SAML based Single Sign-on integration for:



Similar documents
Section 1, Configuring Access Manager, on page 1 Section 2, Configuring Office 365, on page 4 Section 3, Verifying Single Sign-On Access, on page 5

365 Services. 1.1 Configuring Access Manager Prerequisite Adding the Office 365 Metadata. docsys (en) 2 August 2012

webnetwork Office 365 SSO integration v

Configuring Single Sign-On from the VMware Identity Manager Service to Office 365

Dell One Identity Cloud Access Manager How to Configure Microsoft Office 365

PowerShell and Office 365. Presentation created for Simplex-IT Developed by Sarah Dutkiewicz

Egnyte Single Sign-On (SSO) Installation for OneLogin

LAB 2: Identity Management

Office 365 from the ground to the cloud

Lync Online Deployment Guide. Version 1.0

SP-initiated SSO for Smartsheet is automatically enabled when the SAML feature is activated.

AVG Business SSO Partner Getting Started Guide

Connected Data. Connected Data requirements for SSO

An overview of configuring WebEx for single sign-on. To configure the WebEx application for single-sign on from the cloud service (an overview)

User Management Tool 1.5

An overview of configuring WebEx for single sign-on. To configure the WebEx application for single-sign on from the cloud service (an overview)

OneLogin Integration User Guide

Configuring user provisioning for Amazon Web Services (Amazon Specific)

WHITE PAPER BT Sync, the alternative for DirSync during Migrations

Creating a generic user-password application profile

Presented by: Robert Crane BE MBA MVP

Configuring SuccessFactors

Configuring. SugarCRM. Chapter 121

To set up Egnyte so employees can log in using SSO, follow the steps below to configure VMware Horizon and Egnyte to work with each other.

Configuring Salesforce

Exchange 2013 mailbox setup guide

Using Internet or Windows Explorer to Upload Your Site

Office 365 deployment checklists

Egnyte Single Sign-On (SSO) Configuration for Active Directory Federation Services (ADFS)

An overview of configuring Intacct for single sign-on. To configure the Intacct application for single-sign on (an overview)

Lab 05: Deploying Microsoft Office Web Apps Server

This guide identifies two possible enterprise integration scenarios for NetScaler and Azure AD.

Configuring. SuccessFactors. Chapter 67

Cloud Services. Lync. IM/ Web Conferencing Admin Quick Start Guide

Configuring ADFS 3.0 to Communicate with WhosOnLocation SAML

Cloudfinder for Office 365 User Guide. November 2013

For details about using automatic user provisioning with Salesforce, see Configuring user provisioning for Salesforce.

Only LDAP-synchronized users can access SAML SSO-enabled web applications. Local end users and applications users cannot access them.

Security Assertion Markup Language (SAML) Site Manager Setup

Single Sign On (SSO) Implementation Manual. For Connect 5 & MyConnect Sites

Integration of Office 365 with existing faculty SSO

Agenda. Federation using ADFS and Extensibility options. Office 365 Identity overview. Federation and Synchronization

IIS, FTP Server and Windows

Office 365 deploym. ployment checklists. Chapter 27

Configure Single Sign on Between Domino and WPS

Online Statements. About this guide. Important information

Copyright Pivotal Software Inc, of 10

T his feature is add-on service available to Enterprise accounts.

Professional Mailbox Software Setup Guide

Enable Federated Agents in Chime for Lync

Configuring Sponsor Authentication

How to Remotely Access the C&CDHB Network from a Personal Device

Egnyte Single Sign-On (SSO) Installation for Okta

Flexible Identity Federation

Configuring EPM System for SAML2-based Federation Services SSO

Microsoft Office 365 Using SAML Integration Guide

Configuring Single Sign-on from the VMware Identity Manager Service to WebEx

Integrating LANGuardian with Active Directory

Configuring Parature Self-Service Portal

Cash Management 5.0 User Guide

UNIFIED COMMUNICATIONS POST-MIGRATION INSTRUCTIONS

Single Sign On for Office 365 with NetScaler. Deployment Guide

SAP NetWeaver AS Java

Office 365 DirSync, ADFS, Single Sign On and Exchange Federation

Contents 1. Introduction 2. Security Considerations 3. Installation 4. Configuration 5. Uninstallation 6. Automated Bulk Enrollment 7.

