From 59783b9c7938654fde9c2238490c9eb6811a0e29 Mon Sep 17 00:00:00 2001 From: KChapron Date: Tue, 18 Aug 2026 16:21:00 +0200 Subject: [PATCH 1/3] =?UTF-8?q?docs(iam):=20regroupe=20les=20informations?= =?UTF-8?q?=20=C3=A0=20fournir=20pour=20la=20f=C3=A9d=C3=A9ration=20EntraI?= =?UTF-8?q?D?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Le tutoriel décrivait correctement les manipulations dans le portail Azure mais n'énonçait jamais de façon groupée ce que le client doit préparer et transmettre, ce qui imposait plusieurs passes dans Azure et des échanges supplémentaires avec le support. - ajoute une section « Les informations échangées » en tête de page, présentant les deux sens de l'échange - précise que la fédération EntraID s'effectue en OpenID Connect - invite à demander la « Redirect URL » dès l'ouverture de la demande, au lieu de la faire attendre après réponse du support - recommande un canal dédié pour le secret client plutôt que le corps de la demande, et rappelle que les deux identifiants ne sont pas sensibles - documente l'expiration du secret à 24 mois et la procédure de renouvellement sans interruption - documente les informations attendues dans le jeton au-delà d'`email` - ajoute les sections « Bonnes pratiques » et « Dépannage » - mentionne « Azure AD » dans le titre, appellation encore recherchée Les dix-sept captures d'écran et la progression en étapes sont conservées. Répercuté sur les cinq langues, métadonnées de traduction mises à jour. Closes #330 Co-Authored-By: Claude Opus 5 --- docs/console/iam/tutorials/sso_azuread.md | 169 ++++++++++++---- .../console/iam/tutorials/sso_azuread.md | 188 +++++++++++++----- .../console/iam/tutorials/sso_azuread.md | 186 ++++++++++++----- .../console/iam/tutorials/sso_azuread.md | 187 ++++++++++++----- .../console/iam/tutorials/sso_azuread.md | 188 +++++++++++++----- scripts/translate_py/translation-meta.json | 8 +- 6 files changed, 667 insertions(+), 259 deletions(-) diff --git a/docs/console/iam/tutorials/sso_azuread.md b/docs/console/iam/tutorials/sso_azuread.md index 1c46976e..9b239f04 100644 --- a/docs/console/iam/tutorials/sso_azuread.md +++ b/docs/console/iam/tutorials/sso_azuread.md @@ -1,5 +1,5 @@ --- -title: Exemple de fédération d'identité avec Microsoft EntraID +title: Exemple de fédération d'identité avec Microsoft EntraID (Azure AD) tags: - iam - tutorials @@ -23,68 +23,111 @@ import ssoAad_016 from '@site/docs/console/iam/tutorials/images/sso_aad_016.png' import ssoAad_017 from '@site/docs/console/iam/tutorials/images/sso_aad_017.png' import ssoAad_018 from '@site/docs/console/iam/tutorials/images/sso_aad_018.png' -Voici un exemple de configuration du référentiel d'authentification d'une organisation Cloud Temple avec __Microsoft EntraID__ (Azure Active Directory). +Voici un exemple de configuration du référentiel d'authentification d'une organisation Cloud Temple avec __Microsoft EntraID__. -La configuration de votre référentiel Microsoft au niveau d'une organisation Cloud Temple facilite l'authentification de vos utilisateurs sur la Console. Cela permet d'éviter la multiplication des facteurs d'authentification et de diminuer la surface d'attaque. +La configuration de votre référentiel Microsoft au niveau d'une organisation Cloud Temple facilite l'authentification de vos utilisateurs sur la Console. Cela permet d'éviter la multiplication des facteurs d'authentification et de diminuer la surface d'attaque. Si vos utilisateurs sont authentifiés à leur compte Microsoft, l'authentification aux services de la Console sera transparente. -Si vos utilisateurs sont authentifiés à leur compte Microsoft, l'authentification aux services de la Console sera transparente. +:::info[Azure AD et Microsoft EntraID] +Microsoft EntraID est le nouveau nom d'Azure Active Directory (Azure AD) depuis 2023. Il s'agit du même produit : ce tutoriel s'applique indifféremment aux deux appellations. +::: -Voici les différentes étapes pour réaliser cette configuration : +:::info[Protocole utilisé] +La fédération avec EntraID est réalisée en __OpenID Connect (OIDC)__. Aucune configuration SAML n'est nécessaire de votre côté. +::: -## Etape 1 : Configuration du SSO coté Microsoft Azure +## Les informations échangées + +La mise en place repose sur un échange dans les deux sens. En voici le détail d'emblée, pour vous permettre de tout préparer en une seule passe. + +### Ce que vous devez nous transmettre + +| Information | Nom dans le portail Azure | À quoi elle sert | +|---|---|---| +| __Application (client) ID__ | *Application (client) ID* | Identifie l'application auprès d'EntraID | +| __Directory (tenant) ID__ | *Directory (tenant) ID* | Détermine les points de terminaison OpenID Connect de votre annuaire | +| __Secret client__ | *Client secret* → colonne __Value__ | Authentifie la Console auprès d'EntraID | + +Les deux identifiants figurent dans l'onglet __"Overview"__ de votre inscription d'application ; le secret se crée dans l'onglet __"Certificates & secrets"__. + +:::warning[Ne transmettez jamais le secret dans le corps d'une demande] +La valeur du secret client est un identifiant d'authentification. Ne la déposez pas dans le corps d'une demande d'assistance, ni dans un commentaire, ni dans une pièce jointe non chiffrée : elle y resterait consultable de façon durable. + +Indiquez dans votre demande que vous disposez du secret, et transmettez-le par le canal sécurisé que votre contact Cloud Temple vous indiquera. Les deux identifiants (Application ID et Directory ID) ne sont pas sensibles et peuvent, eux, figurer dans la demande. +::: + +### Ce que Cloud Temple vous transmet + +La __"Redirect URL"__, propre à votre organisation. Elle est à déclarer dans votre inscription d'application EntraID (étape 3). + +:::tip[Demandez-la dès l'ouverture de votre demande] +Cette URL dépend de votre organisation et ne peut pas être devinée. En la demandant dès l'ouverture de votre demande d'assistance, vous pourrez réaliser toute la configuration Azure en une seule fois, sans avoir à y revenir. +::: + +## Étape 1 : Configuration du SSO côté Microsoft EntraID ### Enregistrement d'une nouvelle application Azure (portail Azure) -Pour la création de l'__app registration__, il faut se rendre sur le portail Microsoft Azure, puis daans Microsoft EntraID, __"ADD > App Registration"__ +Pour la création de l'__app registration__, rendez-vous sur le portail Microsoft Azure, puis dans Microsoft EntraID, __"ADD > App Registration"__. Dans la page "Register an application", veuillez indiquer : ``` -- __Name__ : Indiquer "__SHIVA__" -- __Supported account types__ : __Accounts in this organizational directory only__ (____ only - Single tenant) -- __Redirect URL__ : A ne pas paramétrer dans un premier temps. L'URL sera fournie par le support Cloud Temple et sera à ajouter dans ce champ plus tard. +- Name : indiquer "SHIVA" +- Supported account types : Accounts in this organizational directory only ( only - Single tenant) +- Redirect URL : renseigner l'URL fournie par Cloud Temple. Si vous ne l'avez pas encore, laissez le champ vide et reportez-vous à l'étape 3. ``` -Les informations __Application (client) ID__ et __Directory (tenant) ID__ sont les informations utiles à fournir dans la demande de support à l'équipe Cloud Temple pour activer l'authentification Microsoft EntraID au niveau de votre organisation. +Les informations __Application (client) ID__ et __Directory (tenant) ID__ sont affichées sur l'onglet "Overview". Relevez-les : ce sont deux des trois informations à fournir dans votre demande d'assistance. ### Définition d'un secret -Dans l'onglet "Certificates & secrets", créer un nouveau secret. - -*À noter : la date d'expiration du secret ne peut être supérieure à 24 mois, y compris avec une date d'expiration custom.