](https://docs.microsoft.com/azure/active-directory/active-directory-appssoaccess-whatis)
230
183
231
-
-[What is application access and single sign-on with Azure Active Directory?](https://docs.microsoft.com/azure/active-directory/active-directory-appssoaccess-whatis)
184
+
-[What is conditional access in Azure Active Directory?](https://docs.microsoft.com/azure/active-directory/conditional-access/overview)
232
185
233
-
-[What is Conditional Access in Azure Active Directory?](https://docs.microsoft.com/azure/active-directory/conditional-access/overview)
0 commit comments