Single Sign-on Frequently Asked Questions

Tool Tip. SyAM Management Utilities and Non-Admin Domain Users

Test Lab Guide: Creating a Windows Azure AD and Windows Server AD Environment using Azure AD Sync

Connecting to UNOSECURE using Windows 7

SecureAnywhereTM Web Security Service

Access and Login. Single Sign On Reference. Signoff

SCADA Security. Enabling Integrated Windows Authentication For CitectSCADA Web Client. Applies To: CitectSCADA 6.xx and 7.xx VijeoCitect 6.xx and 7.

Using and Contributing Virtual Machines to VM Depot

ANDROID GUEST GUIDE. Remote Support & Management PC Tablet - Smartphone. 1. An Introduction. Host module on your PC or device

Working with RD Web Access in Windows Server 2012

Special thanks to the following people for reviewing and providing invaluable feedback for this document: Joe Davies, Bill Mathers, Andreas Kjellman

PowerSchool. Parent Single Sign-On (SSO)

SAML single sign-on configuration overview

Magento Extension Point of Sales User Manual Version 1.0

Active Directory Integration for Greentree

Getting Started Guide: Transaction Download for QuickBooks Windows. Information You ll Need to Get Started

Lifesize Cloud Table of Contents

Configuring IBM Cognos Controller 8 to use Single Sign- On

VMware Identity Manager Administration

Google Apps Deployment Guide

BULK SMS APPLICATION USER MANUAL

Mod 2: User Management

ADFS Integration Guidelines

Configuring on-premise Sharepoint server SSO

Cloud Authentication. Getting Started Guide. Version

Broker Portal Tutorial Broker Portal Basics

Hands on Lab: Building a Virtual Machine and Uploading VM Images to the Cloud using Windows Azure Infrastructure Services

Admin Guide Hosting Control Panel Active Directory (AD) Synchronization

Add in Guide for Microsoft Dynamics CRM May 2012

Cloud Services. Sharepoint. Admin Quick Start Guide

SQL EXPRESS INSTALLATION...

Version 3.2 Release Note. V3.2 Release Note

Pcounter CGI Utilities Installation and Configuration For Pcounter for Windows version 2.55 and above

Advanced Configuration Administration Guide

Microsoft Lync TM Order & Provisioning. Admin Guide

Transcription:

SAML based Single Sign-on integration for: WiActs Inc. 2015. All rights are reserved. Use of this document is subject to the terms and conditions of WiActs products. 1

1. On the WiActs Admin Dashboard, from the left hand menu, click on Apps. 2. Click on New Application. 3. Choose one of the Office 365 apps from the drop-down menu and set a App nickname for it, if it s desirable. Then click on the Next button. WiActs Inc. 2015. All rights are reserved 1

4. Download the certificate by clicking on the Certificate hyperlink. 5. Click on PowerShell command template for ADFS to download it. 6. Click on the Next button. 7. Enter your onmicrosoft.com domain in the App Custom URL <your-domain>.onmicrosoft.com WiActs Inc. 2015. All rights are reserved 2

8. Log into the Office 365 administration center as an administrator. https://portal.microsoftonline.com/ 9. Click on Admin Center, on the left hand side panel, and choose Domain 10. Add a domain that you are going to use for single sign on and go through the steps to confirm that you own the domain. 11. DO NOT add any users at this stage. 12. In the section where you are asked How do you want to use <your domain> with Office 365?, Uncheck the checked boxes next to Exchange Online and Lync Online ; unless DNS entries are to be updated. 13. Make sure that the new domain is not the default domain. If the new domain is not selected as the default domain, go to step 18. 14. If the new domain is set to be the default domain, click on your company name on the top right corner WiActs Inc. 2015. All rights are reserved 3

15. Choose <your domain>.onmicrosoft.com as the Default domain WiActs Inc. 2015. All rights are reserved 4

16. SSO configuration for Office 365 requires Windows Azure Active Directory Module for Windows PowerShell cmdlets. Download and install cmdlets from the following link: https://technet.microsoft.com/en-us/library/jj151815.aspx Tip: Office 365 integration for WiActs Trial and Pilot programs require a few line of coding. The integration for the final version, where it integrates with Windows Active Directory, is significantly simpler. 17. To complete SSO configuration, run the Set-MsolDomainAuthentication cmdlet 18. You need to use the PowerShell command template and the certificate that you downloaded (in step 6 and 7) from WiActs Admin Dashboard. 19. To configure office 365 SSO, customize the PowerShell command template based on following steps and then paste them in the PowerShell command box. 20. Prompt for the administrator s credentials $cred=get-credential Connect-MsolService -Credential $cred WiActs Inc. 2015. All rights are reserved 5

