360 Online authentication

Similar documents
ADFS for. LogMeIn and join.me authentication

Egnyte Single Sign-On (SSO) Configuration for Active Directory Federation Services (ADFS)

LAB 1: Installing Active Directory Federation Services

ADFS Integration Guidelines

Cloud Services ADM. Agent Deployment Guide

Defender Token Deployment System Quick Start Guide

Tool Tip. SyAM Management Utilities and Non-Admin Domain Users

Active Directory Management. Agent Deployment Guide

Configure Microsoft Dynamics AX Connector for Mobile Applications

SalesForce SSO with Active Directory Federated Services (ADFS) v2.0 Authenticating Users Using SecurAccess Server by SecurEnvoy

Configuration Task 3: (Optional) As part of configuration, you can deploy rules. For more information, see "Deploy Inbox Rules" below.

Step-by-Step guide for SSO from MS Sharepoint 2010 to SAP EP 7.0x

CA Nimsoft Service Desk

Configuring Active Directory with AD FS and SAML for Brainloop Secure Dataroom Setup Guide

Mozilla Thunderbird: Setup & Configuration Learning Guide

IIS, FTP Server and Windows

Livezilla How to Install on Shared Hosting By: Jon Manning

NSi Mobile Installation Guide. Version 6.2

Configuring ADFS 3.0 to Communicate with WhosOnLocation SAML

NetWrix File Server Change Reporter. Quick Start Guide

Outlook Profile Setup Guide Exchange 2010 Quick Start and Detailed Instructions

Centrify Cloud Connector Deployment Guide

Active Directory Management. Agent Deployment Guide

Only LDAP-synchronized users can access SAML SSO-enabled web applications. Local end users and applications users cannot access them.

BusinessObjects Enterprise XI Release 2

Test Lab Guide: Creating a Windows Azure AD and Windows Server AD Environment using Azure AD Sync

New Participant Digital Certificate Enrollment Procedure

Configuring Single Sign-On from the VMware Identity Manager Service to Office 365

Security Assertion Markup Language (SAML) Site Manager Setup

VMware Identity Manager Integration with Active Directory Federation Services 2.0

Acunetix Web Vulnerability Scanner. Getting Started. By Acunetix Ltd.

How to set up Outlook Anywhere on your home system

EQUELLA. Blackboard Learn Configuration Guide. Version 6.2

Quick Start Guide: Utilizing Nessus to Secure Microsoft Azure

How To Enable A Websphere To Communicate With Ssl On An Ipad From Aaya One X Portal On A Pc Or Macbook Or Ipad (For Acedo) On A Network With A Password Protected (

VERALAB LDAP Configuration Guide

LAB 2: Identity Management

Lync Online Deployment Guide. Version 1.0

How to Log in to LDRPS-Web v10 (L10)

How To Create An Easybelle History Database On A Microsoft Powerbook (Windows)

CloudBerry Dedup Server

Instructions for Configuring a SAS Metadata Server for Use with JMP Clinical

PCVITA Express Migrator for SharePoint(Exchange Public Folder) Table of Contents

OfficeSuite CRM Connector Quick Start-Up Guide Version 1.0 May 2013

Windows Azure Pack Installation and Initial Configuration

CONFIGURATION GUIDE WITH MICROSOFT ACTIVE DIRECTORY FEDERATION SERVER

Special thanks to the following people for reviewing and providing invaluable feedback for this document: Joe Davies, Bill Mathers, Andreas Kjellman

MadCap Software. Upgrading Guide. Pulse

Preparing to Install SQL Server 2005

Configuring EPM System for SAML2-based Federation Services SSO

Setting up Hyper-V for 2X VirtualDesktopServer Manual

OneLogin Integration User Guide

Using and Contributing Virtual Machines to VM Depot

AvePoint Meetings for SharePoint On-Premises. Installation and Configuration Guide

Set up My Sites (SharePoint Server

Filtering with Microsoft Outlook

FAQs. OneDrive for Business?

Microsoft Dynamics GP SQL Server Reporting Services Guide

Device Enrollment Guide

MultiSite Manager. User Guide

Cloud-Accelerated Hybrid Scenarios with SharePoint and Office 365

RoomWizard Synchronization Software Manual Installation Instructions

Configuring Network Load Balancing with Cerberus FTP Server

Web VTS Installation Guide. Copyright SiiTech Inc. All rights reserved.

