VIEVU Solution AD Sync and ADFS Guide

Similar documents
Microsoft ADFS Configuration

Configuring Microsoft ADFS for Oracle Fusion Expenses Mobile Single Sign-On

ADFS integration with Ibistic Commerce Platform A walkthrough of the feature and basic configuration

Configuring Alfresco Cloud with ADFS 3.0

How to Use ADFS to Implement Single Sign-On for an ASP.NET MVC Application

TECHNICAL GUIDE SSO SAML. At 360Learning, we don t make promises about technical solutions, we make commitments.

NETOP PORTAL ADFS & AZURE AD INTEGRATION

Qualys SAML & Microsoft Active Directory Federation Services Integration

Configuring SAML-based Single Sign-on for Informatica Web Applications

D9.2.2 AD FS via SAML2

Configuration Guide - Single-Sign On for OneDesk

Cloud Access Manager Configuration Guide

Colligo Console. Administrator Guide

Nimsoft Service Desk. Single Sign-On Configuration Guide. [assign the version number for your book]

AD FS CONFIGURATION GUIDE

ADFS Setup (SAML Authentication)

Integrating the YuJa Enterprise Video Platform with ADFS (SAML)

ADFS Authentication and Configuration January 2017

Integrating YuJa Active Learning with ADFS (SAML)

Integrating YuJa Active Learning into ADFS via SAML

Quick Start Guide for SAML SSO Access

Quick Start Guide for SAML SSO Access

Enabling SAML Authentication in an Informatica 10.2.x Domain

Configure Single Sign-On using CUCM and AD FS 2.0 (Windows Server 2008 R2)

Copyright

SAML-Based SSO Configuration

Contents. Introduction To CloudSync. 2. System Requirements...2. Installing CloudSync 2. Getting Started 4

CONFIGURING AD FS AS A THIRD-PARTY IDP IN VMWARE IDENTITY MANAGER: VMWARE WORKSPACE ONE OPERATIONAL TUTORIAL VMware Workspace ONE

VMware Identity Manager Administration

Unified Communications Manager Version 10.5 SAML SSO Configuration Example

Single Sign-On (SSO)Technical Specification

SAML-Based SSO Solution

Integration Guide. SafeNet Authentication Service. NetDocuments

CLI users are not listed on the Cisco Prime Collaboration User Management page.

Integrating the YuJa Enterprise Video Platform with Dell Cloud Access Manager (SAML)

Configuring Claims-based Authentication for Microsoft Dynamics CRM Server. Last updated: May 2015

SAML-Based SSO Solution

Configuring ADFS for Academic Works

Table of Contents. Installing the AD FS Running the PowerShell Script 16. Troubleshooting log in issues 19

SSO Authentication with ADFS SAML 2.0. Ephesoft Transact Documentation

Using Your Own Authentication System with ArcGIS Online. Cameron Kroeker and Gary Lee

Setting Up the Server

Mozy. Implementing with Federated Identity

CLI users are not listed on the Cisco Prime Collaboration User Management page.

Unity Connection Version 10.5 SAML SSO Configuration Example

SAML 2.0 SSO Implementation for Oracle Financial Services Lending and Leasing

TACACs+, RADIUS, LDAP, RSA, and SAML

esignlive SAML Administrator's Guide Product Release: 6.5 Date: July 05, 2018 esignlive 8200 Decarie Blvd, Suite 300 Montreal, Quebec H4P 2P5

Cloud Secure Integration with ADFS. Deployment Guide

Webthority can provide single sign-on to web applications using one of the following authentication methods:

Novell Access Manager

IBM InfoSphere Information Server Single Sign-On (SSO) by using SAML 2.0 and Tivoli Federated Identity Manager (TFIM)

Qualys SAML 2.0 Single Sign-On (SSO) Technical Brief

Single Sign-On with Sage People and Microsoft Active Directory Federation Services 2.0

Integration Guide. PingFederate SAML Integration Guide (SP-Initiated Workflow)

SafeNet Authentication Service

Configuring Claims-based Authentication for Microsoft Dynamics CRM Server. Last updated: June 2014

SAML with ADFS Setup Guide

Novell Access Manager

Module 3 Remote Desktop Gateway Estimated Time: 90 minutes

Manage SAML Single Sign-On

Architecture Assessment Case Study. Single Sign on Approach Document PROBLEM: Technology for a Changing World

for SharePoint On-prem (v5)