WiActs No Password SSO Tip: While you customize the PowerShell command template, where you enter your company domain for SSO, you don t need to enter https://www, Example: wiacts.com $domain = "<your company domain for SSO>" $issuer = "https://id.wiacts.com/" $ssourl = "https://id.wiacts.com/saml/ssoservice.aspx" $ecpurl = "https://id.wiacts.com/saml/ecp.aspx" $logoffurl ="https://id.wiacts.com/logout.aspx" 21. Locate the certificate file you downloaded in step 6 to customize the following part of PowerShell command $certificatefile = <Address of certificate file you just downloaded>" $certificate = [IO.File]::ReadAllText($certificateFile) $certificate = $certificate.replace("-----begin CERTIFICATE-----","") $certificate = $certificate.replace("-----end CERTIFICATE-----","") $certificate = $certificate.replace("`r","") $certificate = $certificate.replace("`n","") WiActs Inc. 2015. All rights are reserved 6

22. the following part of script enables the SSO for your domain Set-MsolDomainAuthentication -FederationBrandName $domain -DomainName $domain - Authentication federated -PreferredAuthenticationProtocol SAMLP -IssuerUri $issuer - SigningCertificate $certificate -PassiveLogOnUri $ssourl -ActiveLogOnUri $ecpurl -LogOffUri $logoffurl Verbose WiActs Inc. 2015. All rights are reserved 7

23. See all licences Get-MsolAccountSku Tip: You need your AccountSku number to be able to add users. 24.Add user New-MsolUser -UserPrincipalName <New user's email at your custom domain> - ImmutableId <New user's ImmutableId which is unique in your domain> -FirstName <New user's first name> -LastName <New user's last name> -DisplayName <New user's display name> -LicenseAssignment <your AccountSku> -usagelocation <Country name i.e US> WiActs Inc. 2015. All rights are reserved 8

Tip: The immutable id is uniquely and permanently identifier for the user. Make sure you enter this Immutable id in WiActs Dashboard as the user s ID. The user principal name is the IDPEmail. Both these values must match with the Office 365 configuration for single sign-on to be successful. Tip: To delete a user that was created by mistake, use the following script: Remove-MsolUser -UserPrincipalName <User's email> Tip: The above command moves the user to the Office 365 recycle bin. To create a user with the same name, the first user must be removed from the recycle bin. Tip: To retrieve a deleted user: Get-MsolUser -ReturnDeletedUsers -SearchString <User's email> select UserPrincipalName, ObjectId Tip: To remove a deleted user from the recycle bin: Remove-MsolUser -RemoveFromRecycleBin ObjectId <objectid value> WiActs Inc. 2015. All rights are reserved 9

25. On the Apps section of WiActs Admin Dashboard, select the Office 365 app that you just added. 26. Click on the Assign users button 27. Assign users and/or groups to the app, then click on the Save Changes button. 28. On the left hand menu, click on Users. Then double-click on the users you added in PowerShell to edit these users. WiActs Inc. 2015. All rights are reserved 10

29. Enter the users ImmutableId in the User ID field and click on the Save Changes button. The process of Office 365 configuration is completed. WiActs Inc. 2015. All rights are reserved 11

This is only required for Trial and Pilot accounts. The final solution integrates with Windows Active Directory. Therefore, the admin does not need to add users separately in WiActs Dashboard. Trouble shooting: The following problem when users are trying to sign into Office 365 is a common problem resulted from Office 365 bug. Sorry, but we're having trouble signing you in. Please try again in a few minutes. If this doesn't work, you might want to contact your admin and report the following error: *********. The solution is simply to close the browser tab you were using, then restart your browser. Then open a fresh browser tap and try to login. Should you have further question, do not hesitate to contact us at support@wiacts.com For further tutorials and video, please visit: https://www.wiacts.com/tutorials WiActs Inc. 2015. All rights are reserved 12