DESLock+ Basic Setup Guide Version 1.20, rev: June 9th 2014

SECURE MOBILE ACCESS MODULE USER GUIDE EFT 2013

Application Note. ShoreTel 9: Active Directory Integration. Integration checklist. AN June 2009

Hybrid for SharePoint Server Search Reference Architecture

Accessing the Online Meeting Room (Blackboard Collaborate)

Setup guide. TELUS AD Sync

Lab 1: Windows Azure Virtual Machines

Table of Contents Introduction... 2 Azure ADSync Requirements/Prerequisites:... 2 Software Requirements... 2 Hardware Requirements...

Office365Mon Developer API

T his feature is add-on service available to Enterprise accounts.

HIRSCH Velocity Web Console Guide

IT Exam Training online / Bootcamp

Software Installation Requirements

Using Microsoft Expression Web to Upload Your Site

Implementing a SAS Metadata Server Configuration for Use with SAS Enterprise Guide

HOTPin Integration Guide: Salesforce SSO with Active Directory Federated Services

Password Manager Windows Desktop Client

FAQs. OneDrive for Business?

TSM for Windows Installation Instructions: Download the latest TSM Client Using the following link:

MultiSite Manager. Setup Guide

SHAREPOINT 2013 IN INFRASTRUCTURE AS A SERVICE

STATISTICA VERSION 10 STATISTICA ENTERPRISE SERVER INSTALLATION INSTRUCTIONS

Using the owncloud Android App

Pocket ESA Network Server Installation

Installing Windows Server Update Services (WSUS) on Windows Server 2012 R2 Essentials

1. Open the preferences screen by opening the Mail menu and selecting Preferences...

Provide instructions for installing the VMware View Client a non-wellmont device. These instructions are for a Windows based OS.

MICROSOFT OFFICE 365 EXCHANGE ONLINE CLOUD

Desktop Deployment Guide ARGUS Enterprise /29/2015 ARGUS Software An Altus Group Company

Snow Active Directory Discovery

NovaBACKUP xsp Version 15.0 Upgrade Guide

QUANTIFY INSTALLATION GUIDE

How to install and use the File Sharing Outlook Plugin

Microsoft Exam MB2-702 Microsoft Dynamics CRM 2013 Deployment Version: 6.1 [ Total Questions: 90 ]

Configuring Outlook 2013 For IMAP Connections

Transcription:

360 Online authentication Version October 2015 This document will help you set up a trust for authentication of 360 Online users between Azure Access Control Service and either Office 365 or Active Directory Federation Services. Software Innovation www.software-innovation.com

Contents 1 Introduction... 2 2 Authentication using Office 365... 2 2.1 Introduction... 2 2.2 Prerequisites... 2 2.3 Step by step... 3 3 Authentication using on-premise Active Directory Federation Services... 6 3.1 Introduction... 6 3.2 Prerequisites... 6 3.3 Integration setup step by step... 7 4 Finding the WS-Federation URL... 14 1 Introduction Users for 360 Online are authenticated by Azure Access Control Service (ACS), which supports several authentication sources, including: Office 365 on-premise Active Directory Federation Services. This document explains how to configure ACS to work with these two authentication methods. 2 Authentication using Office 365 2.1 Introduction The following steps are required to enable authentication of 360 Online user with Office 365: a. Create a Windows Azure account b. Configure 360 Online as a new application in your organisation s Azure Active Directory 2.2 Prerequisites The administrator account for your organisation s Office 365 subscription. A valid credit card for the registration of the Windows Azure account. The Azure Active Directory is a free service but registration requires a valid credit card for payment method. https://azure.microsoft.com/en-us/pricing/details/active-directory/ Software Innovation 2014 Page 2 of 14

2.3 Step by step STEP 1: Verify that you have the administrator account Open https://portal.office.com in your browser and log in. If you can see Office 365 admin center, you have the correct account information. STEP 2: Register for a Windows Azure account 1. Open https://account.windowsazure.com/signup in your browser. 2. Sign in with your Office 365 administrator account. 3. Complete the registration form, enter verification code and enter your organization s credit card information. 4. Select the Pay-As-You-Go offer and complete the registration. Once the page displays your current subscription, you can continue to the next step. STEP 3: Add an application to Azure Active Directory 1. Open https://manage.windowsazure.com in your browser and log in with your Office 365 administrator account. The credentials for both your Office 365 subscription and your Azure Account are the same. 2. Scroll down and select ACTIVE DIRECTORY in the left hand menu. Software Innovation 2014 Page 3 of 14

