diff --git a/docs/console/iam/iam.md b/docs/console/iam/iam.md
index c4d90c2b..cae44283 100644
--- a/docs/console/iam/iam.md
+++ b/docs/console/iam/iam.md
@@ -21,6 +21,6 @@ Il permet d’administrer des comptes locaux tout en supportant une hybridation
diff --git a/docs/console/iam/tutorials/sso_azuread.md b/docs/console/iam/tutorials/sso_azuread.md
index 1c46976e..f94c9897 100644
--- a/docs/console/iam/tutorials/sso_azuread.md
+++ b/docs/console/iam/tutorials/sso_azuread.md
@@ -1,5 +1,5 @@
---
-title: Exemple de fédération d'identité avec Microsoft EntraID
+title: Exemple de fédération d'identité avec Microsoft EntraID (Azure AD)
tags:
- iam
- tutorials
@@ -23,68 +23,182 @@ import ssoAad_016 from '@site/docs/console/iam/tutorials/images/sso_aad_016.png'
import ssoAad_017 from '@site/docs/console/iam/tutorials/images/sso_aad_017.png'
import ssoAad_018 from '@site/docs/console/iam/tutorials/images/sso_aad_018.png'
-Voici un exemple de configuration du référentiel d'authentification d'une organisation Cloud Temple avec __Microsoft EntraID__ (Azure Active Directory).
+Voici un exemple de configuration du référentiel d'authentification d'une organisation Cloud Temple avec __Microsoft EntraID__.
-La configuration de votre référentiel Microsoft au niveau d'une organisation Cloud Temple facilite l'authentification de vos utilisateurs sur la Console. Cela permet d'éviter la multiplication des facteurs d'authentification et de diminuer la surface d'attaque.
+La configuration de votre référentiel Microsoft au niveau d'une organisation Cloud Temple facilite l'authentification de vos utilisateurs sur la Console. Cela permet d'éviter la multiplication des facteurs d'authentification et de diminuer la surface d'attaque. Si vos utilisateurs sont authentifiés à leur compte Microsoft, l'authentification aux services de la Console sera transparente.
-Si vos utilisateurs sont authentifiés à leur compte Microsoft, l'authentification aux services de la Console sera transparente.
+:::info[Azure AD et Microsoft EntraID]
+Microsoft EntraID est le nouveau nom d'Azure Active Directory (Azure AD) depuis 2023. Il s'agit du même produit : ce tutoriel s'applique indifféremment aux deux appellations.
+:::
-Voici les différentes étapes pour réaliser cette configuration :
+## Choisir le protocole
-## Etape 1 : Configuration du SSO coté Microsoft Azure
+La fédération avec EntraID peut être réalisée avec l'un ou l'autre des deux protocoles standards. Les deux offrent un niveau de sécurité équivalent ; ils diffèrent principalement par ce que vous avez à nous transmettre et par ce qu'il faudra entretenir dans la durée.
-### Enregistrement d'une nouvelle application Azure (portail Azure)
+| | OpenID Connect | SAML 2.0 |
+|---|---|---|
+| Ce que vous nous transmettez | Deux identifiants et un secret | Une URL de métadonnées publique |
+| Secret échangé | Oui, le secret client | Aucun |
+| À entretenir dans le temps | Le secret client (24 mois maximum) | Le certificat de signature (3 ans par défaut) |
-Pour la création de l'__app registration__, il faut se rendre sur le portail Microsoft Azure, puis daans Microsoft EntraID, __"ADD > App Registration"__
+__En l'absence de contrainte particulière, nous recommandons OpenID Connect__ : c'est le protocole que nous déployons par défaut. Retenez SAML si votre politique interne l'impose, ou si votre annuaire est raccordé à un concentrateur de fédération qui ne parle que ce protocole.
+
+Indiquez le protocole retenu dès l'ouverture de votre demande d'assistance.
+
+## Les informations échangées
+
+La mise en place repose sur un échange dans les deux sens. En voici le détail d'emblée, pour vous permettre de tout préparer en une seule passe.
+
+### Ce que vous devez nous transmettre — en OpenID Connect
+
+| Information | Nom dans le portail Azure | À quoi elle sert |
+|---|---|---|
+| __Application (client) ID__ | *Application (client) ID* | Identifie l'application auprès d'EntraID |
+| __Directory (tenant) ID__ | *Directory (tenant) ID* | Détermine les points de terminaison OpenID Connect de votre annuaire |
+| __Secret client__ | *Client secret* → colonne __Value__ | Authentifie la Console auprès d'EntraID |
+
+Les deux identifiants figurent dans l'onglet __"Overview"__ de votre inscription d'application ; le secret se crée dans l'onglet __"Certificates & secrets"__.
+
+### Ce que vous devez nous transmettre — en SAML 2.0
+
+Une seule information suffit dans le cas courant :
+
+| Information | Nom dans le portail Azure | À quoi elle sert |
+|---|---|---|
+| __URL des métadonnées de fédération__ | *App Federation Metadata Url* | Nous en dérivons l'identifiant de votre annuaire, ses points de terminaison et son certificat de signature |
+
+Elle se présente sous cette forme :
+
+```
+https://login.microsoftonline.com//federationmetadata/2007-06/federationmetadata.xml?appid=
+```
+
+Vous la trouvez dans __"Enterprise applications"__ → votre application → __"Single sign-on"__, section *SAML Certificates*. Elle est publique et ne contient aucun secret : elle peut figurer dans le corps de votre demande.
+
+:::tip[Pourquoi cette URL plutôt qu'une liste de paramètres]
+Elle regroupe en une seule valeur l'ensemble des paramètres de votre annuaire et simplifie le suivi du renouvellement de votre certificat de signature. Si cette URL n'est pas joignable depuis Internet, transmettez à la place l'*Identity provider entity ID*, la *Single Sign-On service URL*, la *Single Logout service URL* et le certificat de signature au format __Certificate (Base64)__.
+:::
+
+:::warning[Ne transmettez jamais le secret dans le corps d'une demande]
+La valeur du secret client est un identifiant d'authentification. Ne la déposez pas dans le corps d'une demande d'assistance, ni dans un commentaire, ni dans une pièce jointe non chiffrée : elle y resterait consultable de façon durable.
+
+Indiquez dans votre demande que vous disposez du secret, et transmettez-le par le canal sécurisé que votre contact Cloud Temple vous indiquera. Les deux identifiants (Application ID et Directory ID) ne sont pas sensibles et peuvent, eux, figurer dans la demande.
+:::
+
+### Ce que Cloud Temple vous transmet
+
+Des valeurs propres à votre organisation, à déclarer dans votre application EntraID :
+
+| Notre terme | Terme Microsoft | Protocole |
+|---|---|---|
+| URL de redirection | *Redirect URL* | OpenID Connect |
+| URL de redirection | *Reply URL (Assertion Consumer Service URL)* | SAML 2.0 |
+| Identifiant du fournisseur de service | *Identifier (Entity ID)* | SAML 2.0 |
+
+:::tip[Demandez-les dès l'ouverture de votre demande]
+Ces valeurs dépendent de votre organisation et ne peuvent pas être devinées. En les demandant dès l'ouverture de votre demande d'assistance, vous pourrez réaliser toute la configuration Azure en une seule fois, sans avoir à y revenir.
+:::
+
+## Étape 1 : Configuration du SSO côté Microsoft EntraID
+
+Suivez la section correspondant au protocole retenu, puis la section « Configurations de sécurité supplémentaires », commune aux deux.
+
+### Voie OpenID Connect
+
+#### Enregistrement d'une nouvelle application Azure (portail Azure)
+
+Pour la création de l'__app registration__, rendez-vous sur le portail Microsoft Azure, puis dans Microsoft EntraID, __"ADD > App Registration"__.
Dans la page "Register an application", veuillez indiquer :
```
-- __Name__ : Indiquer "__SHIVA__"
-- __Supported account types__ : __Accounts in this organizational directory only__ (____ only - Single tenant)
-- __Redirect URL__ : A ne pas paramétrer dans un premier temps. L'URL sera fournie par le support Cloud Temple et sera à ajouter dans ce champ plus tard.
+- Name : indiquer "SHIVA"
+- Supported account types : Accounts in this organizational directory only ( only - Single tenant)
+- Redirect URL : renseigner l'URL fournie par Cloud Temple. Si vous ne l'avez pas encore, laissez le champ vide et reportez-vous à l'étape 3.
```
-Les informations __Application (client) ID__ et __Directory (tenant) ID__ sont les informations utiles à fournir dans la demande de support à l'équipe Cloud Temple pour activer l'authentification Microsoft EntraID au niveau de votre organisation.
+Les informations __Application (client) ID__ et __Directory (tenant) ID__ sont affichées sur l'onglet "Overview". Relevez-les : ce sont deux des trois informations à fournir dans votre demande d'assistance.
-### Définition d'un secret
+#### Définition d'un secret
-Dans l'onglet "Certificates & secrets", créer un nouveau secret.
-
-*À noter : la date d'expiration du secret ne peut être supérieure à 24 mois, y compris avec une date d'expiration custom.*
+Dans l'onglet "Certificates & secrets", créez un nouveau secret.
-Le secret généré sera à fournir dans la demande de support :
+:::warning[Copiez la valeur immédiatement]
+La valeur du secret n'est affichée qu'une seule fois, juste après sa création. Copiez le contenu de la colonne __"Value"__, et non celui de la colonne __"Secret ID"__. Si vous perdez cette valeur, vous devrez générer un nouveau secret.
+:::
-### Définition du token EntraID
+:::caution[Durée de validité limitée à 24 mois]
+La date d'expiration du secret ne peut être supérieure à 24 mois, y compris avec une date d'expiration personnalisée. __Notez dès maintenant cette date__ : à son échéance, la connexion SSO cessera de fonctionner pour l'ensemble de vos utilisateurs. Voir la section [Maintien de la fédération dans le temps](#maintien-de-la-fédération-dans-le-temps).
+:::
+
+#### Autorisation des informations utilisées par la Console
-Le token EntraID est nécessaire à la configuration de l'authentification.
+La Console identifie vos utilisateurs à partir des informations transportées par le jeton d'identité. Une seule action est nécessaire de votre part : __exposer l'adresse e-mail__.
-Dans le menu __"Token Configuration"__, cliquer sur __"Add optional claim"__. Vous devrez sélectionner "ID" en tant que type de token et cocher "email".
+Dans le menu __"Token Configuration"__, cliquez sur __"Add optional claim"__. Sélectionnez "ID" en tant que type de token et cochez "email".
-L'interface Azure va vous demander si vous souhaitez ajouter une permission qui vous permettra de lire l'email d'un utilisateur (Microsoft Graph email), cochez la case et validez.
+L'interface Azure vous demande si vous souhaitez ajouter une permission permettant de lire l'email d'un utilisateur (Microsoft Graph email). Cochez la case et validez.
-Ensuite, rendez-vous sur "API permissions" et cliquez sur __"Grant admin consent for Cloud Temple"__.
+Rendez-vous ensuite sur "API permissions" et cliquez sur __"Grant admin consent for <votre organisation>"__.
-### Configurations de sécurité supplémentaires (optionel mais recommandé)
+Pour information, voici l'ensemble des informations consommées par la Console :
+
+| Information | Usage | Action de votre part |
+|---|---|---|
+| `email` | Adresse de connexion de l'utilisateur | __Oui__ — à déclarer en claim optionnel (ci-dessus) |
+| `oid` | Rattachement stable du compte Console à l'identité de votre annuaire, y compris si l'adresse e-mail change | Aucune — émis nativement par EntraID |
+| `given_name`, `family_name` | Prénom et nom affichés dans la Console | Aucune — inclus dans le périmètre `profile` |
+
+### Voie SAML 2.0
+
+#### Création de l'application d'entreprise
+
+Dans __Microsoft EntraID__, rendez-vous dans __"Enterprise applications"__, puis __"New application"__. Choisissez __"Create your own application"__, nommez-la, et sélectionnez *Integrate any other application you don't find in the gallery (Non-gallery)*. Validez avec __"Create"__.
-Par défaut, Microsoft EntraID tel que configuré donnera à n'importe quel utilisateur de votre tenant Azure la possibilité de se connecter à votre organisation Cloud Temple.
-Il est possible de restreindre au niveau de __"App Registration"__ les accès pour n'autoriser qu'une liste d'utilisateurs ou groupes à se connecter à votre organisation Cloud Temple.
+#### Configuration de l'authentification unique
-Voici la procédure à suivre ;
+Dans votre application, ouvrez __"Single sign-on"__ et choisissez __"SAML"__. Dans __"Basic SAML Configuration"__, cliquez sur __"Edit"__ et renseignez avec les valeurs fournies par Cloud Temple :
+
+- __Identifier (Entity ID)__ ;
+- __Reply URL (Assertion Consumer Service URL)__.
+
+Enregistrez.
+
+#### Attributs et revendications
+
+EntraID émet par défaut les revendications attendues par la Console. Vérifiez leur présence dans __"Attributes & Claims"__ :
+
+| Revendication | Usage | Action de votre part |
+|---|---|---|
+| `…/claims/emailaddress` | Adresse de connexion de l'utilisateur | Aucune — source `user.mail` |
+| `http://schemas.microsoft.com/identity/claims/objectidentifier` | Rattachement stable du compte Console à l'identité de votre annuaire | Aucune |
+| `…/claims/givenname`, `…/claims/surname` | Prénom et nom affichés dans la Console | Aucune |
+
+:::warning[Identifiant de nom (NameID) : le point le plus souvent manqué]
+Dans __"Attributes & Claims"__ → __"Unique User Identifier (Name ID)"__, positionnez la source sur __user.objectid__ et le format sur __Persistent__.
+
+Par défaut, EntraID émet l'adresse e-mail comme NameID. Si un utilisateur change d'adresse, la Console le traiterait comme une personne différente et il perdrait ses droits. L'identifiant d'objet, lui, ne change jamais.
+:::
+
+### Configurations de sécurité supplémentaires (optionnel mais recommandé)
+
+Par défaut, Microsoft EntraID tel que configuré donnera à n'importe quel utilisateur de votre tenant Azure la possibilité de se connecter à votre organisation Cloud Temple. Il est possible de restreindre au niveau de l'__"App Registration"__ les accès pour n'autoriser qu'une liste d'utilisateurs ou de groupes.
+
+Voici la procédure à suivre.
#### Accéder aux paramètres supplémentaires "App Registration"
@@ -96,13 +210,13 @@ Allez sur l'onglet "Overview" puis cliquez sur le nom de l'application (le lien
##### Option 2
-Se rendre dans les "Enterprise applications" et chercher en utilisant le nom de l'application créée précédemment.