LDAP Synchronization Secure Coding Guide

Contents Introduction... 5 Configuring Single Sign-On... 7 Configuring Identity Federation Using SAML 2.0 Authentication... 29

Configuring the vrealize Automation Plug-in for ServiceNow

VAM. ADFS 2FA Value-Added Module (VAM) Deployment Guide

Trusted Login Connector (Hosted SSO)

Oracle Access Manager Configuration Guide

INTEGRATING OKTA: VMWARE WORKSPACE ONE OPERATIONAL TUTORIAL VMware Workspace ONE

Introduction... 5 Configuring Single Sign-On... 7 Prerequisites for Configuring Single Sign-On... 7 Installing Oracle HTTP Server...

Configuring ADFS 2.1 or 3.0 in Windows Server 2012 or 2012 R2 for Nosco Web SSO

Copyright

SOA S90-20A. SOA Security Lab. Download Full Version :

VMware AirWatch System Settings Reference Manual for On-Premises Customers A comprehensive listing of AirWatch system settings

Health Professional & ADFS Integration Guide

Configure the Identity Provider for Cisco Identity Service to enable SSO

Setting Up Resources in VMware Identity Manager (On Premises) Modified on 30 AUG 2017 VMware AirWatch 9.1.1

ArcGIS Enterprise Administration

VMware AirWatch System Settings Reference Manual for On-Premises Customers A comprehensive listing of AirWatch system settings. AirWatch v9.

Extranet Identity Management and Authentication for SharePoint On Premise, Office 365 and Beyond

SAML-Based SSO Configuration

Configure Unsanctioned Device Access Control

Single Sign On (SSO) with Polarion 17.3

PASS4TEST. IT Certification Guaranteed, The Easy Way! We offer free update service for one year

Object of this document

Extranet User Manager

Enterprise Vault.cloud CloudLink Google Account Synchronization Guide. CloudLink to 4.0.3

How does it look like?

Authentication. August 17, 2018 Version 9.4. For the most recent version of this document, visit our documentation website.

maxecurity Product Suite

.NET SAML Consumer Value-Added (VAM) Deployment Guide

IBM Security Access Manager Version 9.0 October Federation Administration topics IBM

Slack Cloud App SSO. Configuration Guide. Product Release Document Revisions Published Date

IBM Security Access Manager Version January Federation Administration topics IBM

UMANTIS CLOUD SSO (ADFS) CONFIGURATION GUIDE

October 14, SAML 2 Quick Start Guide

SafeConsole On-Prem Install Guide. version DataLocker Inc. July, SafeConsole. Reference for SafeConsole OnPrem

Integrating VMware Workspace ONE with Okta. VMware Workspace ONE

Authentication Guide

Transcription:

VIEVU Solution AD Sync and ADFS Guide Introduction This guide describes how to operate the VIEVU Solution AD Sync utility and configure Active Directory Federation Services (ADFS). Additional support material is available at www.vievu.com/vievu-solution-support. Contact Us If you need assistance or have any questions, please visit www.vievu.com/vievu-solution-support, contact us by phone at 888-285-4548 or email support@vievu.c Version 1.16.0.0 11062017

ACTIVE DIRECTORY SYNC VIEVU Solution AD Sync Guide OVERVIEW The VIEVU Solution AD Sync utility functions as a client application installed on a local computer which synchronizes your local Active Directory user accounts with the VIEVU Solution. CONNECTION Input the domain controller s information and specify an account with access to the domain. The Base DN can connect to an Active Directory OU or Domain. The Sync can be configured from 1-24 hours. Version 1.16.0.0 11062017 2

CONFIGURATION Once connected to Active Directory, you can choose to synchronize based on AD Group(s) or User Attribute(s), depending on how your Active Directory is structured. Match the VIEVU Solution fields to the appropriate Active Directory Attributes. Users also have the ability to not synchronize roles between VIEVU Solution and AD Sync. In cases when VIEVU Solution roles are managed differently from the Active Directory (AD) groups or attributes, the admin can clear the Sync Roles check box (shown below) so that AD roles are not copied to VIEVU Solution. All VIEVU Solution users are required to have a role assigned, so for new users, a default role (AD Sync) is created in VIEVU Solution when the Sync Roles check box is cleared. If the Sync Roles check box is cleared (as shown), roles of users already in VIEVU Solution are not changed or updated. Version 1.16.0.0 11062017 3