* +Dans l'onglet "Certificates & secrets", créez un nouveau secret. -Le secret généré sera à fournir dans la demande de support : +:::warning[Copiez la valeur immédiatement] +La valeur du secret n'est affichée qu'une seule fois, juste après sa création. Copiez le contenu de la colonne __"Value"__, et non celui de la colonne __"Secret ID"__. Si vous perdez cette valeur, vous devrez générer un nouveau secret. +::: -### Définition du token EntraID +:::caution[Durée de validité limitée à 24 mois] +La date d'expiration du secret ne peut être supérieure à 24 mois, y compris avec une date d'expiration personnalisée. __Notez dès maintenant cette date__ : à son échéance, la connexion SSO cessera de fonctionner pour l'ensemble de vos utilisateurs. Voir la section [Renouvellement du secret](#renouvellement-du-secret). +::: + +### Autorisation des informations utilisées par la Console -Le token EntraID est nécessaire à la configuration de l'authentification. +La Console identifie vos utilisateurs à partir des informations transportées par le jeton d'identité. Une seule action est nécessaire de votre part : __exposer l'adresse e-mail__. -Dans le menu __"Token Configuration"__, cliquer sur __"Add optional claim"__. Vous devrez sélectionner "ID" en tant que type de token et cocher "email". +Dans le menu __"Token Configuration"__, cliquez sur __"Add optional claim"__. Sélectionnez "ID" en tant que type de token et cochez "email". -L'interface Azure va vous demander si vous souhaitez ajouter une permission qui vous permettra de lire l'email d'un utilisateur (Microsoft Graph email), cochez la case et validez. +L'interface Azure vous demande si vous souhaitez ajouter une permission permettant de lire l'email d'un utilisateur (Microsoft Graph email). Cochez la case et validez. -Ensuite, rendez-vous sur "API permissions" et cliquez sur __"Grant admin consent for Cloud Temple"__. +Rendez-vous ensuite sur "API permissions" et cliquez sur __"Grant admin consent for <votre organisation>"__. -### Configurations de sécurité supplémentaires (optionel mais recommandé) +Pour information, voici l'ensemble des informations consommées par la Console : -Par défaut, Microsoft EntraID tel que configuré donnera à n'importe quel utilisateur de votre tenant Azure la possibilité de se connecter à votre organisation Cloud Temple. -Il est possible de restreindre au niveau de __"App Registration"__ les accès pour n'autoriser qu'une liste d'utilisateurs ou groupes à se connecter à votre organisation Cloud Temple. +| Information | Usage | Action de votre part | +|---|---|---| +| `email` | Adresse de connexion de l'utilisateur | __Oui__ — à déclarer en claim optionnel (ci-dessus) | +| `oid` | Rattachement stable du compte Console à l'identité de votre annuaire, y compris si l'adresse e-mail change | Aucune — émis nativement par EntraID | +| `given_name`, `family_name` | Prénom et nom affichés dans la Console | Aucune — inclus dans le périmètre `profile` | -Voici la procédure à suivre ; +### Configurations de sécurité supplémentaires (optionnel mais recommandé) + +Par défaut, Microsoft EntraID tel que configuré donnera à n'importe quel utilisateur de votre tenant Azure la possibilité de se connecter à votre organisation Cloud Temple. Il est possible de restreindre au niveau de l'__"App Registration"__ les accès pour n'autoriser qu'une liste d'utilisateurs ou de groupes. + +Voici la procédure à suivre. #### Accéder aux paramètres supplémentaires "App Registration" @@ -96,13 +139,13 @@ Allez sur l'onglet "Overview" puis cliquez sur le nom de l'application (le lien ##### Option 2 -Se rendre dans les "Enterprise applications" et chercher en utilisant le nom de l'application créée précédemment. +Rendez-vous dans les "Enterprise applications" et cherchez en utilisant le nom de l'application créée précédemment. #### Restriction de l'authentification aux utilisateurs assignés à l'application -Indiquer ici la nécessité d'un assignement de l'utilisateur à l'application pour autoriser son authentification : +Indiquez ici la nécessité d'un assignement de l'utilisateur à l'application pour autoriser son authentification : @@ -112,46 +155,86 @@ Seuls les groupes et utilisateurs assignés à l'application pourront se connect -Enfin, vous n'aurez plus qu'à appliquer l'assignation en cliquant sur "Assign". +Enfin, appliquez l'assignation en cliquant sur "Assign". -Désormais les utilisateurs assignés à l'application pourront se connecter à votre organisation Cloud Temple via l'application créée. +Désormais, les utilisateurs assignés à l'application pourront se connecter à votre organisation Cloud Temple via l'application créée. + +## Étape 2 : Demander la configuration du SSO de votre organisation -## Etape 2 : Demander la configuration du SSO (Single Sign-On) de votre organisation +Cette partie de la configuration se fait au niveau de l'organisation par l'équipe Cloud Temple. -Cette partie de la configuration se fait au niveau de l'organisation par l'équipe Cloud temple. +Pour ce faire, faites __une demande d'assistance__ dans la Console indiquant votre souhait de configurer une fédération Microsoft EntraID, en précisant : -Pour se faire, faites __une demande d'assistance__ dans la console indiquant votre souhait de configurer une SSO Microsoft EntraID. +- le nom de votre organisation ; +- le nom d'un contact, avec son adresse e-mail et son numéro de téléphone, pour finaliser la configuration ; +- l'__Application (client) ID__ relevé à l'étape 1 ; +- le __Directory (tenant) ID__ relevé à l'étape 1. -Veuillez donner les informations suivantes dans la demande d'assistance : - Le nom de votre Organisation - Le nom d'un contact avec son mail et n° de téléphone pour finaliser la configuration - Application ID (identifiant unique associé à l'application créée précédemment) - Directory ID (correspond à l'identifiant Azure AD du tenant Azure) - Secret (Secret associé à l'application créée précédemment) +Transmettez le __secret client__ par le canal sécurisé indiqué par votre contact, et non dans le corps de la demande. -Dès que la configuration est réalisée coté Console, le contact indiqué sera informé. +Dès que la configuration est réalisée côté Console, le contact indiqué en sera informé et recevra la __"Redirect URL"__ à déclarer. -## Etape 3 : Finalisation de la configuration +## Étape 3 : Déclaration de la "Redirect URL" -Sur la page d'accueil de l'App Registration, dans le menu overview, cliquez sur "Add a Redirect URL". +Si vous n'avez pas renseigné la "Redirect URL" lors de la création de l'application, ajoutez-la maintenant. + +Sur la page d'accueil de l'App Registration, dans le menu "Overview", cliquez sur "Add a Redirect URL". -Ensuite, dirigez-vous vers le "Add a platform" et ajoutez-en une de type Web. +Dirigez-vous ensuite vers "Add a platform" et ajoutez-en une de type Web. -Il vous suffit de renseigner la "Redirect URL" fournie par la Team Produit Applications. +Renseignez la "Redirect URL" fournie par Cloud Temple. -Vous devriez obtenir ce résulat une fois la "Redirect URL" ajoutée. +Vous devriez obtenir ce résultat une fois la "Redirect URL" ajoutée. La