+Rendez-vous dans les "Enterprise applications" et cherchez en utilisant le nom de l'application créée précédemment.
#### Restriction de l'authentification aux utilisateurs assignés à l'application
-Indiquer ici la nécessité d'un assignement de l'utilisateur à l'application pour autoriser son authentification :
+Indiquez ici la nécessité d'un assignement de l'utilisateur à l'application pour autoriser son authentification :
@@ -112,46 +226,102 @@ Seuls les groupes et utilisateurs assignés à l'application pourront se connect
-Enfin, vous n'aurez plus qu'à appliquer l'assignation en cliquant sur "Assign".
+Enfin, appliquez l'assignation en cliquant sur "Assign".
-Désormais les utilisateurs assignés à l'application pourront se connecter à votre organisation Cloud Temple via l'application créée.
+Désormais, les utilisateurs assignés à l'application pourront se connecter à votre organisation Cloud Temple via l'application créée.
+
+## Étape 2 : Demander la configuration du SSO de votre organisation
+
+Cette partie de la configuration se fait au niveau de l'organisation par l'équipe Cloud Temple.
-## Etape 2 : Demander la configuration du SSO (Single Sign-On) de votre organisation
+Pour ce faire, faites __une demande d'assistance__ dans la Console indiquant votre souhait de configurer une fédération Microsoft EntraID, en précisant :
-Cette partie de la configuration se fait au niveau de l'organisation par l'équipe Cloud temple.
+- le nom de votre organisation ;
+- __le protocole retenu__ : OpenID Connect ou SAML 2.0 ;
+- le nom d'un contact, avec son adresse e-mail et son numéro de téléphone, pour finaliser la configuration ;
+- __en OpenID Connect__ : l'__Application (client) ID__ et le __Directory (tenant) ID__ relevés à l'étape 1 ;
+- __en SAML 2.0__ : l'__URL des métadonnées de fédération__ de votre application.
-Pour se faire, faites __une demande d'assistance__ dans la console indiquant votre souhait de configurer une SSO Microsoft EntraID.
+En OpenID Connect, transmettez le __secret client__ par le canal sécurisé indiqué par votre contact, et non dans le corps de la demande. En SAML, aucun secret n'est échangé.
-Veuillez donner les informations suivantes dans la demande d'assistance :
- Le nom de votre Organisation
- Le nom d'un contact avec son mail et n° de téléphone pour finaliser la configuration
- Application ID (identifiant unique associé à l'application créée précédemment)
- Directory ID (correspond à l'identifiant Azure AD du tenant Azure)
- Secret (Secret associé à l'application créée précédemment)
+Dès que la configuration est réalisée côté Console, le contact indiqué en sera informé.
-Dès que la configuration est réalisée coté Console, le contact indiqué sera informé.
+## Étape 3 : Déclaration de la "Redirect URL" (OpenID Connect)
-## Etape 3 : Finalisation de la configuration
+Si vous n'avez pas renseigné la "Redirect URL" lors de la création de l'application, ajoutez-la maintenant.
-Sur la page d'accueil de l'App Registration, dans le menu overview, cliquez sur "Add a Redirect URL".
+En SAML 2.0, les URL équivalentes ont déjà été déclarées dans __"Basic SAML Configuration"__ à l'étape 1 : passez directement à l'étape 4.
+
+Sur la page d'accueil de l'App Registration, dans le menu "Overview", cliquez sur "Add a Redirect URL".
-Ensuite, dirigez-vous vers le "Add a platform" et ajoutez-en une de type Web.
+Dirigez-vous ensuite vers "Add a platform" et ajoutez-en une de type Web.
-Il vous suffit de renseigner la "Redirect URL" fournie par la Team Produit Applications.
+Renseignez la "Redirect URL" fournie par Cloud Temple.
-Vous devriez obtenir ce résulat une fois la "Redirect URL" ajoutée.
+Vous devriez obtenir ce résultat une fois la "Redirect URL" ajoutée.
La configuration de la "Redirect URL" peut mettre quelques minutes à être effective.
+
+## Étape 4 : Vérification
+
Une fois toutes les étapes réalisées, vous pouvez vous authentifier à votre organisation Cloud Temple via votre SSO.
+
+:::info[Droits des nouveaux utilisateurs]
+La fédération d'identité gère __l'authentification__, pas les __autorisations__. Un utilisateur qui se connecte pour la première fois via le SSO ne dispose d'aucun droit tant qu'un propriétaire de l'organisation ne lui en a pas attribué depuis la Console.
+:::
+
+## Maintien de la fédération dans le temps
+
+C'est le principal point de vigilance : quel que soit le protocole, un élément expire, et son expiration interrompt le SSO __pour l'ensemble de vos utilisateurs__.
+
+### En OpenID Connect : le secret client
+
+Le secret client expire au plus tard 24 mois après sa création. Anticipez son renouvellement :
+
+1. dans "Certificates & secrets", créez un __nouveau__ secret sans supprimer l'ancien ;
+2. transmettez sa valeur à Cloud Temple par le canal sécurisé, en ouvrant une demande d'assistance ;
+3. une fois la bascule confirmée par nos équipes, supprimez l'ancien secret depuis le portail Azure.
+
+Conserver les deux secrets le temps de la bascule évite toute interruption de service.
+
+### En SAML 2.0 : le certificat de signature
+
+Le certificat de signature émis par EntraID a une durée de vie limitée, de trois ans par défaut.
+
+__Prévenez-nous avant toute rotation de certificat__, via une demande d'assistance, en respectant la période de recouvrement proposée par Microsoft. Si vous nous avez transmis un certificat sous forme de fichier plutôt que l'URL de métadonnées, joignez le nouveau certificat à votre demande.
+
+## Bonnes pratiques
+
+- __Pilotez l'accès par groupes__ plutôt que par utilisateurs : l'arrivée ou le départ d'un collaborateur se traite alors dans votre annuaire, sans intervention sur la Console.
+- __Activez l'authentification multifacteur__ sur l'application dans vos stratégies d'accès conditionnel EntraID : elle s'applique alors à l'accès à la Console.
+- __Programmez une alerte__ à l'approche de la date d'expiration du secret client ou du certificat de signature, selon le protocole retenu.
+- __Conservez au moins un compte propriétaire local__ sur votre organisation Cloud Temple, non fédéré, afin de garder un accès en cas d'indisponibilité de votre annuaire.
+
+## Dépannage
+
+| Symptôme | Protocole | Cause probable |
+|---|---|---|
+| `AADSTS50011` : l'URL de redirection ne correspond pas | Les deux | L'URL déclarée dans Azure diffère de celle fournie par Cloud Temple. Vérifiez-la caractère par caractère, y compris l'absence de `/` final. |
+| `AADSTS700016` : application introuvable | SAML 2.0 | L'*Entity ID* déclaré ne correspond pas à celui fourni par Cloud Temple. |
+| `AADSTS7000215` : secret invalide | OpenID Connect | Le secret a expiré, ou la valeur transmise était le "Secret ID" au lieu de la "Value". |
+| `AADSTS50105` : utilisateur non assigné | Les deux | L'option "Assignment required" est active et l'utilisateur n'est pas assigné à l'application. |
+| Le bouton de connexion n'apparaît pas sur la page | Les deux | La configuration n'est pas encore active côté Cloud Temple. |
+| L'utilisateur est authentifié mais la Console refuse l'accès | Les deux | L'adresse e-mail est absente du jeton, ou aucun droit n'a été attribué à l'utilisateur. |
+| L'utilisateur apparaît comme un nouveau compte à chaque connexion | SAML 2.0 | Le NameID n'est pas positionné sur `user.objectid`. |
+| Erreur de signature à l'arrivée sur la Console | SAML 2.0 | Le certificat de signature a été renouvelé côté Azure sans que nous en soyons informés. |
+
+## Support
+
+Pour toute question sur cette procédure, ouvrez une demande d'assistance depuis votre Console. Précisez le nom de votre organisation ainsi que l'horodatage d'une tentative de connexion en échec : cela permet de retrouver la trace correspondante.
diff --git a/i18n/de/docusaurus-plugin-content-docs/current/console/iam/iam.md b/i18n/de/docusaurus-plugin-content-docs/current/console/iam/iam.md
index 58f01e58..990ea987 100644
--- a/i18n/de/docusaurus-plugin-content-docs/current/console/iam/iam.md
+++ b/i18n/de/docusaurus-plugin-content-docs/current/console/iam/iam.md
@@ -21,6 +21,6 @@ Es ermöglicht die Verwaltung lokaler Konten und unterstützt gleichzeitig die H
\ No newline at end of file
diff --git a/i18n/de/docusaurus-plugin-content-docs/current/console/iam/tutorials/sso_azuread.md b/i18n/de/docusaurus-plugin-content-docs/current/console/iam/tutorials/sso_azuread.md
index b0da18d6..04807c5f 100644
--- a/i18n/de/docusaurus-plugin-content-docs/current/console/iam/tutorials/sso_azuread.md
+++ b/i18n/de/docusaurus-plugin-content-docs/current/console/iam/tutorials/sso_azuread.md
@@ -1,5 +1,5 @@
---
-title: Identity Federation Example with Microsoft EntraID
+title: Beispiel einer Identitätsföderation mit Microsoft EntraID (Azure AD)
tags:
- iam
- tutorials
@@ -23,136 +23,305 @@ import ssoAad_016 from '@site/docs/console/iam/tutorials/images/sso_aad_016.png'
import ssoAad_017 from '@site/docs/console/iam/tutorials/images/sso_aad_017.png'
import ssoAad_018 from '@site/docs/console/iam/tutorials/images/sso_aad_018.png'
-Here is an example configuration of the identity provider for a Cloud Temple organization using __Microsoft EntraID__ (Azure Active Directory).
+Nachfolgend finden Sie ein Beispiel für die Konfiguration des Authentifizierungsverzeichnisses einer Cloud-Temple-Organisation mit __Microsoft EntraID__.
-Configuring your Microsoft identity provider at the Cloud Temple organization level simplifies user authentication on the Console. This helps avoid the proliferation of authentication factors and reduces the attack surface.
+Die Konfiguration Ihres Microsoft-Verzeichnisses auf Ebene einer Cloud-Temple-Organisation erleichtert die Authentifizierung Ihrer Benutzer an der Konsole. Dadurch lässt sich die Vervielfachung von Authentifizierungsfaktoren vermeiden und die Angriffsfläche verringern. Wenn Ihre Benutzer bereits an ihrem Microsoft-Konto angemeldet sind, erfolgt die Authentifizierung an den Diensten der Konsole nahtlos.
-If your users are already authenticated to their Microsoft accounts, logging into the Console services will be seamless and transparent.
+:::info[Azure AD und Microsoft EntraID]
+Microsoft EntraID ist seit 2023 der neue Name von Azure Active Directory (Azure AD). Es handelt sich um dasselbe Produkt: Dieses Tutorial gilt gleichermaßen für beide Bezeichnungen.
+:::
-Below are the steps to complete this configuration:
+## Auswahl des Protokolls
-## Step 1: SSO Configuration on Microsoft Azure Side
+Die Föderation mit EntraID lässt sich mit einem der beiden Standardprotokolle umsetzen. Beide bieten ein gleichwertiges Sicherheitsniveau; sie unterscheiden sich vor allem darin, was Sie uns übermitteln müssen und was dauerhaft zu pflegen ist.
-### Register a new Azure application (Azure portal)
+| | OpenID Connect | SAML 2.0 |
+|---|---|---|
+| Was Sie uns übermitteln | Zwei Kennungen und ein Secret | Eine öffentliche Metadaten-URL |
+| Ausgetauschtes Secret | Ja, das Client Secret | Keines |
+| Dauerhaft zu pflegen | Das Client Secret (höchstens 24 Monate) | Das Signaturzertifikat (standardmäßig 3 Jahre) |
-To create the __app registration__, go to the Microsoft Azure portal, then navigate to Microsoft Entra ID, and select __"Add > App Registration"__.
+__Sofern keine besonderen Vorgaben bestehen, empfehlen wir OpenID Connect__: Es ist das Protokoll, das wir standardmäßig einsetzen. Wählen Sie SAML, wenn Ihre internen Richtlinien es vorschreiben oder wenn Ihr Verzeichnis an einen Föderationsdienst angebunden ist, der ausschließlich dieses Protokoll unterstützt.
-On the "Register an application" page, please specify:
+Geben Sie das gewählte Protokoll bereits beim Öffnen Ihrer Supportanfrage an.
+
+## Die ausgetauschten Informationen
+
+Die Einrichtung beruht auf einem Austausch in beide Richtungen. Hier die Einzelheiten vorab, damit Sie alles in einem Durchgang vorbereiten können.
+
+### Was Sie uns übermitteln müssen — bei OpenID Connect
+
+| Information | Bezeichnung im Azure-Portal | Wozu sie dient |
+|---|---|---|
+| __Application (client) ID__ | *Application (client) ID* | Identifiziert die Anwendung gegenüber EntraID |
+| __Directory (tenant) ID__ | *Directory (tenant) ID* | Bestimmt die OpenID-Connect-Endpunkte Ihres Verzeichnisses |
+| __Client Secret__ | *Client secret* → Spalte __Value__ | Authentifiziert die Konsole gegenüber EntraID |
+
+Beide Kennungen finden Sie auf der Registerkarte __"Overview"__ Ihrer App-Registrierung; das Secret wird auf der Registerkarte __"Certificates & secrets"__ erstellt.
+
+### Was Sie uns übermitteln müssen — bei SAML 2.0
+
+Im Regelfall genügt eine einzige Information:
+
+| Information | Bezeichnung im Azure-Portal | Wozu sie dient |
+|---|---|---|
+| __URL der Föderationsmetadaten__ | *App Federation Metadata Url* | Daraus leiten wir die Kennung Ihres Verzeichnisses, dessen Endpunkte und dessen Signaturzertifikat ab |
+
+Sie hat folgende Form:
```
-- __Name__ : Enter "__SHIVA__"
-- __Supported account types__ : __Accounts in this organizational directory only__ (____ only - Single tenant)
-- __Redirect URL__ : Do not configure this field at this time. The URL will be provided by Cloud Temple support and should be added to this field later.
+https://login.microsoftonline.com//federationmetadata/2007-06/federationmetadata.xml?appid=
+```
+
+Sie finden sie unter __"Enterprise applications"__ → Ihre Anwendung → __"Single sign-on"__, Abschnitt *SAML Certificates*. Sie ist öffentlich und enthält kein Secret: Sie darf im Text Ihrer Anfrage stehen.