SYNCING For this example, Role is AD Group is selected, as in the previous window. When you run the sync operation, the program searches for an existing Role with the same name in VIEVU Solution. If a Role does not exist, the operation creates a new one in VIEVU Solution. Next, the program searches for a user that currently exists with the same login. If a user does not exist, a new user is created and automatically placed into that Role. Note: Users residing in multiple AD Groups inherit the first synchronized Group for that user. Version 1.16.0.0 11062017 4

FINISH AD Sync has been successfully configured. To Sync immediately, select the corresponding check box and click Finish. Version 1.16.0.0 11062017 5

If you selected Synchronize Immediately, the following window is displayed until Synchronization is complete. Version 1.16.0.0 11062017 6

Active Directory Federation Services (ADFS) OVERVIEW Before configuring ADFS, it is recommended that at least one (1) Administrator Account is not currently being synchronized with AD Sync. This ensures that you can retain access to login on the VIEVU Solution website to make changes if necessary. ADFS AUTHENTICATION PROCESS WEB-Site + AD FS (using SAML) VIEVU Solution Customer s side A user enters name/password The user is signed in User s browser VIEVU VIEVU Web-Site DB SOAP request for a SAML token AD FS AD through HTTS connection. https://somename.vievusolution.com/ Endpoint: https://<adfs>/adfs/services/trust/13/ VIEVU Login page usernamemixed, The request contains name\password name\password Calls SignOn for the asp.net user, redirect on Videos page any authenticated request If SAML token valid: API.Net Identity searches for a user by the username from attributes the user is found SAML token or fault, if credentials are invalid AD FS authenticates the user ADFS SETUP AND CONFIGURATION Enable UserNameMixed Endpoint 1. Open the ADFS Management Console. 2. Expand Service. 3. Select Endpoints. 4. Confirm /adfs/services/trust/13/usernamemixed is enabled. If not, enable the endpoint. Version 1.16.0.0 11062017 7

Add ADFS Relying Party 1. From the ADFS Management Console, expand the Trust Relationships directory. 2. Select Relying Part Trusts. 3. Click Add Relying Party Trust on the right. 4. Click Start. 5. Select Enter data about the relying party manually and click Next. 6. Enter the display name VIEVU RP. In the notes section, you can enter anything descriptive that you would like listed. Then click Next. 7. Select AD FS profile and click Next. 8. At the token certificate page, click Next. Version 1.16.0.0 11062017 8

9. Uncheck all options on the protocols page and click Next. VIEVU s implementation uses WS-Trust. VIEVU Solution AD Sync Guide 10. In the Relying party trust identifier field, enter the website address for your VIEVU Solution account. Version 1.16.0.0 11062017 9

11. Select I do not want to configure multi-factor authentication settings for this relying party trust at this time and click Next. 12. Select Permit all users to access this relying party and click Next. 13. Review the settings and when ready, click Next. 14. Place a checkmark in Open the edit claim rules dialog for this relying party trust when the wizard closes and click Close. 15. The Claim Rules window is displayed. Click Add Rule. 16. Select Send LDAP Attributes as Claims and click Next. 17. In the Claim rule name field, enter a name for the Claim Rule. On the left, select the Attribute that is being used to match the Login field in the VIEVU Solution. Typically, SAM-Account-Name is matched to the outgoing claim type of Name. 18. Click Finish. Version 1.16.0.0 11062017 10

19. Login to the VIEVU Solution webpage and go to the Settings page. 20. Click Active Directory on the left. 21. In the Active Directory Federation Services section, toggle Active Directory Federation to Yes. 22. Enter the ADFS Service Endpoint as the publicly available URI for your ADFS environment. The format is as follows: https://myadfs.mydomain.com/adfs/services/trust/13/username mixed The section listed in bold must be your ADFS environment URI. 23. Input the ADFS URI as the website address for your VIEVU Solution account. This must be identical to the web address you entered in Step 10. 24. Enter the ADFS Domain as your Active Directory domain name. 25. Click Save. 26. Click Test Connection, then enter your login/password information and click Test Connection. Enter an Active Directory user account and click Test Connection. The username format is simply a login and does not include domain information. Note: The username format is simply a login and does not include domain information. Version 1.16.0.0 11062017 11