configuration de la "Redirect URL" peut mettre quelques minutes à être effective. + +## Étape 4 : Vérification + Une fois toutes les étapes réalisées, vous pouvez vous authentifier à votre organisation Cloud Temple via votre SSO. + +:::info[Droits des nouveaux utilisateurs] +La fédération d'identité gère __l'authentification__, pas les __autorisations__. Un utilisateur qui se connecte pour la première fois via le SSO ne dispose d'aucun droit tant qu'un propriétaire de l'organisation ne lui en a pas attribué depuis la Console. +::: + +## Renouvellement du secret + +Le secret client expire au plus tard 24 mois après sa création. À son échéance, la connexion SSO cesse de fonctionner pour l'ensemble de vos utilisateurs. Anticipez son renouvellement : + +1. dans "Certificates & secrets", créez un __nouveau__ secret sans supprimer l'ancien ; +2. transmettez sa valeur à Cloud Temple par le canal sécurisé, en ouvrant une demande d'assistance ; +3. une fois la bascule confirmée par nos équipes, supprimez l'ancien secret depuis le portail Azure. + +Conserver les deux secrets le temps de la bascule évite toute interruption de service. + +## Bonnes pratiques + +- __Pilotez l'accès par groupes__ plutôt que par utilisateurs : l'arrivée ou le départ d'un collaborateur se traite alors dans votre annuaire, sans intervention sur la Console. +- __Activez l'authentification multifacteur__ sur l'application dans vos stratégies d'accès conditionnel EntraID : elle s'applique alors à l'accès à la Console. +- __Programmez une alerte__ à l'approche de la date d'expiration du secret. +- __Conservez au moins un compte propriétaire local__ sur votre organisation Cloud Temple, non fédéré, afin de garder un accès en cas d'indisponibilité de votre annuaire. + +## Dépannage + +| Symptôme | Cause probable | +|---|---| +| `AADSTS50011` : l'URL de redirection ne correspond pas | La "Redirect URL" déclarée dans Azure diffère de celle fournie par Cloud Temple. Vérifiez-la caractère par caractère, y compris l'absence de `/` final. | +| `AADSTS7000215` : secret invalide | Le secret a expiré, ou la valeur transmise était le "Secret ID" au lieu de la "Value". | +| `AADSTS50105` : utilisateur non assigné | L'option "Assignment required" est active et l'utilisateur n'est pas assigné à l'application. | +| Le bouton de connexion n'apparaît pas sur la page | La configuration n'est pas encore active côté Cloud Temple. | +| L'utilisateur est authentifié mais la Console refuse l'accès | Le claim `email` est absent du jeton, ou aucun droit n'a été attribué à l'utilisateur. | + +## Support + +Pour toute question sur cette procédure, ouvrez une demande d'assistance depuis votre Console. Précisez le nom de votre organisation ainsi que l'horodatage d'une tentative de connexion en échec : cela permet de retrouver la trace correspondante. diff --git a/i18n/de/docusaurus-plugin-content-docs/current/console/iam/tutorials/sso_azuread.md b/i18n/de/docusaurus-plugin-content-docs/current/console/iam/tutorials/sso_azuread.md index b0da18d6..fc3bff7c 100644 --- a/i18n/de/docusaurus-plugin-content-docs/current/console/iam/tutorials/sso_azuread.md +++ b/i18n/de/docusaurus-plugin-content-docs/current/console/iam/tutorials/sso_azuread.md @@ -1,5 +1,5 @@ --- -title: Identity Federation Example with Microsoft EntraID +title: Beispiel einer Identitätsföderation mit Microsoft EntraID (Azure AD) tags: - iam - tutorials @@ -23,136 +23,218 @@ import ssoAad_016 from '@site/docs/console/iam/tutorials/images/sso_aad_016.png' import ssoAad_017 from '@site/docs/console/iam/tutorials/images/sso_aad_017.png' import ssoAad_018 from '@site/docs/console/iam/tutorials/images/sso_aad_018.png' -Here is an example configuration of the identity provider for a Cloud Temple organization using __Microsoft EntraID__ (Azure Active Directory). +Nachfolgend finden Sie ein Beispiel für die Konfiguration des Authentifizierungsverzeichnisses einer Cloud-Temple-Organisation mit __Microsoft EntraID__. -Configuring your Microsoft identity provider at the Cloud Temple organization level simplifies user authentication on the Console. This helps avoid the proliferation of authentication factors and reduces the attack surface. +Die Konfiguration Ihres Microsoft-Verzeichnisses auf Ebene einer Cloud-Temple-Organisation erleichtert die Authentifizierung Ihrer Benutzer an der Konsole. Dadurch lässt sich die Vervielfachung von Authentifizierungsfaktoren vermeiden und die Angriffsfläche verringern. Wenn Ihre Benutzer bereits an ihrem Microsoft-Konto angemeldet sind, erfolgt die Authentifizierung an den Diensten der Konsole nahtlos. -If your users are already authenticated to their Microsoft accounts, logging into the Console services will be seamless and transparent. +:::info[Azure AD und Microsoft EntraID] +Microsoft EntraID ist seit 2023 der neue Name von Azure Active Directory (Azure AD). Es handelt sich um dasselbe Produkt: Dieses Tutorial gilt gleichermaßen für beide Bezeichnungen. +::: -Below are the steps to complete this configuration: +:::info[Verwendetes Protokoll] +Die Föderation mit EntraID erfolgt über __OpenID Connect (OIDC)__. Eine SAML-Konfiguration ist auf Ihrer Seite nicht erforderlich. +::: -## Step 1: SSO Configuration on Microsoft Azure Side +## Die ausgetauschten Informationen -### Register a new Azure application (Azure portal) +Die Einrichtung beruht auf einem Austausch in beide Richtungen. Hier die Einzelheiten vorab, damit Sie alles in einem Durchgang vorbereiten können. -To create the __app registration__, go to the Microsoft Azure portal, then navigate to Microsoft Entra ID, and select __"Add > App Registration"__. +### Was Sie uns übermitteln müssen -On the "Register an application" page, please specify: +| Information | Bezeichnung im Azure-Portal | Wozu sie dient | +|---|---|---| +| __Application (client) ID__ | *Application (client) ID* | Identifiziert die Anwendung gegenüber EntraID | +| __Directory (tenant) ID__ | *Directory (tenant) ID* | Bestimmt die OpenID-Connect-Endpunkte Ihres Verzeichnisses | +| __Client Secret__ | *Client secret* → Spalte __Value__ | Authentifiziert die Konsole gegenüber EntraID | + +Beide Kennungen finden Sie auf der Registerkarte __"Overview"__ Ihrer App-Registrierung; das Secret wird auf der Registerkarte __"Certificates & secrets"__ erstellt. + +:::warning[Übermitteln Sie das Secret niemals im Text einer Anfrage] +Der Wert des Client Secret ist ein Authentifizierungsmerkmal. Fügen Sie ihn nicht in den Text einer Supportanfrage, in einen Kommentar oder in einen unverschlüsselten Anhang ein: Dort bliebe er dauerhaft einsehbar. + +Geben Sie in Ihrer Anfrage an, dass Ihnen das Secret vorliegt, und übermitteln Sie es über den sicheren Kanal, den Ihr Cloud-Temple-Ansprechpartner Ihnen nennt. Die beiden Kennungen (Application ID und Directory ID) sind nicht vertraulich und dürfen in der Anfrage stehen. +::: + +### Was Cloud Temple Ihnen übermittelt + +Die __"Redirect URL"__, die für Ihre Organisation spezifisch ist. Sie ist in Ihrer EntraID-App-Registrierung zu hinterlegen (Schritt 3). + +:::tip[Fordern Sie sie beim Öffnen Ihrer Anfrage an] +Diese URL hängt von Ihrer Organisation ab und lässt sich nicht erraten. Wenn Sie sie beim Öffnen Ihrer Supportanfrage anfordern, können Sie die gesamte Azure-Konfiguration in einem Durchgang vornehmen, ohne später darauf zurückkommen zu müssen. +::: + +## Schritt 1: SSO-Konfiguration auf Seite von Microsoft EntraID + +### Registrierung einer