+
+:::tip[Warum diese URL statt einer Parameterliste]
+Sie fasst sämtliche Parameter Ihres Verzeichnisses in einem einzigen Wert zusammen und erleichtert die Nachverfolgung der Erneuerung Ihres Signaturzertifikats. Falls diese URL aus dem Internet nicht erreichbar ist, übermitteln Sie stattdessen die *Identity provider entity ID*, die *Single Sign-On service URL*, die *Single Logout service URL* sowie das Signaturzertifikat im Format __Certificate (Base64)__.
+:::
+
+:::warning[Übermitteln Sie das Secret niemals im Text einer Anfrage]
+Der Wert des Client Secret ist ein Authentifizierungsmerkmal. Fügen Sie ihn nicht in den Text einer Supportanfrage, in einen Kommentar oder in einen unverschlüsselten Anhang ein: Dort bliebe er dauerhaft einsehbar.
+
+Geben Sie in Ihrer Anfrage an, dass Ihnen das Secret vorliegt, und übermitteln Sie es über den sicheren Kanal, den Ihr Cloud-Temple-Ansprechpartner Ihnen nennt. Die beiden Kennungen (Application ID und Directory ID) sind nicht vertraulich und dürfen in der Anfrage stehen.
+:::
+
+### Was Cloud Temple Ihnen übermittelt
+
+Für Ihre Organisation spezifische Werte, die in Ihrer EntraID-Anwendung zu hinterlegen sind:
+
+| Unsere Bezeichnung | Microsoft-Bezeichnung | Protokoll |
+|---|---|---|
+| Weiterleitungs-URL | *Redirect URL* | OpenID Connect |
+| Weiterleitungs-URL | *Reply URL (Assertion Consumer Service URL)* | SAML 2.0 |
+| Kennung des Dienstanbieters | *Identifier (Entity ID)* | SAML 2.0 |
+
+:::tip[Fordern Sie sie beim Öffnen Ihrer Anfrage an]
+Diese Werte hängen von Ihrer Organisation ab und lassen sich nicht erraten. Wenn Sie sie beim Öffnen Ihrer Supportanfrage anfordern, können Sie die gesamte Azure-Konfiguration in einem Durchgang vornehmen, ohne später darauf zurückkommen zu müssen.
+:::
+
+## Schritt 1: SSO-Konfiguration auf Seite von Microsoft EntraID
+
+Folgen Sie dem Abschnitt zum gewählten Protokoll und anschließend dem Abschnitt „Zusätzliche Sicherheitseinstellungen", der für beide gilt.
+
+### Weg über OpenID Connect
+
+#### Registrierung einer neuen Azure-Anwendung (Azure-Portal)
+
+Für die Erstellung der __App Registration__ rufen Sie das Microsoft-Azure-Portal auf und wählen dann in Microsoft EntraID __"ADD > App Registration"__.
+
+Geben Sie auf der Seite "Register an application" Folgendes an:
+
+```
+- Name: "SHIVA" angeben
+- Supported account types: Accounts in this organizational directory only ( only - Single tenant)
+- Redirect URL: die von Cloud Temple bereitgestellte URL angeben. Falls sie Ihnen noch nicht vorliegt, lassen Sie das Feld leer und fahren Sie mit Schritt 3 fort.
```
-The __Application (client) ID__ and __Directory (tenant) ID__ are the key details that must be provided in your support request to the Cloud Temple team to enable Microsoft Entra ID authentication for your organization.
+Die Angaben __Application (client) ID__ und __Directory (tenant) ID__ werden auf der Registerkarte "Overview" angezeigt. Notieren Sie sie: Es handelt sich um zwei der drei Informationen, die Sie in Ihrer Supportanfrage angeben müssen.
-### Definition of a secret
+#### Festlegung eines Secret
-In the "Certificates & secrets" tab, create a new secret.
-
-*Note: The expiration date of the secret cannot exceed 24 months, even with a custom expiration date.*
+Erstellen Sie auf der Registerkarte "Certificates & secrets" ein neues Secret.
-The generated secret must be provided in the support request:
+:::warning[Kopieren Sie den Wert sofort]
+Der Wert des Secret wird nur ein einziges Mal angezeigt, unmittelbar nach seiner Erstellung. Kopieren Sie den Inhalt der Spalte __"Value"__ und nicht den der Spalte __"Secret ID"__. Falls Sie diesen Wert verlieren, müssen Sie ein neues Secret erzeugen.
+:::
-### Definition des EntraID-Tokens
+:::caution[Gültigkeit auf 24 Monate begrenzt]
+Das Ablaufdatum des Secret darf 24 Monate nicht überschreiten, auch nicht mit einem benutzerdefinierten Ablaufdatum. __Notieren Sie sich dieses Datum bereits jetzt__: Nach Ablauf funktioniert die SSO-Anmeldung für sämtliche Benutzer nicht mehr. Siehe Abschnitt [Pflege der Föderation im Zeitverlauf](#pflege-der-föderation-im-zeitverlauf).
+:::
+
+#### Freigabe der von der Konsole verwendeten Informationen
-Der EntraID-Token ist für die Konfiguration der Authentifizierung erforderlich.
+Die Konsole identifiziert Ihre Benutzer anhand der im Identitätstoken übermittelten Informationen. Nur eine Maßnahme ist Ihrerseits erforderlich: __die E-Mail-Adresse bereitstellen__.
-Klicken Sie im Menü __"Token Configuration"__ auf __"Add optional claim"__. Wählen Sie als Token-Typ "ID" aus und aktivieren Sie die Option "email".
+Klicken Sie im Menü __"Token Configuration"__ auf __"Add optional claim"__. Wählen Sie "ID" als Tokentyp und aktivieren Sie "email".
-Die Azure-Oberfläche fragt Sie daraufhin, ob Sie eine Berechtigung hinzufügen möchten, die Ihnen das Lesen der E-Mail-Adresse eines Benutzers (Microsoft Graph email) ermöglicht. Aktivieren Sie das Kontrollkästchen und bestätigen Sie.
+Die Azure-Oberfläche fragt, ob Sie eine Berechtigung hinzufügen möchten, die das Lesen der E-Mail-Adresse eines Benutzers erlaubt (Microsoft Graph email). Aktivieren Sie das Kontrollkästchen und bestätigen Sie.
-Wechseln Sie anschließend zu "API-Berechtigungen" und klicken Sie auf __"Grant admin consent for Cloud Temple"__.
+Rufen Sie anschließend "API permissions" auf und klicken Sie auf __"Grant admin consent for <Ihre Organisation>"__.
-### Additional Security Configurations (optional but recommended)
+Zur Information: Hier alle von der Konsole genutzten Informationen:
+
+| Information | Verwendung | Maßnahme Ihrerseits |
+|---|---|---|
+| `email` | Anmeldeadresse des Benutzers | __Ja__ — als optionaler Claim zu deklarieren (siehe oben) |
+| `oid` | Stabile Zuordnung des Konsolenkontos zur Identität in Ihrem Verzeichnis, auch bei Änderung der E-Mail-Adresse | Keine — wird von EntraID nativ ausgestellt |
+| `given_name`, `family_name` | In der Konsole angezeigter Vor- und Nachname | Keine — im Bereich `profile` enthalten |
+
+### Weg über SAML 2.0
+
+#### Erstellung der Unternehmensanwendung
-By default, Microsoft Entra ID, as configured, will allow any user in your Azure tenant to sign in to your Cloud Temple organization.
-It is possible to restrict access at the __"App Registration"__ level to allow only a specific list of users or groups to sign in to your Cloud Temple organization.
+Rufen Sie in __Microsoft EntraID__ die __"Enterprise applications"__ auf und dann __"New application"__. Wählen Sie __"Create your own application"__, vergeben Sie einen Namen und wählen Sie *Integrate any other application you don't find in the gallery (Non-gallery)*. Bestätigen Sie mit __"Create"__.
-Follow these steps:
+#### Konfiguration des einmaligen Anmeldens
-#### Access additional "App Registration" settings
+Öffnen Sie in Ihrer Anwendung __"Single sign-on"__ und wählen Sie __"SAML"__. Klicken Sie unter __"Basic SAML Configuration"__ auf __"Edit"__ und tragen Sie die von Cloud Temple bereitgestellten Werte ein:
+
+- __Identifier (Entity ID)__;
+- __Reply URL (Assertion Consumer Service URL)__.
+
+Speichern Sie.
+
+#### Attribute und Ansprüche
+
+EntraID stellt die von der Konsole erwarteten Ansprüche standardmäßig aus. Prüfen Sie ihr Vorhandensein unter __"Attributes & Claims"__:
+
+| Anspruch | Verwendung | Maßnahme Ihrerseits |
+|---|---|---|
+| `…/claims/emailaddress` | Anmeldeadresse des Benutzers | Keine — Quelle `user.mail` |
+| `http://schemas.microsoft.com/identity/claims/objectidentifier` | Stabile Zuordnung des Konsolenkontos zur Identität in Ihrem Verzeichnis | Keine |
+| `…/claims/givenname`, `…/claims/surname` | In der Konsole angezeigter Vor- und Nachname | Keine |
+
+:::warning[Namenskennung (NameID): der am häufigsten übersehene Punkt]
+Setzen Sie unter __"Attributes & Claims"__ → __"Unique User Identifier (Name ID)"__ die Quelle auf __user.objectid__ und das Format auf __Persistent__.
+
+Standardmäßig gibt EntraID die E-Mail-Adresse als NameID aus. Ändert sich die Adresse eines Benutzers, würde die Konsole ihn als andere Person behandeln und er verlöre seine Rechte. Die Objektkennung hingegen ändert sich nie.
+:::
+
+### Zusätzliche Sicherheitseinstellungen (optional, aber empfohlen)
+
+Standardmäßig erlaubt Microsoft EntraID in dieser Konfiguration jedem Benutzer Ihres Azure-Tenants, sich an Ihrer Cloud-Temple-Organisation anzumelden. Sie können den Zugriff auf Ebene der __"App Registration"__ einschränken, sodass nur eine Liste von Benutzern oder Gruppen zugelassen ist.
+
+Gehen Sie dazu wie folgt vor.
+
+#### Zugriff auf die zusätzlichen Einstellungen der "App Registration"
##### Option 1
-Gehen Sie zum Register „Übersicht“ und klicken Sie auf den Anwendungsnamen (den Link hinter „Verwaltete Anwendung“).
+Rufen Sie die Registerkarte "Overview" auf und klicken Sie auf den Namen der Anwendung (der Link hinter "Managed application").
##### Option 2
-Gehe zu den „Enterprise-Anwendungen“ und suche mithilfe des zuvor erstellten Anwendungsnamens.
+Rufen Sie die "Enterprise applications" auf und suchen Sie nach dem Namen der zuvor erstellten Anwendung.
-#### Authentication restriction to users assigned to the application
+#### Beschränkung der Authentifizierung auf zugewiesene Benutzer
-Indicate here the requirement for user assignment to the application to allow authentication:
+Legen Sie hier fest, dass ein Benutzer der Anwendung zugewiesen sein muss, um sich authentifizieren zu dürfen:
-#### Assigning Users and Groups to the Application
+#### Zuweisung von Benutzern und Gruppen zur Anwendung
-Only users and groups assigned to the application will be able to sign in to your Cloud Temple organization via the app registration.
+Nur die der Anwendung zugewiesenen Gruppen und Benutzer können sich über die App Registration an Ihrer Cloud-Temple-Organisation anmelden.
-Finally, simply apply the assignment by clicking "Assign".
+Wenden Sie die Zuweisung abschließend durch Klick auf "Assign" an.
-From now on, users assigned to the application will be able to sign in to your Cloud Temple organization via the created application.
+Ab jetzt können sich die der Anwendung zugewiesenen Benutzer über die erstellte Anwendung an Ihrer Cloud-Temple-Organisation anmelden.
+
+## Schritt 2: SSO-Konfiguration Ihrer Organisation beantragen
-## Step 2: Request SSO (Single Sign-On) Configuration for Your Organization
+Dieser Teil der Konfiguration wird auf Ebene der Organisation vom Cloud-Temple-Team durchgeführt.
-This configuration step is performed at the organization level by the Cloud Temple team.
+Stellen Sie dazu __eine Supportanfrage__ in der Konsole, in der Sie Ihren Wunsch nach einer Microsoft-EntraID-Föderation angeben, und nennen Sie:
-To proceed, please __submit a support request__ in the console indicating your intention to set up Microsoft Entra ID SSO.
+- den Namen Ihrer Organisation;
+- __das gewählte Protokoll__: OpenID Connect oder SAML 2.0;
+- den Namen eines Ansprechpartners mit E-Mail-Adresse und Telefonnummer für den Abschluss der Konfiguration;
+- __bei OpenID Connect__: die in Schritt 1 notierte __Application (client) ID__ und __Directory (tenant) ID__;
+- __bei SAML 2.0__: die __URL der Föderationsmetadaten__ Ihrer Anwendung.
-Please provide the following information in your support request:
+Übermitteln Sie bei OpenID Connect das __Client Secret__ über den von Ihrem Ansprechpartner genannten sicheren Kanal und nicht im Text der Anfrage. Bei SAML wird kein Secret ausgetauscht.
-- Name of your Organization
-- Name of a contact person, including their email address and phone number, to finalize the configuration
-- Application ID (unique identifier associated with the previously created application)
-- Directory ID (corresponds to the Azure AD tenant ID of your Azure environment)
-- Secret (secret associated with the previously created application)
+Sobald die Konfiguration auf Seite der Konsole abgeschlossen ist, wird der angegebene Ansprechpartner informiert.
-Once the configuration is completed on the Console side, the designated contact will be notified.
+## Schritt 3: Hinterlegung der "Redirect URL" (OpenID Connect)
-## Schritt 3: Abschluss der Konfiguration
+Falls Sie die "Redirect URL" bei der Erstellung der Anwendung nicht angegeben haben, fügen Sie sie jetzt hinzu.
-Auf der Startseite der App-Registrierung klicken Sie im Menü „Übersicht“ auf „Redirect-URL hinzufügen“.
+Bei SAML 2.0 wurden die entsprechenden URLs bereits in Schritt 1 unter __"Basic SAML Configuration"__ hinterlegt: Fahren Sie direkt mit Schritt 4 fort.
+
+Klicken Sie auf der Startseite der App Registration im Menü "Overview" auf "Add a Redirect URL".
-Wechseln Sie anschließend zum Abschnitt „Plattform hinzufügen“ und fügen Sie eine Plattform des Typs „Web“ hinzu.