3. Select APPLICATIONS in the top menu. 4. Click ADD on the bottom menu and click Add an application my organization is developing in the next window. 5. Enter the name of your application - Business 360 Online or Public 360 Online and click the right arrow to continue. 6. To establish a trust between your Office 365 authentication and Software Innovation s authentication, enter the following URL in both fields and click the check button: https://360online-ne.accesscontrol.windows.net/ You have now successfully added the application. Software Innovation 2014 Page 4 of 14

STEP 4: Retrieve Federation Metadata Document URL 1. Click ENABLE USERS TO SIGN ON. 2. Copy the FEDERATION METADATA DOCUMENT URL and send it to Software Innovation s Customer Success Team 360online@software-innovation.com. The setup is now complete. Software Innovation 2014 Page 5 of 14

3 Authentication using on-premise Active Directory Federation Services 3.1 Introduction The following steps are required to enable authentication of 360 Online users via on-premise Active Directory: a) On-Premise deployment of Active Directory Federation Services (ADFS) to enable Active Directory federation b) Configure on-premise ADFS with Azure Access Control Service (ACS) as a trusted relying party This document describes (b). (a) is a prerequisite, as described below. If you need help with this setup, contact Software Innovation. Our authentication specialists will be happy to advise you. 3.2 Prerequisites The following are prerequisites for enabling ADFS ACS integration: ADFS server (ADFS 2.0 or higher/windows Server 2008 R2 or higher) has been setup onpremise. These documents provide relevant information: TechNet - ADFS Deployment Guide TechNet - Best Practices for Secure Planning and Deployment of AD FS ADFS Federation metadata URL of the following format should be publically accessible https://adfs.contoso.com/federationmetadata/2007-06/federationmetadata.xml Tenant specific Azure ACS namespace has been configured and the Azure ACS Federation metadata URL is publicly accessible. https://360online-ne.accesscontrol.windows.net/federationmetadata/2007-06/federationmetadata.xml Software Innovation 2014 Page 6 of 14

3.3 Integration setup step by step The following steps setup trust between ADFS and ACS: STEP 1: Navigate to ADFS management screen and click on Add Relying Party Trust STEP 2: Click on Start to initiate addition of relying party Software Innovation 2014 Page 7 of 14

STEP 3: In the Select Data Source step add the following metadata URL address https://360onlinene.accesscontrol.windows.net/federationmetadata/2007-06/federationmetadata.xml Click Next to continue. STEP 4: Leave the default Display name as it is and click on Next to continue to next step. Software Innovation 2014 Page 8 of 14

STEP 5: Permit all users to access this relying party is the default selection. Click on Next to continue with next step. STEP 6: Review the Federation metadata URL and click Next without making any changes. Software Innovation 2014 Page 9 of 14

STEP 7: Click on Close to launch Edit Claims Rules dialog. STEP 8: In the Edit Claim Rules dialog click on Add Rule to add claims rules. Software Innovation 2014 Page 10 of 14

STEP 9: Select Send LDAP Attributes as Claims and click Next. STEP 10: Add E-Mail-Addresses as displayed in the dialog below. Click Finish to continue Software Innovation 2014 Page 11 of 14

STEP 11: Click on Add Rule again to add Windows Account Name to the set of claims. Select Pass Through or Filter an Incoming Claim. Click Next to continue. STEP 12: Add Windows Account Name as mentioned in the dialog below. Click Finish to end the wizard. Software Innovation 2014 Page 12 of 14

STEP 13: Click on Add Rule again to add UPN to the set of claims. Select Pass Through or Filter an Incoming Claim. Click Next to continue. STEP 14: Add UPN as mentioned in the dialog below. Click Finish to end the wizard. Software Innovation 2014 Page 13 of 14

STEP 15: Click OK to close the Edit Claim Rules dialog and end the configuration setup. 4 Finding the WS-Federation URL The URL for the FederationMetadata.xml is standardized for all ADFS installations. Assuming your ADFS instance is hosted at https://adfs.contoso.com, the WS-Federation URL with the FederationMetadata.xml is located at https://adfs.contoso.com/federationmetadata/2007-06/federationmetadata.xml. Return the WS-Federation URL to Software Innovation s Customer Success Team: 360online@software-innovation.com. Software Innovation 2014 Page 14 of 14