neuen Azure-Anwendung (Azure-Portal) + +Für die Erstellung der __App Registration__ rufen Sie das Microsoft-Azure-Portal auf und wählen dann in Microsoft EntraID __"ADD > App Registration"__. + +Geben Sie auf der Seite "Register an application" Folgendes an: ``` -- __Name__ : Enter "__SHIVA__" -- __Supported account types__ : __Accounts in this organizational directory only__ (____ only - Single tenant) -- __Redirect URL__ : Do not configure this field at this time. The URL will be provided by Cloud Temple support and should be added to this field later. +- Name: "SHIVA" angeben +- Supported account types: Accounts in this organizational directory only ( only - Single tenant) +- Redirect URL: die von Cloud Temple bereitgestellte URL angeben. Falls sie Ihnen noch nicht vorliegt, lassen Sie das Feld leer und fahren Sie mit Schritt 3 fort. ``` -The __Application (client) ID__ and __Directory (tenant) ID__ are the key details that must be provided in your support request to the Cloud Temple team to enable Microsoft Entra ID authentication for your organization. +Die Angaben __Application (client) ID__ und __Directory (tenant) ID__ werden auf der Registerkarte "Overview" angezeigt. Notieren Sie sie: Es handelt sich um zwei der drei Informationen, die Sie in Ihrer Supportanfrage angeben müssen. -### Definition of a secret - -In the "Certificates & secrets" tab, create a new secret. +### Festlegung eines Secret -*Note: The expiration date of the secret cannot exceed 24 months, even with a custom expiration date.* +Erstellen Sie auf der Registerkarte "Certificates & secrets" ein neues Secret. -The generated secret must be provided in the support request: +:::warning[Kopieren Sie den Wert sofort] +Der Wert des Secret wird nur ein einziges Mal angezeigt, unmittelbar nach seiner Erstellung. Kopieren Sie den Inhalt der Spalte __"Value"__ und nicht den der Spalte __"Secret ID"__. Falls Sie diesen Wert verlieren, müssen Sie ein neues Secret erzeugen. +::: -### Definition des EntraID-Tokens +:::caution[Gültigkeit auf 24 Monate begrenzt] +Das Ablaufdatum des Secret darf 24 Monate nicht überschreiten, auch nicht mit einem benutzerdefinierten Ablaufdatum. __Notieren Sie sich dieses Datum bereits jetzt__: Nach Ablauf funktioniert die SSO-Anmeldung für sämtliche Benutzer nicht mehr. Siehe Abschnitt [Erneuerung des Secret](#erneuerung-des-secret). +::: -Der EntraID-Token ist für die Konfiguration der Authentifizierung erforderlich. +### Freigabe der von der Konsole verwendeten Informationen -Klicken Sie im Menü __"Token Configuration"__ auf __"Add optional claim"__. Wählen Sie als Token-Typ "ID" aus und aktivieren Sie die Option "email". +Die Konsole identifiziert Ihre Benutzer anhand der im Identitätstoken übermittelten Informationen. Nur eine Maßnahme ist Ihrerseits erforderlich: __die E-Mail-Adresse bereitstellen__. + +Klicken Sie im Menü __"Token Configuration"__ auf __"Add optional claim"__. Wählen Sie "ID" als Tokentyp und aktivieren Sie "email". -Die Azure-Oberfläche fragt Sie daraufhin, ob Sie eine Berechtigung hinzufügen möchten, die Ihnen das Lesen der E-Mail-Adresse eines Benutzers (Microsoft Graph email) ermöglicht. Aktivieren Sie das Kontrollkästchen und bestätigen Sie. +Die Azure-Oberfläche fragt, ob Sie eine Berechtigung hinzufügen möchten, die das Lesen der E-Mail-Adresse eines Benutzers erlaubt (Microsoft Graph email). Aktivieren Sie das Kontrollkästchen und bestätigen Sie. -Wechseln Sie anschließend zu "API-Berechtigungen" und klicken Sie auf __"Grant admin consent for Cloud Temple"__. +Rufen Sie anschließend "API permissions" auf und klicken Sie auf __"Grant admin consent for <Ihre Organisation>"__. -### Additional Security Configurations (optional but recommended) +Zur Information: Hier alle von der Konsole genutzten Informationen: + +| Information | Verwendung | Maßnahme Ihrerseits | +|---|---|---| +| `email` | Anmeldeadresse des Benutzers | __Ja__ — als optionaler Claim zu deklarieren (siehe oben) | +| `oid` | Stabile Zuordnung des Konsolenkontos zur Identität in Ihrem Verzeichnis, auch bei Änderung der E-Mail-Adresse | Keine — wird von EntraID nativ ausgestellt | +| `given_name`, `family_name` | In der Konsole angezeigter Vor- und Nachname | Keine — im Bereich `profile` enthalten | + +### Zusätzliche Sicherheitseinstellungen (optional, aber empfohlen) -By default, Microsoft Entra ID, as configured, will allow any user in your Azure tenant to sign in to your Cloud Temple organization. -It is possible to restrict access at the __"App Registration"__ level to allow only a specific list of users or groups to sign in to your Cloud Temple organization. +Standardmäßig erlaubt Microsoft EntraID in dieser Konfiguration jedem Benutzer Ihres Azure-Tenants, sich an Ihrer Cloud-Temple-Organisation anzumelden. Sie können den Zugriff auf Ebene der __"App Registration"__ einschränken, sodass nur eine Liste von Benutzern oder Gruppen zugelassen ist. -Follow these steps: +Gehen Sie dazu wie folgt vor. -#### Access additional "App Registration" settings +#### Zugriff auf die zusätzlichen Einstellungen der "App Registration" ##### Option 1 -Gehen Sie zum Register „Übersicht“ und klicken Sie auf den Anwendungsnamen (den Link hinter „Verwaltete Anwendung“). +Rufen Sie die Registerkarte "Overview" auf und klicken Sie auf den Namen der Anwendung (der Link hinter "Managed application"). ##### Option 2 -Gehe zu den „Enterprise-Anwendungen“ und suche mithilfe des zuvor erstellten Anwendungsnamens. +Rufen Sie die "Enterprise applications" auf und suchen Sie nach dem Namen der zuvor erstellten Anwendung. -#### Authentication restriction to users assigned to the application +#### Beschränkung der Authentifizierung auf zugewiesene Benutzer -Indicate here the requirement for user assignment to the application to allow authentication: +Legen Sie hier fest, dass ein Benutzer der Anwendung zugewiesen sein muss, um sich authentifizieren zu dürfen: -#### Assigning Users and Groups to the Application +#### Zuweisung von Benutzern und Gruppen zur Anwendung -Only users and groups assigned to the application will be able to sign in to your Cloud Temple organization via the app registration. +Nur die der Anwendung zugewiesenen Gruppen und Benutzer können sich über die App Registration an Ihrer Cloud-Temple-Organisation anmelden. -Finally, simply apply the assignment by clicking "Assign". +Wenden Sie die Zuweisung abschließend durch Klick auf "Assign" an. -From now on, users assigned to the application will be able to sign in to your Cloud Temple organization via the created application. +Ab jetzt können sich die der Anwendung zugewiesenen Benutzer über die erstellte Anwendung an Ihrer Cloud-Temple-Organisation anmelden. -## Step 2: Request SSO (Single Sign-On) Configuration for Your Organization +## Schritt 2: SSO-Konfiguration Ihrer Organisation beantragen -This configuration step is performed at the organization level by the Cloud Temple team. +Dieser Teil der Konfiguration wird auf Ebene der Organisation vom Cloud-Temple-Team durchgeführt. -To proceed, please __submit a support request__ in the console indicating your intention to set up Microsoft Entra ID SSO. +Stellen Sie dazu __eine Supportanfrage__ in der Konsole, in der Sie Ihren Wunsch nach einer Microsoft-EntraID-Föderation angeben, und nennen Sie: -Please provide the following information in your support request: +- den Namen Ihrer Organisation; +- den Namen eines Ansprechpartners mit E-Mail-Adresse