+Rufen Sie anschließend "Add a platform" auf und fügen Sie eine Plattform vom Typ Web hinzu.
-Geben Sie einfach die von der Produkt-Team Anwendungen bereitgestellte „Redirect-URL“ ein.
+Geben Sie die von Cloud Temple bereitgestellte "Redirect URL" an.
-Nachdem die „Redirect-URL“ hinzugefügt wurde, sollte das folgende Ergebnis angezeigt werden.
+Nach dem Hinzufügen der "Redirect URL" sollten Sie dieses Ergebnis erhalten.
-Die Konfiguration der „Redirect-URL“ kann einige Minuten in Anspruch nehmen, bis sie wirksam ist.
-Nach Abschluss aller Schritte können Sie sich über Ihren SSO bei Ihrer Cloud Temple-Organisation authentifizieren.
+Es kann einige Minuten dauern, bis die Konfiguration der "Redirect URL" wirksam wird.
+
+## Schritt 4: Überprüfung
+
+Sobald alle Schritte abgeschlossen sind, können Sie sich über Ihr SSO an Ihrer Cloud-Temple-Organisation anmelden.
+
+:::info[Berechtigungen neuer Benutzer]
+Die Identitätsföderation regelt die __Authentifizierung__, nicht die __Berechtigungen__. Ein Benutzer, der sich zum ersten Mal über SSO anmeldet, verfügt über keinerlei Rechte, solange ein Eigentümer der Organisation ihm keine über die Konsole zugewiesen hat.
+:::
+
+## Pflege der Föderation im Zeitverlauf
+
+Dies ist der wichtigste Punkt: Unabhängig vom Protokoll läuft ein Element ab, und sein Ablauf unterbricht die SSO-Anmeldung __für sämtliche Benutzer__.
+
+### Bei OpenID Connect: das Client Secret
+
+Das Client Secret läuft spätestens 24 Monate nach seiner Erstellung ab. Planen Sie die Erneuerung rechtzeitig:
+
+1. Erstellen Sie unter "Certificates & secrets" ein __neues__ Secret, ohne das alte zu löschen;
+2. übermitteln Sie dessen Wert über den sicheren Kanal an Cloud Temple, indem Sie eine Supportanfrage stellen;
+3. löschen Sie das alte Secret im Azure-Portal, sobald unsere Teams die Umstellung bestätigt haben.
+
+Indem Sie beide Secrets während der Umstellung beibehalten, vermeiden Sie jede Betriebsunterbrechung.
+
+### Bei SAML 2.0: das Signaturzertifikat
+
+Das von EntraID ausgestellte Signaturzertifikat hat eine begrenzte Laufzeit, standardmäßig drei Jahre.
+
+__Informieren Sie uns vor jeder Zertifikatsrotation__ über eine Supportanfrage und halten Sie den von Microsoft vorgesehenen Überlappungszeitraum ein. Falls Sie uns ein Zertifikat als Datei statt der Metadaten-URL übermittelt haben, fügen Sie Ihrer Anfrage das neue Zertifikat bei.
+
+## Bewährte Vorgehensweisen
+
+- __Steuern Sie den Zugriff über Gruppen__ statt über einzelne Benutzer: Der Zugang oder Abgang einer Person wird dann in Ihrem Verzeichnis geregelt, ohne Eingriff in der Konsole.
+- __Aktivieren Sie die Multi-Faktor-Authentifizierung__ für die Anwendung in Ihren EntraID-Richtlinien für bedingten Zugriff: Sie gilt dann auch für den Zugang zur Konsole.
+- __Richten Sie eine Erinnerung__ vor dem Ablaufdatum des Client Secret bzw. des Signaturzertifikats ein, je nach gewähltem Protokoll.
+- __Behalten Sie mindestens ein lokales Eigentümerkonto__ in Ihrer Cloud-Temple-Organisation außerhalb der Föderation, um bei Nichtverfügbarkeit Ihres Verzeichnisses weiterhin Zugang zu haben.
+
+## Fehlerbehebung
+
+| Symptom | Protokoll | Wahrscheinliche Ursache |
+|---|---|---|
+| `AADSTS50011`: Die Redirect-URL stimmt nicht überein | Beide | Die in Azure hinterlegte URL weicht von der durch Cloud Temple bereitgestellten ab. Prüfen Sie sie Zeichen für Zeichen, einschließlich eines fehlenden abschließenden `/`. |
+| `AADSTS700016`: Anwendung nicht gefunden | SAML 2.0 | Die hinterlegte *Entity ID* stimmt nicht mit der von Cloud Temple bereitgestellten überein. |
+| `AADSTS7000215`: ungültiges Secret | OpenID Connect | Das Secret ist abgelaufen, oder es wurde die "Secret ID" statt des "Value" übermittelt. |
+| `AADSTS50105`: Benutzer nicht zugewiesen | Beide | Die Option "Assignment required" ist aktiv und der Benutzer ist der Anwendung nicht zugewiesen. |
+| Die Anmeldeschaltfläche erscheint nicht auf der Seite | Beide | Die Konfiguration ist auf Seite von Cloud Temple noch nicht aktiv. |
+| Der Benutzer wird authentifiziert, die Konsole verweigert jedoch den Zugriff | Beide | Die E-Mail-Adresse fehlt im Token, oder dem Benutzer wurden keine Rechte zugewiesen. |
+| Der Benutzer erscheint bei jeder Anmeldung als neues Konto | SAML 2.0 | Die NameID ist nicht auf `user.objectid` gesetzt. |
+| Signaturfehler bei der Ankunft in der Konsole | SAML 2.0 | Das Signaturzertifikat wurde auf Azure-Seite erneuert, ohne dass wir informiert wurden. |
+
+## Support
+
+Bei Fragen zu diesem Vorgehen stellen Sie bitte eine Supportanfrage über Ihre Konsole. Geben Sie den Namen Ihrer Organisation sowie den Zeitstempel eines fehlgeschlagenen Anmeldeversuchs an: So lässt sich der entsprechende Eintrag auffinden.
diff --git a/i18n/en/docusaurus-plugin-content-docs/current/console/iam/iam.md b/i18n/en/docusaurus-plugin-content-docs/current/console/iam/iam.md
index fdc7d20d..8f661561 100644
--- a/i18n/en/docusaurus-plugin-content-docs/current/console/iam/iam.md
+++ b/i18n/en/docusaurus-plugin-content-docs/current/console/iam/iam.md
@@ -21,6 +21,6 @@ It enables the administration of local accounts while supporting hybrid configur
\ No newline at end of file
diff --git a/i18n/en/docusaurus-plugin-content-docs/current/console/iam/tutorials/sso_azuread.md b/i18n/en/docusaurus-plugin-content-docs/current/console/iam/tutorials/sso_azuread.md
index 33ce4ebd..0307863e 100644
--- a/i18n/en/docusaurus-plugin-content-docs/current/console/iam/tutorials/sso_azuread.md
+++ b/i18n/en/docusaurus-plugin-content-docs/current/console/iam/tutorials/sso_azuread.md
@@ -1,5 +1,5 @@
---
-title: Identity Federation Example with Microsoft EntraID
+title: Identity Federation Example with Microsoft EntraID (Azure AD)
tags:
- iam
- tutorials
@@ -23,136 +23,305 @@ import ssoAad_016 from '@site/docs/console/iam/tutorials/images/sso_aad_016.png'
import ssoAad_017 from '@site/docs/console/iam/tutorials/images/sso_aad_017.png'
import ssoAad_018 from '@site/docs/console/iam/tutorials/images/sso_aad_018.png'
-Here is an example configuration of the identity provider for a Cloud Temple organization using __Microsoft EntraID__ (Azure Active Directory).
+Here is an example configuration of the identity provider for a Cloud Temple organization using __Microsoft EntraID__.
-Configuring your Microsoft identity provider at the Cloud Temple organization level simplifies user authentication on the Console. This helps avoid the proliferation of authentication factors and reduces the attack surface.
+Configuring your Microsoft identity provider at the Cloud Temple organization level simplifies user authentication on the Console. This helps avoid the proliferation of authentication factors and reduces the attack surface. If your users are already authenticated to their Microsoft accounts, logging into the Console services will be seamless.
-If your users are already authenticated to their Microsoft accounts, logging into the Console services will be seamless and transparent.
+:::info[Azure AD and Microsoft EntraID]
+Microsoft EntraID is the new name of Azure Active Directory (Azure AD) since 2023. It is the same product: this tutorial applies to both names interchangeably.
+:::
-Below are the steps to complete this configuration:
+## Choosing the protocol
-## Step 1: SSO Configuration on Microsoft Azure Side
+Federation with EntraID can be set up using either of the two standard protocols. Both offer an equivalent level of security; they differ mainly in what you need to send us and in what has to be maintained over time.
-### Registering a New Azure Application (Azure Portal)
+| | OpenID Connect | SAML 2.0 |
+|---|---|---|
+| What you send us | Two identifiers and a secret | A public metadata URL |
+| Secret exchanged | Yes, the client secret | None |
+| To maintain over time | The client secret (24 months maximum) | The signing certificate (3 years by default) |
-To create the __app registration__, navigate to the Microsoft Azure portal, then go to Microsoft Entra ID, and select __"Add > App Registration"__.
+__Unless you have a specific constraint, we recommend OpenID Connect__: it is the protocol we deploy by default. Choose SAML if your internal policy requires it, or if your directory is connected to a federation hub that only speaks that protocol.
-On the "Register an application" page, please provide the following:
+State the protocol you have chosen when you open your support request.
+
+## Information exchanged
+
+Setting up the federation relies on a two-way exchange. Here are the details upfront, so you can prepare everything in a single pass.
+
+### What you need to send us — with OpenID Connect
+
+| Information | Name in the Azure portal | What it is used for |
+|---|---|---|
+| __Application (client) ID__ | *Application (client) ID* | Identifies the application to EntraID |
+| __Directory (tenant) ID__ | *Directory (tenant) ID* | Determines the OpenID Connect endpoints of your directory |
+| __Client secret__ | *Client secret* → __Value__ column | Authenticates the Console to EntraID |
+
+Both identifiers appear in the __"Overview"__ tab of your app registration; the secret is created in the __"Certificates & secrets"__ tab.
+
+### What you need to send us — with SAML 2.0
+
+A single piece of information is enough in the usual case:
+
+| Information | Name in the Azure portal | What it is used for |
+|---|---|---|
+| __Federation metadata URL__ | *App Federation Metadata Url* | We derive from it your directory identifier, its endpoints and its signing certificate |
+
+It takes the following form:
```
-- __Name__ : Enter "__SHIVA__"
-- __Supported account types__ : __Accounts in this organizational directory only__ (____ only - Single tenant)
-- __Redirect URL__ : Do not configure this field at this time. The URL will be provided by Cloud Temple support and should be added to this field later.
+https://login.microsoftonline.com//federationmetadata/2007-06/federationmetadata.xml?appid=
+```
+
+You will find it under __"Enterprise applications"__ → your application → __"Single sign-on"__, in the *SAML Certificates* section. It is public and contains no secret: it may appear in the body of your request.
+
+:::tip[Why this URL rather than a list of parameters]
+It gathers all your directory parameters into a single value and simplifies tracking the renewal of your signing certificate. If this URL is not reachable from the internet, send instead the *Identity provider entity ID*, the *Single Sign-On service URL*, the *Single Logout service URL* and the signing certificate in __Certificate (Base64)__ format.
+:::
+
+:::warning[Never send the secret in the body of a request]
+The client secret value is an authentication credential. Do not place it in the body of a support request, in a comment, or in an unencrypted attachment: it would remain readable there permanently.
+
+State in your request that you have the secret, and send it through the secure channel your Cloud Temple contact will indicate. Both identifiers (Application ID and Directory ID) are not sensitive and may appear in the request.
+:::
+
+### What Cloud Temple sends you
+
+Values specific to your organization, to be declared in your EntraID application:
+
+| Our term | Microsoft term | Protocol |
+|---|---|---|
+| Redirect URL | *Redirect URL* | OpenID Connect |
+| Redirect URL | *Reply URL (Assertion Consumer Service URL)* | SAML 2.0 |
+| Service provider identifier | *Identifier (Entity ID)* | SAML 2.0 |
+
+:::tip[Ask for them when you open your request]
+These values depend on your organization and cannot be guessed. By requesting them when you open your support request, you can complete the entire Azure configuration in one pass, without having to come back to it.
+:::
+
+## Step 1: SSO configuration on the Microsoft EntraID side
+
+Follow the section matching the protocol you have chosen, then the "Additional security settings" section, which is common to both.
+
+### OpenID Connect path
+
+#### Registering a new Azure application (Azure portal)
+
+To create the __app registration__, go to the Microsoft Azure portal, then in Microsoft EntraID, __"ADD > App Registration"__.
+
+On the "Register an application" page, provide the following:
+
+```
+- Name: enter "SHIVA"
+- Supported account types: Accounts in this organizational directory only ( only - Single tenant)
+- Redirect URL: enter the URL provided by Cloud Temple. If you do not have it yet, leave the field empty and refer to step 3.
```
-The __Application (client) ID__ and __Directory (tenant) ID__ are the key details to provide in your support request to the Cloud Temple team to enable Microsoft Entra ID authentication for your organization.
+The __Application (client) ID__ and __Directory (tenant) ID__ are displayed on the "Overview" tab. Make a note of them: these are two of the three pieces of information to provide in your support request.
-### Definition of a Secret
+#### Creating a secret
In the "Certificates & secrets" tab, create a new secret.
-*Note: The secret's expiration date cannot exceed 24 months, even with a custom expiration date.*
-
-The generated secret will need to be provided in the support request:
+:::warning[Copy the value immediately]
+The secret value is displayed only once, right after it is created. Copy the contents of the __"Value"__ column, not the __"Secret ID"__ column. If you lose this value, you will have to generate a new secret.
+:::
-### Definition of EntraID Token
+:::caution[Validity limited to 24 months]
+The secret expiry date cannot exceed 24 months, even with a custom expiry date. __Make a note of this date now__: once it is reached, SSO will stop working for all your users. See the [Maintaining the federation over time](#maintaining-the-federation-over-time) section.
+:::
+
+#### Authorising the information used by the Console
-The EntraID token is required for authentication configuration.
+The Console identifies your users from the information carried by the identity token. Only one action is required on your side: __exposing the email address__.
-In the _*"Token Configuration"* menu, click on __"Add optional claim"__. You will need to select "ID" as the token type and check "email".
+In the __"Token Configuration"__ menu, click __"Add optional claim"__. Select "ID" as the token type and tick "email".
-Azure will prompt you to grant a permission allowing you to read a user's email (Microsoft Graph email). Check the box and confirm.
