You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/active-directory/saas-apps/cyberark-saml-authentication-tutorial.md
+16-11Lines changed: 16 additions & 11 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,5 +1,5 @@
1
1
---
2
-
title: 'Tutorial: Azure Active Directory single sign-on (SSO) integration with CyberArk SAML Authentication | Microsoft Docs'
2
+
title: 'Tutorial: Azure AD SSO integration with CyberArk SAML Authentication'
3
3
description: Learn how to configure single sign-on between Azure Active Directory and CyberArk SAML Authentication.
4
4
services: active-directory
5
5
author: jeevansd
@@ -9,11 +9,11 @@ ms.service: active-directory
9
9
ms.subservice: saas-app-tutorial
10
10
ms.workload: identity
11
11
ms.topic: tutorial
12
-
ms.date: 02/09/2021
12
+
ms.date: 05/11/2022
13
13
ms.author: jeedes
14
14
---
15
15
16
-
# Tutorial: Azure Active Directory single sign-on (SSO) integration with CyberArk SAML Authentication
16
+
# Tutorial: Azure AD SSO integration with CyberArk SAML Authentication
17
17
18
18
In this tutorial, you'll learn how to integrate CyberArk SAML Authentication with Azure Active Directory (Azure AD). When you integrate CyberArk SAML Authentication with Azure AD, you can:
19
19
@@ -27,13 +27,18 @@ To get started, you need the following items:
27
27
28
28
* An Azure AD subscription. If you don't have a subscription, you can get a [free account](https://azure.microsoft.com/free/).
29
29
* CyberArk SAML Authentication single sign-on (SSO) enabled subscription.
30
+
* Along with Cloud Application Administrator, Application Administrator can also add or manage applications in Azure AD.
31
+
For more information, see [Azure built-in roles](../roles/permissions-reference.md).
30
32
31
33
## Scenario description
32
34
33
35
In this tutorial, you configure and test Azure AD SSO in a test environment.
34
36
35
37
* CyberArk SAML Authentication supports **SP and IDP** initiated SSO.
36
38
39
+
> [!NOTE]
40
+
> Identifier of this application is a fixed string value so only one instance can be configured in one tenant.
41
+
37
42
## Add CyberArk SAML Authentication from the gallery
38
43
39
44
To configure the integration of CyberArk SAML Authentication into Azure AD, you need to add CyberArk SAML Authentication from the gallery to your list of managed SaaS apps.
@@ -66,9 +71,9 @@ Follow these steps to enable Azure AD SSO in the Azure portal.
66
71
1. On the **Select a single sign-on method** page, select **SAML**.
67
72
1. On the **Set up single sign-on with SAML** page, click the pencil icon for **Basic SAML Configuration** to edit the settings.

70
75
71
-
1. On the **Basic SAML Configuration** section, if you wish to configure the application in **IDP** initiated mode, enter the values for the following fields:
76
+
1. On the **Basic SAML Configuration** section, perform the following step:
72
77
73
78
In the **Reply URL** text box, type a URL using the following pattern:
74
79
`https://<PVWA DNS or IP>/passwordvault/api/auth/saml/logon`
@@ -79,15 +84,15 @@ Follow these steps to enable Azure AD SSO in the Azure portal.
79
84
`https://<PVWA DNS or IP>/PasswordVault/v10/logon/saml`
80
85
81
86
> [!NOTE]
82
-
> These values are not real. Update these values with the actual Reply URL and Sign-On URL. Contact [CyberArk SAML Authentication Client support team](mailto:[email protected]) to get these values. You can also refer to the patterns shown in the **Basic SAML Configuration** section in the Azure portal.
87
+
> These values are not real. Update these values with the actual Reply URL and Sign-On URL. Contact your CyberArk Administration team to get these values. You can also refer to the patterns shown in the **Basic SAML Configuration** section in the Azure portal.
83
88
84
89
1. On the **Set up single sign-on with SAML** page, in the **SAML Signing Certificate** section, find **Certificate (Base64)** and select **Download** to download the certificate and save it on your computer.

91
96
92
97
### Create an Azure AD test user
93
98
@@ -115,11 +120,11 @@ In this section, you'll enable B.Simon to use Azure single sign-on by granting a
115
120
116
121
## Configure CyberArk SAML Authentication SSO
117
122
118
-
To configure single sign-on on **CyberArk SAML Authentication** side, you need to send the downloaded **Certificate (Base64)** and appropriate copied URLs from Azure portal to [CyberArk SAML Authentication support team](mailto:[email protected]). They set this setting to have the SAML SSO connection set properly on both sides.
123
+
To configure single sign-on on **CyberArk SAML Authentication** side, you need to send the downloaded **Certificate (Base64)** and appropriate copied URLs from Azure portal to your CyberArk Administration team. They set this setting to have the SAML SSO connection set properly on both sides.
119
124
120
125
### Create CyberArk SAML Authentication test user
121
126
122
-
In this section, you create a user called B.Simon in CyberArk SAML Authentication. Work with [CyberArk SAML Authentication support team](mailto:[email protected]) to add the users in the CyberArk SAML Authentication platform. Users must be created and activated before you use single sign-on.
127
+
In this section, you create a user called B.Simon in CyberArk SAML Authentication. Work with your CyberArk Administration team to add the users in the CyberArk SAML Authentication platform. Users must be created and activated before you use single sign-on.
123
128
124
129
## Test SSO
125
130
@@ -139,4 +144,4 @@ You can also use Microsoft My Apps to test the application in any mode. When you
139
144
140
145
## Next steps
141
146
142
-
Once you configure CyberArk SAML Authentication you can enforce session control, which protects exfiltration and infiltration of your organization’s sensitive data in real time. Session control extends from Conditional Access. [Learn how to enforce session control with Microsoft Defender for Cloud Apps](/cloud-app-security/proxy-deployment-any-app).
147
+
Once you configure CyberArk SAML Authentication you can enforce session control, which protects exfiltration and infiltration of your organization’s sensitive data in real time. Session control extends from Conditional Access. [Learn how to enforce session control with Microsoft Defender for Cloud Apps](/cloud-app-security/proxy-deployment-any-app).
0 commit comments