und Telefonnummer für den Abschluss der Konfiguration; +- die in Schritt 1 notierte __Application (client) ID__; +- die in Schritt 1 notierte __Directory (tenant) ID__. -- Name of your Organization -- Name of a contact person, including their email address and phone number, to finalize the configuration -- Application ID (unique identifier associated with the previously created application) -- Directory ID (corresponds to the Azure AD tenant ID of your Azure environment) -- Secret (secret associated with the previously created application) +Übermitteln Sie das __Client Secret__ über den von Ihrem Ansprechpartner genannten sicheren Kanal und nicht im Text der Anfrage. -Once the configuration is completed on the Console side, the designated contact will be notified. +Sobald die Konfiguration auf Seite der Konsole abgeschlossen ist, wird der angegebene Ansprechpartner informiert und erhält die zu hinterlegende __"Redirect URL"__. -## Schritt 3: Abschluss der Konfiguration +## Schritt 3: Hinterlegung der "Redirect URL" -Auf der Startseite der App-Registrierung klicken Sie im Menü „Übersicht“ auf „Redirect-URL hinzufügen“. +Falls Sie die "Redirect URL" bei der Erstellung der Anwendung nicht angegeben haben, fügen Sie sie jetzt hinzu. + +Klicken Sie auf der Startseite der App Registration im Menü "Overview" auf "Add a Redirect URL". -Wechseln Sie anschließend zum Abschnitt „Plattform hinzufügen“ und fügen Sie eine Plattform des Typs „Web“ hinzu. +Rufen Sie anschließend "Add a platform" auf und fügen Sie eine Plattform vom Typ Web hinzu. -Geben Sie einfach die von der Produkt-Team Anwendungen bereitgestellte „Redirect-URL“ ein. +Geben Sie die von Cloud Temple bereitgestellte "Redirect URL" an. -Nachdem die „Redirect-URL“ hinzugefügt wurde, sollte das folgende Ergebnis angezeigt werden. +Nach dem Hinzufügen der "Redirect URL" sollten Sie dieses Ergebnis erhalten. -Die Konfiguration der „Redirect-URL“ kann einige Minuten in Anspruch nehmen, bis sie wirksam ist. -Nach Abschluss aller Schritte können Sie sich über Ihren SSO bei Ihrer Cloud Temple-Organisation authentifizieren. +Es kann einige Minuten dauern, bis die Konfiguration der "Redirect URL" wirksam wird. + +## Schritt 4: Überprüfung + +Sobald alle Schritte abgeschlossen sind, können Sie sich über Ihr SSO an Ihrer Cloud-Temple-Organisation anmelden. + +:::info[Berechtigungen neuer Benutzer] +Die Identitätsföderation regelt die __Authentifizierung__, nicht die __Berechtigungen__. Ein Benutzer, der sich zum ersten Mal über SSO anmeldet, verfügt über keinerlei Rechte, solange ein Eigentümer der Organisation ihm keine über die Konsole zugewiesen hat. +::: + +## Erneuerung des Secret + +Das Client Secret läuft spätestens 24 Monate nach seiner Erstellung ab. Nach Ablauf funktioniert die SSO-Anmeldung für sämtliche Benutzer nicht mehr. Planen Sie die Erneuerung rechtzeitig: + +1. Erstellen Sie unter "Certificates & secrets" ein __neues__ Secret, ohne das alte zu löschen; +2. übermitteln Sie dessen Wert über den sicheren Kanal an Cloud Temple, indem Sie eine Supportanfrage stellen; +3. löschen Sie das alte Secret im Azure-Portal, sobald unsere Teams die Umstellung bestätigt haben. + +Indem Sie beide Secrets während der Umstellung beibehalten, vermeiden Sie jede Betriebsunterbrechung. + +## Bewährte Vorgehensweisen + +- __Steuern Sie den Zugriff über Gruppen__ statt über einzelne Benutzer: Der Zugang oder Abgang einer Person wird dann in Ihrem Verzeichnis geregelt, ohne Eingriff in der Konsole. +- __Aktivieren Sie die Multi-Faktor-Authentifizierung__ für die Anwendung in Ihren EntraID-Richtlinien für bedingten Zugriff: Sie gilt dann auch für den Zugang zur Konsole. +- __Richten Sie eine Erinnerung__ vor dem Ablaufdatum des Secret ein. +- __Behalten Sie mindestens ein lokales Eigentümerkonto__ in Ihrer Cloud-Temple-Organisation außerhalb der Föderation, um bei Nichtverfügbarkeit Ihres Verzeichnisses weiterhin Zugang zu haben. + +## Fehlerbehebung + +| Symptom | Wahrscheinliche Ursache | +|---|---| +| `AADSTS50011`: Die Redirect-URL stimmt nicht überein | Die in Azure hinterlegte "Redirect URL" weicht von der durch Cloud Temple bereitgestellten ab. Prüfen Sie sie Zeichen für Zeichen, einschließlich eines fehlenden abschließenden `/`. | +| `AADSTS7000215`: ungültiges Secret | Das Secret ist abgelaufen, oder es wurde die "Secret ID" statt des "Value" übermittelt. | +| `AADSTS50105`: Benutzer nicht zugewiesen | Die Option "Assignment required" ist aktiv und der Benutzer ist der Anwendung nicht zugewiesen. | +| Die Anmeldeschaltfläche erscheint nicht auf der Seite | Die Konfiguration ist auf Seite von Cloud Temple noch nicht aktiv. | +| Der Benutzer wird authentifiziert, die Konsole verweigert jedoch den Zugriff | Der Claim `email` fehlt im Token, oder dem Benutzer wurden keine Rechte zugewiesen. | + +## Support + +Bei Fragen zu diesem Vorgehen stellen Sie bitte eine Supportanfrage über Ihre Konsole. Geben Sie den Namen Ihrer Organisation sowie den Zeitstempel eines fehlgeschlagenen Anmeldeversuchs an: So lässt sich der entsprechende Eintrag auffinden. diff --git a/i18n/en/docusaurus-plugin-content-docs/current/console/iam/tutorials/sso_azuread.md b/i18n/en/docusaurus-plugin-content-docs/current/console/iam/tutorials/sso_azuread.md index 33ce4ebd..ca449ac8 100644 --- a/i18n/en/docusaurus-plugin-content-docs/current/console/iam/tutorials/sso_azuread.md +++ b/i18n/en/docusaurus-plugin-content-docs/current/console/iam/tutorials/sso_azuread.md @@ -1,5 +1,5 @@ --- -title: Identity Federation Example with Microsoft EntraID +title: Identity Federation Example with Microsoft EntraID (Azure AD) tags: - iam - tutorials @@ -23,136 +23,218 @@ import ssoAad_016 from '@site/docs/console/iam/tutorials/images/sso_aad_016.png' import ssoAad_017 from '@site/docs/console/iam/tutorials/images/sso_aad_017.png' import ssoAad_018 from '@site/docs/console/iam/tutorials/images/sso_aad_018.png' -Here is an example configuration of the identity provider for a Cloud Temple organization using __Microsoft EntraID__ (Azure Active Directory). +Here is an example configuration of the identity provider for a Cloud Temple organization using __Microsoft EntraID__. -Configuring your Microsoft identity provider at the Cloud Temple organization level simplifies user authentication on the Console. This helps avoid the proliferation of authentication factors and reduces the attack surface. +Configuring your Microsoft identity provider at the Cloud Temple organization level simplifies user authentication on the Console. This helps avoid the proliferation of authentication factors and reduces the attack surface. If your users are already authenticated to their Microsoft accounts, logging into the Console services will be seamless. -If your users are already authenticated to their Microsoft accounts, logging into the Console services will be seamless and transparent. +:::info[Azure AD and Microsoft EntraID] +Microsoft EntraID is the new name of Azure Active Directory (Azure AD) since 2023. It is the same product: this tutorial applies to both names interchangeably. +::: -Below are the steps to complete this configuration: +:::info[Protocol used] +Federation with EntraID is performed using __OpenID Connect (OIDC)__. No SAML configuration is required on your side. +::: -## Step 1: SSO Configuration on Microsoft Azure Side +## Information exchanged -### Registering a New Azure Application (Azure Portal) +Setting up the federation relies