+The Azure interface asks whether you want to add a permission allowing it to read a user's email (Microsoft Graph email). Tick the box and confirm.
-Next, go to "API permissions" and click on __"Grant admin consent for Cloud Temple"__.
+Then go to "API permissions" and click __"Grant admin consent for <your organization>"__.
-### Additional Security Configurations (Optional but Recommended)
+For reference, here is all the information consumed by the Console:
+
+| Information | Usage | Action on your side |
+|---|---|---|
+| `email` | User's sign-in address | __Yes__ — must be declared as an optional claim (above) |
+| `oid` | Stable link between the Console account and the identity in your directory, even if the email address changes | None — issued natively by EntraID |
+| `given_name`, `family_name` | First name and last name shown in the Console | None — included in the `profile` scope |
+
+### SAML 2.0 path
+
+#### Creating the enterprise application
-By default, Microsoft Entra ID, as configured, will allow any user from your Azure tenant to sign in to your Cloud Temple organization.
-It is possible to restrict access at the __"App Registration"__ level, allowing only a specific list of users or groups to sign in to your Cloud Temple organization.
+In __Microsoft EntraID__, go to __"Enterprise applications"__, then __"New application"__. Choose __"Create your own application"__, name it, and select *Integrate any other application you don't find in the gallery (Non-gallery)*. Confirm with __"Create"__.
-Follow the procedure below:
+#### Configuring single sign-on
-#### Access additional "App Registration" settings
+In your application, open __"Single sign-on"__ and choose __"SAML"__. In __"Basic SAML Configuration"__, click __"Edit"__ and fill in the values provided by Cloud Temple:
+
+- __Identifier (Entity ID)__;
+- __Reply URL (Assertion Consumer Service URL)__.
+
+Save.
+
+#### Attributes and claims
+
+EntraID issues by default the claims expected by the Console. Check that they are present under __"Attributes & Claims"__:
+
+| Claim | Usage | Action on your side |
+|---|---|---|
+| `…/claims/emailaddress` | User's sign-in address | None — source `user.mail` |
+| `http://schemas.microsoft.com/identity/claims/objectidentifier` | Stable link between the Console account and the identity in your directory | None |
+| `…/claims/givenname`, `…/claims/surname` | First name and last name shown in the Console | None |
+
+:::warning[Name identifier (NameID): the most commonly missed step]
+Under __"Attributes & Claims"__ → __"Unique User Identifier (Name ID)"__, set the source to __user.objectid__ and the format to __Persistent__.
+
+By default, EntraID issues the email address as the NameID. If a user's address changes, the Console would treat them as a different person and they would lose their permissions. The object identifier, by contrast, never changes.
+:::
+
+### Additional security settings (optional but recommended)
+
+By default, Microsoft EntraID as configured will allow any user of your Azure tenant to sign in to your Cloud Temple organization. You can restrict access at the __"App Registration"__ level so that only a list of users or groups is authorised.
+
+Here is the procedure to follow.
+
+#### Accessing the additional "App Registration" settings
##### Option 1
-Go to the "Overview" tab, then click on the application name (the link located next to "Managed application").
+Go to the "Overview" tab, then click the application name (the link next to "Managed application").
##### Option 2
-Go to "Enterprise applications" and search using the name of the previously created application.
+Go to "Enterprise applications" and search using the name of the application created earlier.
-#### Authentication restriction to users assigned to the application
+#### Restricting authentication to users assigned to the application
-Indicate here the requirement for user assignment to the application to allow authentication:
+Specify here that a user must be assigned to the application in order to authenticate:
-#### Assigning Users and Groups to the Application
+#### Assigning users and groups to the application
-Only users and groups assigned to the application will be able to sign in to your Cloud Temple organization via the app registration.
+Only the groups and users assigned to the application will be able to sign in to your Cloud Temple organization through the app registration.
-Finally, simply apply the assignment by clicking "Assign".
+Finally, apply the assignment by clicking "Assign".
-From now on, assigned users will be able to sign in to your Cloud Temple organization through the created application.
+Users assigned to the application can now sign in to your Cloud Temple organization through the application you created.
+
+## Step 2: Requesting the SSO configuration for your organization
-## Step 2: Request SSO (Single Sign-On) Configuration for Your Organization
+This part of the configuration is carried out at the organization level by the Cloud Temple team.
-This configuration step is performed at the organization level by the Cloud Temple team.
+To do so, submit __a support request__ in the Console stating that you wish to configure Microsoft EntraID federation, specifying:
-To proceed, submit a __support request__ in the console indicating your intent to set up Microsoft Entra ID SSO.
+- your organization name;
+- __the protocol you have chosen__: OpenID Connect or SAML 2.0;
+- the name of a contact, with their email address and phone number, to finalise the configuration;
+- __with OpenID Connect__: the __Application (client) ID__ and the __Directory (tenant) ID__ noted in step 1;
+- __with SAML 2.0__: the __federation metadata URL__ of your application.
-Please include the following information in your support request:
+With OpenID Connect, send the __client secret__ through the secure channel indicated by your contact, not in the body of the request. With SAML, no secret is exchanged.
-- Name of your Organization
-- Name of a contact person, along with their email address and phone number, to finalize the configuration
-- Application ID (unique identifier associated with the previously created application)
-- Directory ID (corresponds to the Azure AD tenant ID in Azure)
-- Secret (secret associated with the previously created application)
+Once the configuration is complete on the Console side, the contact you provided will be informed.
-Once the configuration is completed on the Console side, the designated contact will be notified.
+## Step 3: Declaring the "Redirect URL" (OpenID Connect)
-## Step 3: Finalize the Configuration
+If you did not enter the "Redirect URL" when creating the application, add it now.
-On the App Registration home page, in the Overview menu, click on "Add a Redirect URL".
+With SAML 2.0, the equivalent URLs were already declared under __"Basic SAML Configuration"__ in step 1: go straight to step 4.
+
+On the App Registration home page, in the "Overview" menu, click "Add a Redirect URL".
-Next, go to "Add a platform" and add one of type Web.
+Then go to "Add a platform" and add one of type Web.
-Simply enter the "Redirect URL" provided by the Applications Product Team.
+Enter the "Redirect URL" provided by Cloud Temple.
-You should see this result once the "Redirect URL" has been added.
+You should get this result once the "Redirect URL" has been added.
-It may take a few minutes for the "Redirect URL" configuration to take effect.
-Once all steps are completed, you can authenticate to your Cloud Temple organization using your SSO.
+The "Redirect URL" configuration may take a few minutes to take effect.
+
+## Step 4: Verification
+
+Once all the steps are complete, you can authenticate to your Cloud Temple organization through your SSO.
+
+:::info[Permissions for new users]
+Identity federation handles __authentication__, not __authorisation__. A user signing in for the first time through SSO has no permissions until an organization owner grants them from the Console.
+:::
+
+## Maintaining the federation over time
+
+This is the main point to watch: whatever the protocol, one element expires, and its expiry interrupts SSO __for all your users__.
+
+### With OpenID Connect: the client secret
+
+The client secret expires no later than 24 months after it is created. Plan its renewal ahead:
+
+1. in "Certificates & secrets", create a __new__ secret without deleting the old one;
+2. send its value to Cloud Temple through the secure channel, by opening a support request;
+3. once our teams confirm the switchover, delete the old secret from the Azure portal.
+
+Keeping both secrets during the switchover avoids any service interruption.
+
+### With SAML 2.0: the signing certificate
+
+The signing certificate issued by EntraID has a limited lifetime, three years by default.
+
+__Let us know before any certificate rotation__, through a support request, respecting the overlap period offered by Microsoft. If you sent us a certificate as a file rather than the metadata URL, attach the new certificate to your request.
+
+## Best practices
+
+- __Manage access through groups__ rather than individual users: a colleague joining or leaving is then handled in your directory, with no action needed on the Console.
+- __Enable multi-factor authentication__ on the application in your EntraID conditional access policies: it then applies to Console access.
+- __Set a reminder__ ahead of the expiry date of the client secret or the signing certificate, depending on the protocol chosen.
+- __Keep at least one local owner account__ on your Cloud Temple organization, outside the federation, so you retain access if your directory becomes unavailable.
+
+## Troubleshooting
+
+| Symptom | Protocol | Likely cause |
+|---|---|---|
+| `AADSTS50011`: redirect URL mismatch | Both | The URL declared in Azure differs from the one provided by Cloud Temple. Check it character by character, including the absence of a trailing `/`. |
+| `AADSTS700016`: application not found | SAML 2.0 | The *Entity ID* declared does not match the one provided by Cloud Temple. |
+| `AADSTS7000215`: invalid secret | OpenID Connect | The secret has expired, or the value sent was the "Secret ID" instead of the "Value". |
+| `AADSTS50105`: user not assigned | Both | The "Assignment required" option is enabled and the user is not assigned to the application. |
+| The sign-in button does not appear on the page | Both | The configuration is not yet active on the Cloud Temple side. |
+| The user authenticates but the Console denies access | Both | The email address is missing from the token, or no permissions have been granted to the user. |
+| The user appears as a new account at every sign-in | SAML 2.0 | The NameID is not set to `user.objectid`. |
+| Signature error on arrival at the Console | SAML 2.0 | The signing certificate was renewed on the Azure side without us being informed. |
+
+## Support
+
+For any question about this procedure, open a support request from your Console. Specify your organization name and the timestamp of a failed sign-in attempt: this allows the corresponding trace to be located.
diff --git a/i18n/es/docusaurus-plugin-content-docs/current/console/iam/iam.md b/i18n/es/docusaurus-plugin-content-docs/current/console/iam/iam.md
index 1db02a43..13ae1e1f 100644
--- a/i18n/es/docusaurus-plugin-content-docs/current/console/iam/iam.md
+++ b/i18n/es/docusaurus-plugin-content-docs/current/console/iam/iam.md
@@ -21,6 +21,6 @@ Permite administrar cuentas locales al tiempo que admite la hibridación con con
\ No newline at end of file
diff --git a/i18n/es/docusaurus-plugin-content-docs/current/console/iam/tutorials/sso_azuread.md b/i18n/es/docusaurus-plugin-content-docs/current/console/iam/tutorials/sso_azuread.md
index e1a0fbc9..6bd7ffa6 100644
--- a/i18n/es/docusaurus-plugin-content-docs/current/console/iam/tutorials/sso_azuread.md
+++ b/i18n/es/docusaurus-plugin-content-docs/current/console/iam/tutorials/sso_azuread.md
@@ -1,5 +1,5 @@
---
-title: Example of Identity Federation with Microsoft EntraID
+title: Ejemplo de federación de identidad con Microsoft EntraID (Azure AD)
tags:
- iam
- tutorials
@@ -23,139 +23,305 @@ import ssoAad_016 from '@site/docs/console/iam/tutorials/images/sso_aad_016.png'
import ssoAad_017 from '@site/docs/console/iam/tutorials/images/sso_aad_017.png'
import ssoAad_018 from '@site/docs/console/iam/tutorials/images/sso_aad_018.png'
-Here is an example configuration of the authentication repository for a Cloud Temple organization using __Microsoft EntraID__ (Azure Active Directory).
+A continuación se presenta un ejemplo de configuración del repositorio de autenticación de una organización Cloud Temple con __Microsoft EntraID__.
-Configuring your Microsoft EntraID repository at the Cloud Temple organization level simplifies user authentication on the Console. This helps avoid the proliferation of authentication factors and reduces the attack surface.
+La configuración de su repositorio Microsoft a nivel de una organización Cloud Temple facilita la autenticación de sus usuarios en la Consola. Esto permite evitar la multiplicación de factores de autenticación y reducir la superficie de ataque. Si sus usuarios ya están autenticados en su cuenta Microsoft, la autenticación en los servicios de la Consola será transparente.
-If your users are already authenticated to their Microsoft accounts, logging into the Console services will be seamless and transparent.
+:::info[Azure AD y Microsoft EntraID]
+Microsoft EntraID es el nuevo nombre de Azure Active Directory (Azure AD) desde 2023. Se trata del mismo producto: este tutorial se aplica indistintamente a ambas denominaciones.
+:::
-Below are the steps to complete this configuration:
+## Elegir el protocolo
-## Step 1: SSO configuration on Microsoft Azure side
+La federación con EntraID puede realizarse con cualquiera de los dos protocolos estándar. Ambos ofrecen un nivel de seguridad equivalente; se diferencian principalmente en lo que debe transmitirnos y en lo que habrá que mantener a lo largo del tiempo.
-### Registro de una nueva aplicación Azure (portal Azure)
+| | OpenID Connect | SAML 2.0 |
+|---|---|---|
+| Lo que nos transmite | Dos identificadores y un secreto | Una URL de metadatos pública |
+| Secreto intercambiado | Sí, el secreto de cliente | Ninguno |
+| A mantener en el tiempo | El secreto de cliente (24 meses máximo) | El certificado de firma (3 años por defecto) |
-Para la creación del __registro de aplicación__, debe acceder al portal Microsoft Azure, y luego a Microsoft Entra ID, seleccionando __"Agregar > Registro de aplicación"__.
+__Salvo restricción específica, recomendamos OpenID Connect__: es el protocolo que desplegamos de forma predeterminada. Opte por SAML si su política interna lo impone, o si su directorio está conectado a un concentrador de federación que solo admite ese protocolo.
-En la página "Registrar una aplicación", indique lo siguiente:
+Indique el protocolo elegido al abrir su solicitud de asistencia.
+
+## Información intercambiada
+
+La implementación se basa en un intercambio en ambos sentidos. Estos son los detalles desde el principio, para que pueda prepararlo todo de una sola vez.
+
+### Lo que debe transmitirnos — con OpenID Connect
+
+| Información | Nombre en el portal de Azure | Para qué sirve |
+|---|---|---|
+| __Application (client) ID__ | *Application (client) ID* | Identifica la aplicación ante EntraID |
+| __Directory (tenant) ID__ | *Directory (tenant) ID* | Determina los puntos de conexión OpenID Connect de su directorio |
+| __Secreto de cliente__ | *Client secret* → columna __Value__ | Autentica la Consola ante EntraID |
+
+Ambos identificadores figuran en la pestaña __"Overview"__ de su registro de aplicación; el secreto se crea en la pestaña __"Certificates & secrets"__.
