Lab 12A Cnfiguring Single Sign On Service Intrductin In this lab exercise we will see hw t cnfigure the Single Sign On Service and cnfigure Individual and Grup Enterprise Applicatin Definitins. The lab steps are presented in: Task Gal General Task Steps Detailed Task Steps This sectin details the verall task t be achieved. The task will be brken dwn int general and detailed steps. These general steps tell yu what requires ding t achieve the task gal. Yu can perfrm the required steps withut fllwing the detailed steps if yu wish. These are the detailed step by step guide required t achieve the task gal. Time t cmplete this lab: 20 minutes. Scenari Yu are the SharePint administratr fr yur rganisatin and yu are required t cnfigure the Single Sign On Service s that yur rganisatin s applicatin develpers can create web parts that access infrmatin frm bth yur rganisatins custm help desk enquiry system and SAP database. A separate team f administratrs will be set up t manage the applicatin definitins and user infrmatin in the future, but fr nw, yu will be required t cnfigure the initial applicatin definitins. Other administratrs may be required t cnfigure the Single Sign On service in the future. Users n the Help Desk applicatin use a generic accunt t read infrmatin and are required t specify a username, passwrd and database name. Users f SAP have their wn lgns and are required t specify username, passwrd, statin ID and SAP database ID. Passwrds and Statin ID s must be kept secure at all times. Task 1 Create Users Task Gal General Task Steps Create user and grup accunts fr the Single Sign On Service t use as well as a Grup fr the future Applicatin Definitin Administratrs. Create the fllwing accunts will be used: User accunt fr the Micrsft Single Sign On Service t use as a lgn. Grup accunt fr administratrs f the Single Sign On Service. Grup accunt fr administratrs f Applicatin Definitins. The fllwing grup membership is required: The Micrsft Single Sign On Service user accunt must be a member f the Single Sign On Service Administratrs grup. The Dmain Administratr accunt must be a member f the Single Sign On Service Administratrs grup.
Detailed Task Steps T create the required users and grup accunts: Open Active Directry Users and Cmputers frm the Administrative Tls prgram grup n the Start Menu. Expand the Dmain Trainsbydave.cm and Select the Users cntainer in the left hand pane. Click the New User icn n the tlbar. Create a new user accunt with the fllwing infrmatin: First Name: SSO Last Name: Service Lgn Name: SSOService Passwrd: P@ssw0rd Unselect the User Must Change Passwrd at Next Lgn check bx. Select the Passwrd Never Expires check bx. Click Next. Click Finish. Click the New Grup icn frm the tlbar. Enter G_SSOAdmins as the grup name. Ensure that the grup scpe is set t Glbal and that the grup type is set t Security. Click Next. Click Finish. Click the New Grup icn frm the tlbar again. Enter G_SSODEFAdmins as the grup name. Ensure that the grup scpe is set t Glbal and that the grup type is set t Security. Click Next. Click Finish. Duble click n the G_SSOAdmins grup in the right hand pane. Select the Members tab. Click Add. Type SSOService int the Enter the Object Name T Select bx and click Check Names. Type Administratr int the Enter the Object Name T Select bx and click Check Names. Ensure that the SSOService accunt and the Administratr accunt are listed in the Members bx. If nt, repeat the previus steps t add any missing user accunts. Clse Active Directry Users and Cmputers. Lgff and back n as Administratr. Why did yu need t lgff and back n?
Task 2 Cnfigure Required Access Task Gal General Task Steps Cnfigure the access required by the Micrsft Single Sign On Service accunt n the SQL and SharePint Servers. The Micrsft Single Sign On Service Accunt has the fllwing access requirements: Member f the STS_WPG grup n all SharePint Servers. Member f the SPS_WPG grup n all SharePint servers. Server Administratr rle n the SQL server. Public access t the SharePint Cnfiguratin Database. Detailed Task Steps Open Active Directry Users and Cmputers frm the Administrative Tls prgram grup n the Start Menu. Expand the Dmain Trainsbydave.cm and Select the Users cntainer in the left hand pane. Duble click n the STS_WPG grup in the right hand pane. Select the Members tab. Click Add. Type SSOService int the Enter the Object Name T Select bx and click Check Names. Ensure that the SSOService accunt is listed in the Members bx. If nt, repeat the previus steps t add the missing user accunt. Duble click n the SPS_WPG grup in the right hand pane. Select the Members tab. Click Add. Type SSOService int the Enter the Object Name T Select bx and click Check Names. Ensure that the SSOService accunt is listed in the Members bx. If nt, repeat the previus steps t add the missing user accunt. This is an example cnfiguratin fr a single SharePint server running n a Dmain Cntrller. What wuld be different fr a server farm r a single SharePint server that wasn t a Dmain Cntrller? Open Enterprise Manager frm the Micrsft SQL Server prgram grup n the start menu. In the left hand pane, expand Micrsft SQL Servers. Expand SQL Server Grup. Expand (Lcal)(Windws NT). Select Security. Right click n Lgins in the right hand pane and select New Lgin frm the cntext menu. Enter trainsbydave\ssservice int the name field.