on a two-way exchange. Here are the details upfront, so you can prepare everything in a single pass. -To create the __app registration__, navigate to the Microsoft Azure portal, then go to Microsoft Entra ID, and select __"Add > App Registration"__. +### What you need to send us -On the "Register an application" page, please provide the following: +| Information | Name in the Azure portal | What it is used for | +|---|---|---| +| __Application (client) ID__ | *Application (client) ID* | Identifies the application to EntraID | +| __Directory (tenant) ID__ | *Directory (tenant) ID* | Determines the OpenID Connect endpoints of your directory | +| __Client secret__ | *Client secret* → __Value__ column | Authenticates the Console to EntraID | + +Both identifiers appear in the __"Overview"__ tab of your app registration; the secret is created in the __"Certificates & secrets"__ tab. + +:::warning[Never send the secret in the body of a request] +The client secret value is an authentication credential. Do not place it in the body of a support request, in a comment, or in an unencrypted attachment: it would remain readable there permanently. + +State in your request that you have the secret, and send it through the secure channel your Cloud Temple contact will indicate. Both identifiers (Application ID and Directory ID) are not sensitive and may appear in the request. +::: + +### What Cloud Temple sends you + +The __"Redirect URL"__, specific to your organization. You must declare it in your EntraID app registration (step 3). + +:::tip[Ask for it when you open your request] +This URL depends on your organization and cannot be guessed. By requesting it when you open your support request, you can complete the entire Azure configuration in one pass, without having to come back to it. +::: + +## Step 1: SSO configuration on the Microsoft EntraID side + +### Registering a new Azure application (Azure portal) + +To create the __app registration__, go to the Microsoft Azure portal, then in Microsoft EntraID, __"ADD > App Registration"__. + +On the "Register an application" page, provide the following: ``` -- __Name__ : Enter "__SHIVA__" -- __Supported account types__ : __Accounts in this organizational directory only__ (____ only - Single tenant) -- __Redirect URL__ : Do not configure this field at this time. The URL will be provided by Cloud Temple support and should be added to this field later. +- Name: enter "SHIVA" +- Supported account types: Accounts in this organizational directory only ( only - Single tenant) +- Redirect URL: enter the URL provided by Cloud Temple. If you do not have it yet, leave the field empty and refer to step 3. ``` -The __Application (client) ID__ and __Directory (tenant) ID__ are the key details to provide in your support request to the Cloud Temple team to enable Microsoft Entra ID authentication for your organization. +The __Application (client) ID__ and __Directory (tenant) ID__ are displayed on the "Overview" tab. Make a note of them: these are two of the three pieces of information to provide in your support request. -### Definition of a Secret +### Creating a secret In the "Certificates & secrets" tab, create a new secret. -*Note: The secret's expiration date cannot exceed 24 months, even with a custom expiration date.* - -The generated secret will need to be provided in the support request: +:::warning[Copy the value immediately] +The secret value is displayed only once, right after it is created. Copy the contents of the __"Value"__ column, not the __"Secret ID"__ column. If you lose this value, you will have to generate a new secret. +::: -### Definition of EntraID Token +:::caution[Validity limited to 24 months] +The secret expiry date cannot exceed 24 months, even with a custom expiry date. __Make a note of this date now__: once it is reached, SSO will stop working for all your users. See the [Renewing the secret](#renewing-the-secret) section. +::: -The EntraID token is required for authentication configuration. +### Authorising the information used by the Console -In the _*"Token Configuration"* menu, click on __"Add optional claim"__. You will need to select "ID" as the token type and check "email". +The Console identifies your users from the information carried by the identity token. Only one action is required on your side: __exposing the email address__. + +In the __"Token Configuration"__ menu, click __"Add optional claim"__. Select "ID" as the token type and tick "email". -Azure will prompt you to grant a permission allowing you to read a user's email (Microsoft Graph email). Check the box and confirm. +The Azure interface asks whether you want to add a permission allowing it to read a user's email (Microsoft Graph email). Tick the box and confirm. -Next, go to "API permissions" and click on __"Grant admin consent for Cloud Temple"__. +Then go to "API permissions" and click __"Grant admin consent for <your organization>"__. -### Additional Security Configurations (Optional but Recommended) +For reference, here is all the information consumed by the Console: + +| Information | Usage | Action on your side | +|---|---|---| +| `email` | User's sign-in address | __Yes__ — must be declared as an optional claim (above) | +| `oid` | Stable link between the Console account and the identity in your directory, even if the email address changes | None — issued natively by EntraID | +| `given_name`, `family_name` | First name and last name shown in the Console | None — included in the `profile` scope | + +### Additional security settings (optional but recommended) -By default, Microsoft Entra ID, as configured, will allow any user from your Azure tenant to sign in to your Cloud Temple organization. -It is possible to restrict access at the __"App Registration"__ level, allowing only a specific list of users or groups to sign in to your Cloud Temple organization. +By default, Microsoft EntraID as configured will allow any user of your Azure tenant to sign in to your Cloud Temple organization. You can restrict access at the __"App Registration"__ level so that only a list of users or groups is authorised. -Follow the procedure below: +Here is the procedure to follow. -#### Access additional "App Registration" settings +#### Accessing the additional "App Registration" settings ##### Option 1 -Go to the "Overview" tab, then click on the application name (the link located next to "Managed application"). +Go to the "Overview" tab, then click the application name (the link next to "Managed application"). ##### Option 2 -Go to "Enterprise applications" and search using the name of the previously created application. +Go to "Enterprise applications" and search using the name of the application created earlier. -#### Authentication restriction to users assigned to the application +#### Restricting authentication to users assigned to the application -Indicate here the requirement for user assignment to the application to allow authentication: +Specify here that a user must be assigned to the application in order to authenticate: -#### Assigning Users and Groups to the Application +#### Assigning users and groups to the application -Only users and groups assigned to the application will be able to sign in to your Cloud Temple organization via the app registration. +Only the groups and users assigned to the application will be able to sign in to your Cloud Temple organization through the app registration. -Finally, simply