+
+### Lo que debe transmitirnos — con SAML 2.0
+
+Una sola información basta en el caso habitual:
+
+| Información | Nombre en el portal de Azure | Para qué sirve |
+|---|---|---|
+| __URL de los metadatos de federación__ | *App Federation Metadata Url* | De ella derivamos el identificador de su directorio, sus puntos de conexión y su certificado de firma |
+
+Se presenta de la siguiente forma:
```
-- __Nombre__: Escriba "__SHIVA__"
-- __Tipos de cuentas compatibles__: __Cuentas solo en este directorio organizativo__ (____ solo - de un solo inquilino)
-- __URL de redirección__: No configurar en este momento. La URL será proporcionada por el soporte de Cloud Temple y se deberá añadir en este campo más adelante.
+https://login.microsoftonline.com//federationmetadata/2007-06/federationmetadata.xml?appid=
```
-
+La encontrará en __"Enterprise applications"__ → su aplicación → __"Single sign-on"__, sección *SAML Certificates*. Es pública y no contiene ningún secreto: puede figurar en el cuerpo de su solicitud.
+
+:::tip[Por qué esta URL en lugar de una lista de parámetros]
+Reúne en un solo valor el conjunto de parámetros de su directorio y simplifica el seguimiento de la renovación de su certificado de firma. Si esta URL no es accesible desde Internet, transmita en su lugar el *Identity provider entity ID*, la *Single Sign-On service URL*, la *Single Logout service URL* y el certificado de firma en formato __Certificate (Base64)__.
+:::
+
+:::warning[Nunca transmita el secreto en el cuerpo de una solicitud]
+El valor del secreto de cliente es una credencial de autenticación. No lo incluya en el cuerpo de una solicitud de asistencia, ni en un comentario, ni en un archivo adjunto sin cifrar: permanecería allí consultable de forma duradera.
+
+Indique en su solicitud que dispone del secreto y transmítalo por el canal seguro que le indicará su contacto de Cloud Temple. Los dos identificadores (Application ID y Directory ID) no son sensibles y sí pueden figurar en la solicitud.
+:::
+
+### Lo que Cloud Temple le transmite
+
+Valores propios de su organización, que debe declarar en su aplicación EntraID:
+
+| Nuestro término | Término de Microsoft | Protocolo |
+|---|---|---|
+| URL de redirección | *Redirect URL* | OpenID Connect |
+| URL de redirección | *Reply URL (Assertion Consumer Service URL)* | SAML 2.0 |
+| Identificador del proveedor de servicio | *Identifier (Entity ID)* | SAML 2.0 |
-Las siguientes informaciones son las que deben proporcionarse en la solicitud de soporte a la equipe Cloud Temple para habilitar la autenticación de Microsoft Entra ID a nivel de su organización:
+:::tip[Solicítelos al abrir su petición]
+Estos valores dependen de su organización y no pueden deducirse. Al solicitarlos en el momento de abrir su solicitud de asistencia, podrá realizar toda la configuración de Azure de una sola vez, sin tener que volver sobre ella.
+:::
-- __Application (client) ID__
-- __Directory (tenant) ID__
+## Paso 1: Configuración del SSO en el lado de Microsoft EntraID
+
+Siga la sección correspondiente al protocolo elegido y, a continuación, la sección «Configuraciones de seguridad adicionales», común a ambos.
+
+### Vía OpenID Connect
+
+#### Registro de una nueva aplicación de Azure (portal de Azure)
+
+Para crear el __app registration__, diríjase al portal de Microsoft Azure y, a continuación, en Microsoft EntraID, __"ADD > App Registration"__.
+
+En la página "Register an application", indique lo siguiente:
+
+```
+- Name: indicar "SHIVA"
+- Supported account types: Accounts in this organizational directory only ( only - Single tenant)
+- Redirect URL: indicar la URL proporcionada por Cloud Temple. Si aún no dispone de ella, deje el campo vacío y consulte el paso 3.
+```
+
+
+
+Los datos __Application (client) ID__ y __Directory (tenant) ID__ se muestran en la pestaña "Overview". Anótelos: son dos de las tres informaciones que deberá facilitar en su solicitud de asistencia.
-### Definición de un secreto
+#### Definición de un secreto
En la pestaña "Certificates & secrets", cree un nuevo secreto.
-*Nota: la fecha de expiración del secreto no puede ser superior a 24 meses, incluso con una fecha de expiración personalizada.*
-
-El secreto generado deberá proporcionarse en la solicitud de soporte:
+:::warning[Copie el valor inmediatamente]
+El valor del secreto solo se muestra una vez, justo después de su creación. Copie el contenido de la columna __"Value"__, y no el de la columna __"Secret ID"__. Si pierde este valor, deberá generar un nuevo secreto.
+:::
-### Definición del token EntraID
+:::caution[Validez limitada a 24 meses]
+La fecha de expiración del secreto no puede ser superior a 24 meses, incluso con una fecha de expiración personalizada. __Anote esta fecha desde ahora__: al alcanzarla, la conexión SSO dejará de funcionar para todos sus usuarios. Consulte la sección [Mantenimiento de la federación a lo largo del tiempo](#mantenimiento-de-la-federación-a-lo-largo-del-tiempo).
+:::
-El token EntraID es necesario para la configuración de la autenticación.
+#### Autorización de la información utilizada por la Consola
-En el menú __"Configuración de token"__, haga clic en __"Agregar afirmación opcional"__. Deberá seleccionar "ID" como tipo de token y marcar la opción "email".
+La Consola identifica a sus usuarios a partir de la información transportada por el token de identidad. Solo se requiere una acción por su parte: __exponer la dirección de correo electrónico__.
+
+En el menú __"Token Configuration"__, haga clic en __"Add optional claim"__. Seleccione "ID" como tipo de token y marque "email".
-La interfaz de Azure le preguntará si desea agregar un permiso que le permitirá leer el correo electrónico de un usuario (correo electrónico de Microsoft Graph); marque la casilla y confirme.
+La interfaz de Azure le preguntará si desea añadir un permiso que permita leer el correo electrónico de un usuario (Microsoft Graph email). Marque la casilla y valide.
-A continuación, vaya a "Permisos de API" y haga clic en __"Conceder consentimiento de administrador para Cloud Temple"__.
+A continuación, diríjase a "API permissions" y haga clic en __"Grant admin consent for <su organización>"__.
-### Additional security configurations (optional but recommended)
+A título informativo, esta es toda la información consumida por la Consola:
+
+| Información | Uso | Acción por su parte |
+|---|---|---|
+| `email` | Dirección de conexión del usuario | __Sí__ — debe declararse como claim opcional (más arriba) |
+| `oid` | Vinculación estable de la cuenta de la Consola con la identidad de su directorio, incluso si cambia la dirección de correo | Ninguna — emitido de forma nativa por EntraID |
+| `given_name`, `family_name` | Nombre y apellidos mostrados en la Consola | Ninguna — incluidos en el ámbito `profile` |
+
+### Vía SAML 2.0
+
+#### Creación de la aplicación empresarial
-By default, Microsoft Entra ID, as configured, will allow any user in your Azure tenant to sign in to your Cloud Temple organization.
-It is possible to restrict access at the __"App Registration"__ level, allowing only a specific list of users or groups to sign in to your Cloud Temple organization.
+En __Microsoft EntraID__, diríjase a __"Enterprise applications"__ y luego a __"New application"__. Elija __"Create your own application"__, asígnele un nombre y seleccione *Integrate any other application you don't find in the gallery (Non-gallery)*. Valide con __"Create"__.
-Follow these steps:
+#### Configuración del inicio de sesión único
-#### Access additional "App Registration" settings
+En su aplicación, abra __"Single sign-on"__ y elija __"SAML"__. En __"Basic SAML Configuration"__, haga clic en __"Edit"__ e indique los valores proporcionados por Cloud Temple:
+
+- __Identifier (Entity ID)__;
+- __Reply URL (Assertion Consumer Service URL)__.
+
+Guarde.
+
+#### Atributos y notificaciones
+
+EntraID emite de forma predeterminada las notificaciones esperadas por la Consola. Compruebe su presencia en __"Attributes & Claims"__:
+
+| Notificación | Uso | Acción por su parte |
+|---|---|---|
+| `…/claims/emailaddress` | Dirección de conexión del usuario | Ninguna — origen `user.mail` |
+| `http://schemas.microsoft.com/identity/claims/objectidentifier` | Vinculación estable de la cuenta de la Consola con la identidad de su directorio | Ninguna |
+| `…/claims/givenname`, `…/claims/surname` | Nombre y apellidos mostrados en la Consola | Ninguna |
+
+:::warning[Identificador de nombre (NameID): el punto que más se olvida]
+En __"Attributes & Claims"__ → __"Unique User Identifier (Name ID)"__, establezca el origen en __user.objectid__ y el formato en __Persistent__.
+
+De forma predeterminada, EntraID emite la dirección de correo electrónico como NameID. Si un usuario cambia de dirección, la Consola lo trataría como una persona distinta y perdería sus permisos. El identificador de objeto, en cambio, nunca cambia.
+:::
+
+### Configuraciones de seguridad adicionales (opcional pero recomendado)
+
+De forma predeterminada, Microsoft EntraID tal como está configurado permitirá que cualquier usuario de su tenant de Azure se conecte a su organización Cloud Temple. Es posible restringir los accesos a nivel de __"App Registration"__ para autorizar únicamente a una lista de usuarios o grupos.
+
+Este es el procedimiento a seguir.
+
+#### Acceder a los parámetros adicionales de "App Registration"
##### Opción 1
-Vaya a la pestaña "Información general" y haga clic en el nombre de la aplicación (el enlace situado después de "Aplicación administrada").
+Vaya a la pestaña "Overview" y haga clic en el nombre de la aplicación (el enlace situado a continuación de "Managed application").
##### Opción 2
-Diríjase a "Aplicaciones empresariales" y busque utilizando el nombre de la aplicación creada anteriormente.
+Diríjase a "Enterprise applications" y busque utilizando el nombre de la aplicación creada anteriormente.
-#### Authentication restriction to users assigned to the application
+#### Restricción de la autenticación a los usuarios asignados a la aplicación
-Indicate here the requirement for user assignment to the application to allow authentication:
+Indique aquí la necesidad de una asignación del usuario a la aplicación para autorizar su autenticación:
-#### Assigning users and groups to the application
+#### Asignación de usuarios y grupos a la aplicación
-Only the users and groups assigned to the application will be able to sign in to your Cloud Temple organization via the app registration.
+Solo los grupos y usuarios asignados a la aplicación podrán conectarse a su organización Cloud Temple mediante el app registration.
-Finally, you will only need to apply the assignment by clicking on "Assign".
+Por último, aplique la asignación haciendo clic en "Assign".
-From now on, the assigned users will be able to sign in to your Cloud Temple organization through the created application.
+A partir de ahora, los usuarios asignados a la aplicación podrán conectarse a su organización Cloud Temple mediante la aplicación creada.
+
+## Paso 2: Solicitar la configuración del SSO de su organización
-## Step 2: Request your organization's SSO (Single Sign-On) configuration
+Esta parte de la configuración se realiza a nivel de la organización por parte del equipo de Cloud Temple.
-This configuration step is performed at the organization level by the Cloud Temple team.
+Para ello, presente __una solicitud de asistencia__ en la Consola indicando su deseo de configurar una federación Microsoft EntraID, precisando:
-To proceed, please __submit a support request__ in the console indicating your intention to set up Microsoft Entra ID SSO.
+- el nombre de su organización;
+- __el protocolo elegido__: OpenID Connect o SAML 2.0;
+- el nombre de un contacto, con su correo electrónico y número de teléfono, para finalizar la configuración;
+- __con OpenID Connect__: el __Application (client) ID__ y el __Directory (tenant) ID__ anotados en el paso 1;
+- __con SAML 2.0__: la __URL de los metadatos de federación__ de su aplicación.
-Include the following information in your support request:
+Con OpenID Connect, transmita el __secreto de cliente__ por el canal seguro indicado por su contacto, y no en el cuerpo de la solicitud. Con SAML, no se intercambia ningún secreto.
-- Name of your Organization
-- Name of a contact person, along with their email address and phone number, to finalize the configuration
-- Application ID (unique identifier associated with the previously created application)
-- Directory ID (corresponds to the Azure AD tenant ID in Azure)
-- Secret (secret associated with the previously created application)
+En cuanto la configuración se realice en el lado de la Consola, se informará al contacto indicado.
-Once the configuration is completed on the Console side, the designated contact will be notified.
+## Paso 3: Declaración de la "Redirect URL" (OpenID Connect)
-## Paso 3: Finalización de la configuración
+Si no indicó la "Redirect URL" durante la creación de la aplicación, añádala ahora.
-En la página principal del registro de aplicaciones, en el menú Overview, haga clic en "Add a Redirect URL".
+Con SAML 2.0, las URL equivalentes ya se declararon en __"Basic SAML Configuration"__ en el paso 1: pase directamente al paso 4.
+
+En la página de inicio del App Registration, en el menú "Overview", haga clic en "Add a Redirect URL".
-A continuación, vaya al apartado "Add a platform" y agregue una plataforma del tipo Web.
+A continuación, diríjase a "Add a platform" y añada una de tipo Web.
-Solo necesita rellenar la "Redirect URL" proporcionada por el equipo de Productos de Aplicaciones.
+Indique la "Redirect URL" proporcionada por Cloud Temple.
-Una vez añadida la "Redirect URL", debería obtener este resultado.
+Debería obtener este resultado una vez añadida la "Redirect URL".
-La configuración de la "Redirect URL" puede tardar unos minutos en aplicarse.
-Una vez completados todos los pasos, podrá autenticarse en su organización Cloud Temple mediante su SSO.
+La configuración de la "Redirect URL" puede tardar unos minutos en ser efectiva.
+
+## Paso 4: Verificación
+
+Una vez realizados todos los pasos, puede autenticarse en su organización Cloud Temple mediante su SSO.
+
+:::info[Permisos de los nuevos usuarios]
+La federación de identidad gestiona __la autenticación__, no las __autorizaciones__. Un usuario que se conecta por primera vez mediante el SSO no dispone de ningún permiso mientras un propietario de la organización no se lo haya atribuido desde la Consola.
+:::
+
+## Mantenimiento de la federación a lo largo del tiempo
+
+Este es el principal punto de vigilancia: sea cual sea el protocolo, un elemento expira, y su expiración interrumpe el SSO __para todos sus usuarios__.
+
+### Con OpenID Connect: el secreto de cliente
+
+El secreto de cliente expira como máximo 24 meses después de su creación. Anticipe su renovación:
+
+1. en "Certificates & secrets", cree un __nuevo__ secreto sin eliminar el anterior;
+2. transmita su valor a Cloud Temple por el canal seguro, abriendo una solicitud de asistencia;
+3. una vez confirmada la conmutación por nuestros equipos, elimine el antiguo secreto desde el portal de Azure.