Select the Server Rles tab. Select the check bx next t Server Administratrs. Select the Database Access tab. Select the permit check bx next t the cnfiguratin database SPS01_Cnfig_db. Ensure that Public is selected in the Permit in Database Rle sectin. Clse SQL Server Enterprise Manager. Task 3 Cnfigure and Start the Service Task Gal Cnfigure and start the Micrsft Single Sign-n Service General Task Steps Cnfigure the Micrsft Single Sign-n Service t start autmatically and t use the Micrsft Single Sign On accunt. Start the service n the Jb and Web Frnt End Servers. Detailed Task Steps Open Services frm the Administrative Tls prgram Grup n the start menu. Duble click the Micrsft Single Sign-n Service. Under Startup Type: select Autmatic frm the drp dwn list. Select the Lg On tab. Select the This Accunt radi buttn. Enter trainsbydave\ssservice in the username field. Enter P@ssw0rd in bth f the passwrd fields. A Message appears stating that the accunt will be granted t lgn as a service right. Click OK Right click n the Micrsft Single Sign-n Service and select Start frm the cntext menu. Ensure the Micrsft Single Sign-n Service has started and clse the services cnsle. What additinal servers wuld yu need t start the service n in a server farm? In what rder shuld yu start the service n these servers?
Task 4 Setup the Single Sign On Service Task Gal Cnfigure the Single Sign On Service by using the SharePint Prtal Server Single Sign-On Administratin page. General Task Steps Use the SharePint Prtal Server Single Sign-On Administratin page t cnfigure the service and applicatin definitin administratin accunts. Create a Grup Applicatin Definitin fr the Help Desk applicatin Create an Individual Applicatin Definitin fr the SAP database. Detailed Task Steps Open the SharePint Prtal Server Single Sign-On Administratin page frm the SharePint Prtal Server prgram grup n the start menu. Hw else culd yu get t this page? Click the Manage Server Settings link. In the Single Sign-On Settings sectin - Accunt Name field, enter TRAINSBYDAVE\G_SSOAdmins. In the Enterprise Applicatin Definitin Settings sectin - Accunt Name field, enter TRAINSBYDAVE\G_SSODEFAdmins. In the Database Settings sectin, ensure that the Server Name field shws STUDENT1 and that the Database Name field shws SSO. Click the Manage settings fr enterprise applicatin definitins link. On the Manage Enterprise Applicatin Definitins page, click New Item. Under Display Name enter Help Desk Applicatin. Under Applicatin Name enter HelpDesk. Under Cntact Email Address enter administratr@trainsbydave.cm. Under Accunt Type, ensure that Grup is selected. In Field 1 Display Name enter User Name. In Field 2 Display Name enter Passwrd. Set the Mask ptin t Yes under Field 2. In Field 3 Display Name enter Database Name. On the Manage Enterprise Applicatin Definitins page, click New Item. Under Display Name enter SAP Database. Under Applicatin Name enter SAP. Under Cntact Email Address enter administratr@trainsbydave.cm. Under Accunt Type, ensure that Individual is selected. In Field 1 Display Name enter User Name. In Field 2 Display Name enter Passwrd. Set the Mask ptin t Yes under Field 2. In Field 3 Display Name enter Statin ID. Set the Mask ptin t Yes under Field 3. In Field 4 Display Name enter SAP Database ID.
Click the Manage Single Sign-n link at the tp f the page. Click the Manage accunt infrmatin fr enterprise applicatin definitins link. In the drp dwn list f applicatin definitins, ensure that Help Desk is selected. In the Grup accunt name field, enter TRAINSBYDAVE\Dmain Users. On the Prvide Help Desk Accunt Infrmatin page, enter infrmatin int the User Name, Passwrd and Database Name fields. Nte that the passwrd field as masked. Select SAP frm the drp dwn list f applicatin definitins. In the Grup accunt name field, enter TRAINSBYDAVE\Administratr. On the Prvide SAP Accunt Infrmatin page, enter infrmatin int the User Name, Passwrd, Statin ID and SAP Database ID fields. Ntice that the Passwrd and Statin ID fields are masked. Clse the Internet Explrer Windw.