apply the assignment by clicking "Assign". +Finally, apply the assignment by clicking "Assign". -From now on, assigned users will be able to sign in to your Cloud Temple organization through the created application. +Users assigned to the application can now sign in to your Cloud Temple organization through the application you created. -## Step 2: Request SSO (Single Sign-On) Configuration for Your Organization +## Step 2: Requesting the SSO configuration for your organization -This configuration step is performed at the organization level by the Cloud Temple team. +This part of the configuration is carried out at the organization level by the Cloud Temple team. -To proceed, submit a __support request__ in the console indicating your intent to set up Microsoft Entra ID SSO. +To do so, submit __a support request__ in the Console stating that you wish to configure Microsoft EntraID federation, specifying: -Please include the following information in your support request: +- your organization name; +- the name of a contact, with their email address and phone number, to finalise the configuration; +- the __Application (client) ID__ noted in step 1; +- the __Directory (tenant) ID__ noted in step 1. -- Name of your Organization -- Name of a contact person, along with their email address and phone number, to finalize the configuration -- Application ID (unique identifier associated with the previously created application) -- Directory ID (corresponds to the Azure AD tenant ID in Azure) -- Secret (secret associated with the previously created application) +Send the __client secret__ through the secure channel indicated by your contact, not in the body of the request. -Once the configuration is completed on the Console side, the designated contact will be notified. +Once the configuration is complete on the Console side, the contact you provided will be informed and will receive the __"Redirect URL"__ to declare. -## Step 3: Finalize the Configuration +## Step 3: Declaring the "Redirect URL" -On the App Registration home page, in the Overview menu, click on "Add a Redirect URL". +If you did not enter the "Redirect URL" when creating the application, add it now. + +On the App Registration home page, in the "Overview" menu, click "Add a Redirect URL". -Next, go to "Add a platform" and add one of type Web. +Then go to "Add a platform" and add one of type Web. -Simply enter the "Redirect URL" provided by the Applications Product Team. +Enter the "Redirect URL" provided by Cloud Temple. -You should see this result once the "Redirect URL" has been added. +You should get this result once the "Redirect URL" has been added. -It may take a few minutes for the "Redirect URL" configuration to take effect. -Once all steps are completed, you can authenticate to your Cloud Temple organization using your SSO. +The "Redirect URL" configuration may take a few minutes to take effect. + +## Step 4: Verification + +Once all the steps are complete, you can authenticate to your Cloud Temple organization through your SSO. + +:::info[Permissions for new users] +Identity federation handles __authentication__, not __authorisation__. A user signing in for the first time through SSO has no permissions until an organization owner grants them from the Console. +::: + +## Renewing the secret + +The client secret expires no later than 24 months after it is created. Once it expires, SSO stops working for all your users. Plan its renewal ahead: + +1. in "Certificates & secrets", create a __new__ secret without deleting the old one; +2. send its value to Cloud Temple through the secure channel, by opening a support request; +3. once our teams confirm the switchover, delete the old secret from the Azure portal. + +Keeping both secrets during the switchover avoids any service interruption. + +## Best practices + +- __Manage access through groups__ rather than individual users: a colleague joining or leaving is then handled in your directory, with no action needed on the Console. +- __Enable multi-factor authentication__ on the application in your EntraID conditional access policies: it then applies to Console access. +- __Set a reminder__ ahead of the secret expiry date. +- __Keep at least one local owner account__ on your Cloud Temple organization, outside the federation, so you retain access if your directory becomes unavailable. + +## Troubleshooting + +| Symptom | Likely cause | +|---|---| +| `AADSTS50011`: redirect URL mismatch | The "Redirect URL" declared in Azure differs from the one provided by Cloud Temple. Check it character by character, including the absence of a trailing `/`. | +| `AADSTS7000215`: invalid secret | The secret has expired, or the value sent was the "Secret ID" instead of the "Value". | +| `AADSTS50105`: user not assigned | The "Assignment required" option is enabled and the user is not assigned to the application. | +| The sign-in button does not appear on the page | The configuration is not yet active on the Cloud Temple side. | +| The user authenticates but the Console denies access | The `email` claim is missing from the token, or no permissions have been granted to the user. | + +## Support + +For any question about this procedure, open a support request from your Console. Specify your organization name and the timestamp of a failed sign-in attempt: this allows the corresponding trace to be located. diff --git a/i18n/es/docusaurus-plugin-content-docs/current/console/iam/tutorials/sso_azuread.md b/i18n/es/docusaurus-plugin-content-docs/current/console/iam/tutorials/sso_azuread.md index e1a0fbc9..8bd7feae 100644 --- a/i18n/es/docusaurus-plugin-content-docs/current/console/iam/tutorials/sso_azuread.md +++ b/i18n/es/docusaurus-plugin-content-docs/current/console/iam/tutorials/sso_azuread.md @@ -1,5 +1,5 @@ --- -title: Example of Identity Federation with Microsoft EntraID +title: Ejemplo de federación de identidad con Microsoft EntraID (Azure AD) tags: - iam - tutorials @@ -23,34 +23,63 @@ import ssoAad_016 from '@site/docs/console/iam/tutorials/images/sso_aad_016.png' import ssoAad_017 from '@site/docs/console/iam/tutorials/images/sso_aad_017.png' import ssoAad_018 from '@site/docs/console/iam/tutorials/images/sso_aad_018.png' -Here is an example configuration of the authentication repository for a Cloud Temple organization using __Microsoft EntraID__ (Azure Active Directory). +A continuación se presenta un ejemplo de configuración del repositorio de autenticación de una organización Cloud Temple con __Microsoft EntraID__. -Configuring your Microsoft EntraID repository at the Cloud Temple organization level simplifies user authentication on the Console. This helps avoid the proliferation of authentication factors and reduces the attack surface. +La configuración de su repositorio Microsoft a nivel de una organización Cloud Temple facilita la autenticación de sus usuarios en la Consola. Esto permite evitar la multiplicación de factores de autenticación y reducir la superficie de ataque. Si sus usuarios ya están autenticados en su cuenta Microsoft, la autenticación en los servicios de la Consola será transparente. -If your users are already authenticated to their Microsoft accounts, logging into the Console services will be seamless and transparent. +:::info[Azure AD y Microsoft EntraID] +Microsoft EntraID es el nuevo nombre de Azure Active Directory (Azure AD) desde 2023. Se trata del mismo producto: este tutorial se aplica