+
+Conservar ambos secretos durante la conmutación evita cualquier interrupción del servicio.
+
+### Con SAML 2.0: el certificado de firma
+
+El certificado de firma emitido por EntraID tiene una vida útil limitada, de tres años por defecto.
+
+__Avísenos antes de cualquier rotación de certificado__, mediante una solicitud de asistencia, respetando el periodo de solapamiento propuesto por Microsoft. Si nos transmitió un certificado en forma de archivo en lugar de la URL de metadatos, adjunte el nuevo certificado a su solicitud.
+
+## Buenas prácticas
+
+- __Gestione el acceso por grupos__ en lugar de por usuarios: la llegada o salida de un colaborador se trata entonces en su directorio, sin intervención en la Consola.
+- __Active la autenticación multifactor__ en la aplicación desde sus directivas de acceso condicional de EntraID: se aplicará entonces al acceso a la Consola.
+- __Programe una alerta__ ante la proximidad de la fecha de expiración del secreto de cliente o del certificado de firma, según el protocolo elegido.
+- __Conserve al menos una cuenta propietaria local__ en su organización Cloud Temple, fuera de la federación, para mantener el acceso en caso de indisponibilidad de su directorio.
+
+## Resolución de problemas
+
+| Síntoma | Protocolo | Causa probable |
+|---|---|---|
+| `AADSTS50011`: la URL de redirección no coincide | Ambos | La URL declarada en Azure difiere de la proporcionada por Cloud Temple. Verifíquela carácter por carácter, incluida la ausencia de `/` final. |
+| `AADSTS700016`: aplicación no encontrada | SAML 2.0 | El *Entity ID* declarado no corresponde al proporcionado por Cloud Temple. |
+| `AADSTS7000215`: secreto no válido | OpenID Connect | El secreto ha expirado, o el valor transmitido era el "Secret ID" en lugar del "Value". |
+| `AADSTS50105`: usuario no asignado | Ambos | La opción "Assignment required" está activa y el usuario no está asignado a la aplicación. |
+| El botón de conexión no aparece en la página | Ambos | La configuración aún no está activa en el lado de Cloud Temple. |
+| El usuario se autentica pero la Consola deniega el acceso | Ambos | Falta la dirección de correo en el token, o no se ha atribuido ningún permiso al usuario. |
+| El usuario aparece como una cuenta nueva en cada conexión | SAML 2.0 | El NameID no está establecido en `user.objectid`. |
+| Error de firma al llegar a la Consola | SAML 2.0 | El certificado de firma se renovó en Azure sin que se nos informara. |
+
+## Soporte
+
+Para cualquier duda sobre este procedimiento, abra una solicitud de asistencia desde su Consola. Indique el nombre de su organización así como la marca temporal de un intento de conexión fallido: esto permite localizar el rastro correspondiente.
diff --git a/i18n/it/docusaurus-plugin-content-docs/current/console/iam/iam.md b/i18n/it/docusaurus-plugin-content-docs/current/console/iam/iam.md
index 4b9e5abb..1bc17b91 100644
--- a/i18n/it/docusaurus-plugin-content-docs/current/console/iam/iam.md
+++ b/i18n/it/docusaurus-plugin-content-docs/current/console/iam/iam.md
@@ -21,6 +21,6 @@ Consente di amministrare account locali supportando al contempo un'integrazione
\ No newline at end of file
diff --git a/i18n/it/docusaurus-plugin-content-docs/current/console/iam/tutorials/sso_azuread.md b/i18n/it/docusaurus-plugin-content-docs/current/console/iam/tutorials/sso_azuread.md
index 8ceaa7c9..2a43259e 100644
--- a/i18n/it/docusaurus-plugin-content-docs/current/console/iam/tutorials/sso_azuread.md
+++ b/i18n/it/docusaurus-plugin-content-docs/current/console/iam/tutorials/sso_azuread.md
@@ -1,5 +1,5 @@
---
-title: Esempio di federazione dell'identità con Microsoft EntraID
+title: Esempio di federazione delle identità con Microsoft EntraID (Azure AD)
tags:
- iam
- tutorials
@@ -23,136 +23,305 @@ import ssoAad_016 from '@site/docs/console/iam/tutorials/images/sso_aad_016.png'
import ssoAad_017 from '@site/docs/console/iam/tutorials/images/sso_aad_017.png'
import ssoAad_018 from '@site/docs/console/iam/tutorials/images/sso_aad_018.png'
-Ecco un esempio di configurazione del repository di autenticazione di un'organizzazione Cloud Temple con __Microsoft EntraID__ (Azure Active Directory).
+Ecco un esempio di configurazione del repository di autenticazione di un'organizzazione Cloud Temple con __Microsoft EntraID__.
-La configurazione del tuo repository Microsoft a livello di organizzazione Cloud Temple semplifica l'autenticazione degli utenti sulla Console. Ciò permette di evitare la moltiplicazione dei fattori di autenticazione e di ridurre la superficie di attacco.
+La configurazione del vostro repository Microsoft a livello di un'organizzazione Cloud Temple facilita l'autenticazione dei vostri utenti sulla Console. Ciò consente di evitare la moltiplicazione dei fattori di autenticazione e di ridurre la superficie di attacco. Se i vostri utenti sono già autenticati sul loro account Microsoft, l'autenticazione ai servizi della Console sarà trasparente.
-Se gli utenti sono autenticati con il loro account Microsoft, l'autenticazione ai servizi della Console avverrà in modo trasparente.
+:::info[Azure AD e Microsoft EntraID]
+Microsoft EntraID è il nuovo nome di Azure Active Directory (Azure AD) dal 2023. Si tratta dello stesso prodotto: questo tutorial si applica indifferentemente a entrambe le denominazioni.
+:::
-Di seguito sono riportati i diversi passaggi necessari per completare questa configurazione:
+## Scegliere il protocollo
-## Step 1: SSO configuration on Microsoft Azure side
+La federazione con EntraID può essere realizzata con uno o l'altro dei due protocolli standard. Entrambi offrono un livello di sicurezza equivalente; si differenziano principalmente per ciò che dovete trasmetterci e per ciò che sarà da mantenere nel tempo.
-### Registration of a new Azure application (Azure portal)
+| | OpenID Connect | SAML 2.0 |
+|---|---|---|
+| Ciò che ci trasmettete | Due identificatori e un secret | Un URL di metadati pubblico |
+| Secret scambiato | Sì, il secret client | Nessuno |
+| Da mantenere nel tempo | Il secret client (24 mesi massimo) | Il certificato di firma (3 anni per impostazione predefinita) |
-To create the __app registration__, go to the Microsoft Azure portal, then navigate to Microsoft Entra ID, and select __"Add > App Registration"__.
+__In assenza di vincoli particolari, raccomandiamo OpenID Connect__: è il protocollo che distribuiamo per impostazione predefinita. Scegliete SAML se la vostra politica interna lo impone, o se la vostra directory è collegata a un concentratore di federazione che supporta solo questo protocollo.
-In the "Register an application" page, please specify:
+Indicate il protocollo scelto fin dall'apertura della vostra richiesta di assistenza.
+
+## Le informazioni scambiate
+
+L'implementazione si basa su uno scambio nei due sensi. Eccone il dettaglio fin da subito, per consentirvi di preparare tutto in un'unica volta.
+
+### Ciò che dovete trasmetterci — con OpenID Connect
+
+| Informazione | Nome nel portale Azure | A cosa serve |
+|---|---|---|
+| __Application (client) ID__ | *Application (client) ID* | Identifica l'applicazione presso EntraID |
+| __Directory (tenant) ID__ | *Directory (tenant) ID* | Determina gli endpoint OpenID Connect della vostra directory |
+| __Secret client__ | *Client secret* → colonna __Value__ | Autentica la Console presso EntraID |
+
+I due identificatori figurano nella scheda __"Overview"__ della vostra registrazione applicativa; il secret viene creato nella scheda __"Certificates & secrets"__.
+
+### Ciò che dovete trasmetterci — con SAML 2.0
+
+Nel caso corrente è sufficiente una sola informazione:
+
+| Informazione | Nome nel portale Azure | A cosa serve |
+|---|---|---|
+| __URL dei metadati di federazione__ | *App Federation Metadata Url* | Ne ricaviamo l'identificatore della vostra directory, i suoi endpoint e il suo certificato di firma |
+
+Si presenta nella forma seguente:
```
-- __Name__ : Enter "__SHIVA__"
-- __Supported account types__ : __Accounts in this organizational directory only__ (____ only - Single tenant)
-- __Redirect URL__ : Do not configure this field at this stage. The URL will be provided by Cloud Temple support and should be added to this field later.
+https://login.microsoftonline.com//federationmetadata/2007-06/federationmetadata.xml?appid=
+```
+
+La trovate in __"Enterprise applications"__ → la vostra applicazione → __"Single sign-on"__, sezione *SAML Certificates*. È pubblica e non contiene alcun secret: può figurare nel corpo della vostra richiesta.
+
+:::tip[Perché questo URL anziché un elenco di parametri]
+Riunisce in un unico valore l'insieme dei parametri della vostra directory e semplifica il monitoraggio del rinnovo del vostro certificato di firma. Se questo URL non è raggiungibile da Internet, trasmettete invece l'*Identity provider entity ID*, la *Single Sign-On service URL*, la *Single Logout service URL* e il certificato di firma in formato __Certificate (Base64)__.
+:::
+
+:::warning[Non trasmettete mai il secret nel corpo di una richiesta]
+Il valore del secret client è una credenziale di autenticazione. Non inseritelo nel corpo di una richiesta di assistenza, né in un commento, né in un allegato non cifrato: vi resterebbe consultabile in modo duraturo.
+
+Indicate nella vostra richiesta che disponete del secret, e trasmettetelo tramite il canale sicuro che il vostro referente Cloud Temple vi indicherà. I due identificatori (Application ID e Directory ID) non sono sensibili e possono invece figurare nella richiesta.
+:::
+
+### Ciò che Cloud Temple vi trasmette
+
+Valori specifici della vostra organizzazione, da dichiarare nella vostra applicazione EntraID:
+
+| Il nostro termine | Termine Microsoft | Protocollo |
+|---|---|---|
+| URL di reindirizzamento | *Redirect URL* | OpenID Connect |
+| URL di reindirizzamento | *Reply URL (Assertion Consumer Service URL)* | SAML 2.0 |
+| Identificatore del fornitore di servizio | *Identifier (Entity ID)* | SAML 2.0 |
+
+:::tip[Richiedeteli all'apertura della vostra domanda]
+Questi valori dipendono dalla vostra organizzazione e non possono essere indovinati. Richiedendoli all'apertura della vostra richiesta di assistenza, potrete realizzare tutta la configurazione Azure in un'unica volta, senza doverci ritornare.
+:::
+
+## Fase 1: Configurazione dell'SSO lato Microsoft EntraID
+
+Seguite la sezione corrispondente al protocollo scelto, poi la sezione «Configurazioni di sicurezza supplementari», comune a entrambi.
+
+### Via OpenID Connect
+
+#### Registrazione di una nuova applicazione Azure (portale Azure)
+
+Per la creazione dell'__app registration__, recatevi sul portale Microsoft Azure, poi in Microsoft EntraID, __"ADD > App Registration"__.
+
+Nella pagina "Register an application", indicate quanto segue:
+
+```
+- Name: indicare "SHIVA"
+- Supported account types: Accounts in this organizational directory only ( only - Single tenant)
+- Redirect URL: indicare l'URL fornita da Cloud Temple. Se non ne disponete ancora, lasciate il campo vuoto e fate riferimento alla fase 3.
```
-The __Application (client) ID__ and __Directory (tenant) ID__ are the key details to provide in your support request to the Cloud Temple team to enable Microsoft Entra ID authentication for your organization.
+Le informazioni __Application (client) ID__ e __Directory (tenant) ID__ sono visualizzate nella scheda "Overview". Annotatele: sono due delle tre informazioni da fornire nella vostra richiesta di assistenza.
-### Definizione di un segreto
+#### Definizione di un secret
-Nella scheda "Certificates & secrets", creare un nuovo segreto.
-
-*Nota: la data di scadenza del segreto non può essere superiore a 24 mesi, anche con una data di scadenza personalizzata.*
+Nella scheda "Certificates & secrets", create un nuovo secret.
-Il segreto generato dovrà essere fornito nella richiesta di supporto:
+:::warning[Copiate il valore immediatamente]
+Il valore del secret viene visualizzato una sola volta, subito dopo la sua creazione. Copiate il contenuto della colonna __"Value"__, e non quello della colonna __"Secret ID"__. Se perdete questo valore, dovrete generare un nuovo secret.
+:::
-### Definizione del token EntraID
+:::caution[Validità limitata a 24 mesi]
+La data di scadenza del secret non può essere superiore a 24 mesi, anche con una data di scadenza personalizzata. __Annotate fin da ora questa data__: alla scadenza, la connessione SSO cesserà di funzionare per tutti i vostri utenti. Vedere la sezione [Mantenimento della federazione nel tempo](#mantenimento-della-federazione-nel-tempo).
+:::
+
+#### Autorizzazione delle informazioni utilizzate dalla Console
-Il token EntraID è necessario per la configurazione dell'autenticazione.
+La Console identifica i vostri utenti a partire dalle informazioni trasportate dal token di identità. È necessaria una sola azione da parte vostra: __esporre l'indirizzo e-mail__.
-Nel menu __"Token Configuration"__, fare clic su __"Add optional claim"__. Selezionare "ID" come tipo di token e selezionare la voce "email".
+Nel menu __"Token Configuration"__, cliccate su __"Add optional claim"__. Selezionate "ID" come tipo di token e spuntate "email".
-L'interfaccia Azure vi chiederà se desiderate aggiungere un'autorizzazione che vi permetterà di leggere l'email di un utente (Microsoft Graph email), selezionare la casella e confermare.
+L'interfaccia Azure vi chiederà se desiderate aggiungere un'autorizzazione che consenta di leggere l'e-mail di un utente (Microsoft Graph email). Spuntate la casella e confermate.
-Successivamente, recarsi su "API permissions" e fare clic su __"Grant admin consent for Cloud Temple"__.
+Recatevi poi su "API permissions" e cliccate su __"Grant admin consent for <la vostra organizzazione>"__.
-### Additional security configurations (optional but recommended)
+A titolo informativo, ecco l'insieme delle informazioni consumate dalla Console:
+
+| Informazione | Utilizzo | Azione da parte vostra |
+|---|---|---|
+| `email` | Indirizzo di connessione dell'utente | __Sì__ — da dichiarare come claim opzionale (sopra) |
+| `oid` | Collegamento stabile tra l'account Console e l'identità della vostra directory, anche se l'indirizzo e-mail cambia | Nessuna — emesso nativamente da EntraID |
+| `given_name`, `family_name` | Nome e cognome visualizzati nella Console | Nessuna — inclusi nell'ambito `profile` |
+
+### Via SAML 2.0
+
+#### Creazione dell'applicazione aziendale
-By default, Microsoft Entra ID, as configured, will allow any user from your Azure tenant to sign in to your Cloud Temple organization.
-It is possible to restrict access at the __"App Registration"__ level, allowing only a specific list of users or groups to sign in to your Cloud Temple organization.
+In __Microsoft EntraID__, recatevi in __"Enterprise applications"__, poi __"New application"__. Scegliete __"Create your own application"__, assegnatele un nome e selezionate *Integrate any other application you don't find in the gallery (Non-gallery)*. Confermate con __"Create"__.
-Follow these steps:
+#### Configurazione dell'autenticazione unica
-#### Accedere alle impostazioni aggiuntive "App Registration"
+Nella vostra applicazione, aprite __"Single sign-on"__ e scegliete __"SAML"__. In __"Basic SAML Configuration"__, cliccate su __"Edit"__ e inserite i valori forniti da Cloud Temple:
+
+- __Identifier (Entity ID)__;
+- __Reply URL (Assertion Consumer Service URL)__.
+
+Salvate.
+
+#### Attributi e attestazioni
+
+EntraID emette per impostazione predefinita le attestazioni attese dalla Console. Verificatene la presenza in __"Attributes & Claims"__:
+
+| Attestazione | Utilizzo | Azione da parte vostra |
+|---|---|---|
+| `…/claims/emailaddress` | Indirizzo di connessione dell'utente | Nessuna — origine `user.mail` |
+| `http://schemas.microsoft.com/identity/claims/objectidentifier` | Collegamento stabile tra l'account Console e l'identità della vostra directory | Nessuna |
+| `…/claims/givenname`, `…/claims/surname` | Nome e cognome visualizzati nella Console | Nessuna |
+
+:::warning[Identificatore di nome (NameID): il punto più spesso trascurato]
+In __"Attributes & Claims"__ → __"Unique User Identifier (Name ID)"__, impostate l'origine su __user.objectid__ e il formato su __Persistent__.
+
+Per impostazione predefinita, EntraID emette l'indirizzo e-mail come NameID. Se un utente cambia indirizzo, la Console lo tratterebbe come una persona diversa e perderebbe i suoi diritti. L'identificatore di oggetto, invece, non cambia mai.
+:::
+
+### Configurazioni di sicurezza supplementari (opzionale ma consigliato)
+
+Per impostazione predefinita, Microsoft EntraID così configurato consentirà a qualsiasi utente del vostro tenant Azure di connettersi alla vostra organizzazione Cloud Temple. È possibile limitare a livello di __"App Registration"__ gli accessi per autorizzare solo un elenco di utenti o gruppi.
+
+Ecco la procedura da seguire.
+
+#### Accedere ai parametri supplementari "App Registration"
##### Opzione 1
-Vai sulla scheda "Overview" e fai clic sul nome dell'applicazione (il collegamento situato dopo "Managed application").
+Andate sulla scheda "Overview" e cliccate sul nome dell'applicazione (il link situato dopo "Managed application").
##### Opzione 2
-Passare alle "Applicazioni aziendali" e cercare utilizzando il nome dell'applicazione creata in precedenza.
+Recatevi nelle "Enterprise applications" e cercate utilizzando il nome dell'applicazione creata in precedenza.
-#### Authentication restriction to users assigned to the application
+#### Limitazione dell'autenticazione agli utenti assegnati all'applicazione
-Indicate here the need for user assignment to the application to allow authentication:
+Indicate qui la necessità di un'assegnazione dell'utente all'applicazione per autorizzarne l'autenticazione:
-#### Assegnazione di utenti e gruppi all'applicazione
+#### Assegnazione degli utenti e dei gruppi all'applicazione
-Solo gli utenti e i gruppi assegnati all'applicazione potranno accedere alla vostra organizzazione Cloud Temple tramite la registrazione dell'applicazione.
+Solo i gruppi e gli utenti assegnati all'applicazione potranno connettersi alla vostra organizzazione Cloud Temple tramite l'app registration.
-Infine, dovrete applicare l'assegnazione facendo clic su "Assegna".
+Infine, applicate l'assegnazione cliccando su "Assign".
-A partire da ora, gli utenti assegnati all'applicazione potranno accedere alla vostra organizzazione Cloud Temple tramite l'applicazione creata.
+Da questo momento gli utenti assegnati all'applicazione potranno connettersi alla vostra organizzazione Cloud Temple tramite l'applicazione creata.
+
+## Fase 2: Richiedere la configurazione dell'SSO della vostra organizzazione
-## Step 2: Request your organization's SSO (Single Sign-On) configuration
+Questa parte della configurazione viene effettuata a livello dell'organizzazione dal team Cloud Temple.
-This configuration step is performed at the organization level by the Cloud Temple team.
+A tal fine, presentate __una richiesta di assistenza__ nella Console indicando il vostro desiderio di configurare una federazione Microsoft EntraID, precisando:
-To proceed, please __submit a support request__ in the console indicating your intention to set up Microsoft Entra ID SSO.
+- il nome della vostra organizzazione;
+- __il protocollo scelto__: OpenID Connect o SAML 2.0;
+- il nome di un referente, con la sua e-mail e il suo numero di telefono, per finalizzare la configurazione;
+- __con OpenID Connect__: l'__Application (client) ID__ e il __Directory (tenant) ID__ annotati alla fase 1;
+- __con SAML 2.0__: l'__URL dei metadati di federazione__ della vostra applicazione.
-Please include the following information in your support request:
+Con OpenID Connect, trasmettete il __secret client__ tramite il canale sicuro indicato dal vostro referente, e non nel corpo della richiesta. Con SAML, non viene scambiato alcun secret.
-- Name of your Organization
-- Name of a contact person, along with their email address and phone number, to finalize the configuration
-- Application ID (unique identifier associated with the previously created application)
-- Directory ID (corresponds to the Azure AD tenant ID of your Azure environment)
-- Secret (secret associated with the previously created application)
+Non appena la configurazione sarà realizzata lato Console, il referente indicato ne sarà informato.
-Once the configuration is completed on the Console side, the designated contact will be notified.
+## Fase 3: Dichiarazione della "Redirect URL" (OpenID Connect)
-## Step 3: Finalization of the configuration
+Se non avete indicato la "Redirect URL" al momento della creazione dell'applicazione, aggiungetela ora.
-On the App Registration home page, in the Overview menu, click on "Add a Redirect URL".
+Con SAML 2.0, gli URL equivalenti sono già stati dichiarati in __"Basic SAML Configuration"__ alla fase 1: passate direttamente alla fase 4.
+
+Nella pagina iniziale dell'App Registration, nel menu "Overview", cliccate su "Add a Redirect URL".
-Next, go to "Add a platform" and add one of type Web.
+Dirigetevi poi verso "Add a platform" e aggiungetene una di tipo Web.
-Enter the "Redirect URL" provided by the Applications Product Team.
+Indicate la "Redirect URL" fornita da Cloud Temple.
-You should see this result once the "Redirect URL" has been added.
+Dovreste ottenere questo risultato una volta aggiunta la "Redirect URL".
-The configuration of the "Redirect URL" may take a few minutes to take effect.
-Once all steps are completed, you can authenticate to your Cloud Temple organization via your SSO.
+La configurazione della "Redirect URL" può richiedere qualche minuto per diventare effettiva.
+
+## Fase 4: Verifica
+
+Una volta realizzate tutte le fasi, potete autenticarvi alla vostra organizzazione Cloud Temple tramite il vostro SSO.
+
+:::info[Diritti dei nuovi utenti]
+La federazione delle identità gestisce __l'autenticazione__, non le __autorizzazioni__. Un utente che si connette per la prima volta tramite l'SSO non dispone di alcun diritto finché un proprietario dell'organizzazione non gliene ha attribuiti dalla Console.
+:::
+
+## Mantenimento della federazione nel tempo
+
+È il principale punto di vigilanza: qualunque sia il protocollo, un elemento scade, e la sua scadenza interrompe l'SSO __per tutti i vostri utenti__.
+
+### Con OpenID Connect: il secret client
+
+Il secret client scade al più tardi 24 mesi dopo la sua creazione. Anticipatene il rinnovo:
+
+1. in "Certificates & secrets", create un __nuovo__ secret senza eliminare il precedente;
+2. trasmettetene il valore a Cloud Temple tramite il canale sicuro, aprendo una richiesta di assistenza;
+3. una volta confermato il passaggio dai nostri team, eliminate il vecchio secret dal portale Azure.
+
+Conservare i due secret durante il passaggio evita qualsiasi interruzione di servizio.
+
+### Con SAML 2.0: il certificato di firma
+
+Il certificato di firma emesso da EntraID ha una durata di vita limitata, di tre anni per impostazione predefinita.
+
+__Avvisateci prima di qualsiasi rotazione di certificato__, tramite una richiesta di assistenza, rispettando il periodo di sovrapposizione proposto da Microsoft. Se ci avete trasmesso un certificato sotto forma di file anziché l'URL dei metadati, allegate il nuovo certificato alla vostra richiesta.
+
+## Buone pratiche
+
+- __Gestite l'accesso per gruppi__ anziché per utenti: l'arrivo o la partenza di un collaboratore viene allora trattato nella vostra directory, senza intervento sulla Console.
+- __Attivate l'autenticazione a più fattori__ sull'applicazione nelle vostre politiche di accesso condizionale EntraID: si applicherà allora all'accesso alla Console.
+- __Programmate un avviso__ all'avvicinarsi della data di scadenza del secret client o del certificato di firma, a seconda del protocollo scelto.
+- __Conservate almeno un account proprietario locale__ sulla vostra organizzazione Cloud Temple, al di fuori della federazione, per mantenere un accesso in caso di indisponibilità della vostra directory.
+
+## Risoluzione dei problemi
+
+| Sintomo | Protocollo | Causa probabile |
+|---|---|---|
+| `AADSTS50011`: l'URL di reindirizzamento non corrisponde | Entrambi | L'URL dichiarato in Azure differisce da quello fornito da Cloud Temple. Verificatelo carattere per carattere, compresa l'assenza di `/` finale. |
+| `AADSTS700016`: applicazione non trovata | SAML 2.0 | L'*Entity ID* dichiarato non corrisponde a quello fornito da Cloud Temple. |
+| `AADSTS7000215`: secret non valido | OpenID Connect | Il secret è scaduto, oppure il valore trasmesso era il "Secret ID" anziché il "Value". |
+| `AADSTS50105`: utente non assegnato | Entrambi | L'opzione "Assignment required" è attiva e l'utente non è assegnato all'applicazione. |
+| Il pulsante di connessione non appare nella pagina | Entrambi | La configurazione non è ancora attiva lato Cloud Temple. |
+| L'utente è autenticato ma la Console rifiuta l'accesso | Entrambi | L'indirizzo e-mail è assente dal token, oppure nessun diritto è stato attribuito all'utente. |
+| L'utente appare come un nuovo account a ogni connessione | SAML 2.0 | Il NameID non è impostato su `user.objectid`. |
+| Errore di firma all'arrivo sulla Console | SAML 2.0 | Il certificato di firma è stato rinnovato lato Azure senza che ne fossimo informati. |
+
+## Supporto
+
+Per qualsiasi domanda su questa procedura, aprite una richiesta di assistenza dalla vostra Console. Precisate il nome della vostra organizzazione nonché l'orario di un tentativo di connessione fallito: ciò consente di ritrovare la traccia corrispondente.
diff --git a/scripts/translate_py/translation-meta.json b/scripts/translate_py/translation-meta.json
index 31a782f0..568131d1 100644
--- a/scripts/translate_py/translation-meta.json
+++ b/scripts/translate_py/translation-meta.json
@@ -85,10 +85,10 @@
"it": "1b52c385e0e00c19a63588dc81ea75e21417da5a1356cea502171fc8b38ea454"
},
"console/iam/iam.md": {
- "en": "484e52649550098662ce7e64419dd94d10c20b10e5e2d2bee7e987d53841c949",
- "de": "484e52649550098662ce7e64419dd94d10c20b10e5e2d2bee7e987d53841c949",
- "es": "484e52649550098662ce7e64419dd94d10c20b10e5e2d2bee7e987d53841c949",
- "it": "484e52649550098662ce7e64419dd94d10c20b10e5e2d2bee7e987d53841c949"
+ "en": "6343fe83b77f396e23d9f8e15b4c9dfd68aa19572825d091d94a100558b61b14",
+ "de": "6343fe83b77f396e23d9f8e15b4c9dfd68aa19572825d091d94a100558b61b14",
+ "es": "6343fe83b77f396e23d9f8e15b4c9dfd68aa19572825d091d94a100558b61b14",
+ "it": "6343fe83b77f396e23d9f8e15b4c9dfd68aa19572825d091d94a100558b61b14"
},
"console/iam/quickstart.md": {
"en": "3b3a44b3e281fa129a58463c3dae6336fd8ee4809d2ba091f693f65850739434",
@@ -103,10 +103,10 @@
"it": "606b1e74af281a97dc6c45adc4a7e5fcf461776e0cdf2ea86945b3ceabe9d7d0"
},
"console/iam/tutorials/sso_azuread.md": {
- "en": "5f7663bd054a82964ede9dfe11dc45e6a2a79624c7b924bafce3f9fd91195fec",
- "de": "5f7663bd054a82964ede9dfe11dc45e6a2a79624c7b924bafce3f9fd91195fec",
- "es": "5f7663bd054a82964ede9dfe11dc45e6a2a79624c7b924bafce3f9fd91195fec",
- "it": "5f7663bd054a82964ede9dfe11dc45e6a2a79624c7b924bafce3f9fd91195fec"
+ "en": "72f752096aee9255e48d816010882035b50add83ea687e2690cb61b48d03176d",
+ "de": "72f752096aee9255e48d816010882035b50add83ea687e2690cb61b48d03176d",
+ "es": "72f752096aee9255e48d816010882035b50add83ea687e2690cb61b48d03176d",
+ "it": "72f752096aee9255e48d816010882035b50add83ea687e2690cb61b48d03176d"
},
"console/iam/tutorials/sso_intune.md": {
"en": "2a5fc99951f052a2c71188580b1c2b51df998ab9b958fd09d4bd4d3160ec7878",