indistintamente a ambas denominaciones. +::: -Below are the steps to complete this configuration: +:::info[Protocolo utilizado] +La federación con EntraID se realiza mediante __OpenID Connect (OIDC)__. No se requiere ninguna configuración SAML por su parte. +::: -## Step 1: SSO configuration on Microsoft Azure side +## Información intercambiada -### Registro de una nueva aplicación Azure (portal Azure) +La implementación se basa en un intercambio en ambos sentidos. Estos son los detalles desde el principio, para que pueda prepararlo todo de una sola vez. -Para la creación del __registro de aplicación__, debe acceder al portal Microsoft Azure, y luego a Microsoft Entra ID, seleccionando __"Agregar > Registro de aplicación"__. +### Lo que debe transmitirnos -En la página "Registrar una aplicación", indique lo siguiente: +| Información | Nombre en el portal de Azure | Para qué sirve | +|---|---|---| +| __Application (client) ID__ | *Application (client) ID* | Identifica la aplicación ante EntraID | +| __Directory (tenant) ID__ | *Directory (tenant) ID* | Determina los puntos de conexión OpenID Connect de su directorio | +| __Secreto de cliente__ | *Client secret* → columna __Value__ | Autentica la Consola ante EntraID | + +Ambos identificadores figuran en la pestaña __"Overview"__ de su registro de aplicación; el secreto se crea en la pestaña __"Certificates & secrets"__. + +:::warning[Nunca transmita el secreto en el cuerpo de una solicitud] +El valor del secreto de cliente es una credencial de autenticación. No lo incluya en el cuerpo de una solicitud de asistencia, ni en un comentario, ni en un archivo adjunto sin cifrar: permanecería allí consultable de forma duradera. + +Indique en su solicitud que dispone del secreto y transmítalo por el canal seguro que le indicará su contacto de Cloud Temple. Los dos identificadores (Application ID y Directory ID) no son sensibles y sí pueden figurar en la solicitud. +::: + +### Lo que Cloud Temple le transmite + +La __"Redirect URL"__, propia de su organización. Debe declararla en su registro de aplicación EntraID (paso 3). + +:::tip[Solicítela al abrir su petición] +Esta URL depende de su organización y no puede deducirse. Al solicitarla en el momento de abrir su solicitud de asistencia, podrá realizar toda la configuración de Azure de una sola vez, sin tener que volver sobre ella. +::: + +## Paso 1: Configuración del SSO en el lado de Microsoft EntraID + +### Registro de una nueva aplicación de Azure (portal de Azure) + +Para crear el __app registration__, diríjase al portal de Microsoft Azure y, a continuación, en Microsoft EntraID, __"ADD > App Registration"__. + +En la página "Register an application", indique lo siguiente: ``` -- __Nombre__: Escriba "__SHIVA__" -- __Tipos de cuentas compatibles__: __Cuentas solo en este directorio organizativo__ (____ solo - de un solo inquilino) -- __URL de redirección__: No configurar en este momento. La URL será proporcionada por el soporte de Cloud Temple y se deberá añadir en este campo más adelante. +- Name: indicar "SHIVA" +- Supported account types: Accounts in this organizational directory only ( only - Single tenant) +- Redirect URL: indicar la URL proporcionada por Cloud Temple. Si aún no dispone de ella, deje el campo vacío y consulte el paso 3. ``` -Las siguientes informaciones son las que deben proporcionarse en la solicitud de soporte a la equipe Cloud Temple para habilitar la autenticación de Microsoft Entra ID a nivel de su organización: - -- __Application (client) ID__ -- __Directory (tenant) ID__ +Los datos __Application (client) ID__ y __Directory (tenant) ID__ se muestran en la pestaña "Overview". Anótelos: son dos de las tres informaciones que deberá facilitar en su solicitud de asistencia. @@ -58,104 +87,154 @@ Las siguientes informaciones son las que deben proporcionarse en la solicitud de En la pestaña "Certificates & secrets", cree un nuevo secreto. -*Nota: la fecha de expiración del secreto no puede ser superior a 24 meses, incluso con una fecha de expiración personalizada.* - -El secreto generado deberá proporcionarse en la solicitud de soporte: +:::warning[Copie el valor inmediatamente] +El valor del secreto solo se muestra una vez, justo después de su creación. Copie el contenido de la columna __"Value"__, y no el de la columna __"Secret ID"__. Si pierde este valor, deberá generar un nuevo secreto. +::: -### Definición del token EntraID +:::caution[Validez limitada a 24 meses] +La fecha de expiración del secreto no puede ser superior a 24 meses, incluso con una fecha de expiración personalizada. __Anote esta fecha desde ahora__: al alcanzarla, la conexión SSO dejará de funcionar para todos sus usuarios. Consulte la sección [Renovación del secreto](#renovación-del-secreto). +::: -El token EntraID es necesario para la configuración de la autenticación. +### Autorización de la información utilizada por la Consola -En el menú __"Configuración de token"__, haga clic en __"Agregar afirmación opcional"__. Deberá seleccionar "ID" como tipo de token y marcar la opción "email". +La Consola identifica a sus usuarios a partir de la información transportada por el token de identidad. Solo se requiere una acción por su parte: __exponer la dirección de correo electrónico__. + +En el menú __"Token Configuration"__, haga clic en __"Add optional claim"__. Seleccione "ID" como tipo de token y marque "email". -La interfaz de Azure le preguntará si desea agregar un permiso que le permitirá leer el correo electrónico de un usuario (correo electrónico de Microsoft Graph); marque la casilla y confirme. +La interfaz de Azure le preguntará si desea añadir un permiso que permita leer el correo electrónico de un usuario (Microsoft Graph email). Marque la casilla y valide. -A continuación, vaya a "Permisos de API" y haga clic en __"Conceder consentimiento de administrador para Cloud Temple"__. +A continuación, diríjase a "API permissions" y haga clic en __"Grant admin consent for <su organización>"__. -### Additional security configurations (optional but recommended) +A título informativo, esta es toda la información consumida por la Consola: + +| Información | Uso | Acción por su parte | +|---|---|---| +| `email` | Dirección de conexión del usuario | __Sí__ — debe declararse como claim opcional (más arriba) | +| `oid` | Vinculación estable de la cuenta de la Consola con la identidad de su directorio, incluso si cambia la dirección de correo | Ninguna — emitido de forma nativa por EntraID | +| `given_name`, `family_name` | Nombre y apellidos mostrados en la Consola | Ninguna — incluidos en el ámbito `profile` | + +### Configuraciones de seguridad adicionales (opcional pero recomendado) -By default, Microsoft Entra ID, as configured, will allow any user in your Azure tenant to sign in to your Cloud Temple organization. -It is possible to restrict access at the __"App Registration"__ level, allowing only a specific list of users or groups to sign in to your Cloud Temple organization. +De forma predeterminada, Microsoft EntraID tal como está configurado permitirá que cualquier usuario de su tenant de Azure se conecte a su organización Cloud Temple. Es posible restringir los accesos a nivel de __"App Registration"__ para autorizar únicamente a una lista de usuarios o grupos. -Follow these steps: +Este es el procedimiento a seguir. -#### Access additional "App Registration" settings +#### Acceder a los parámetros adicionales de "App Registration" ##### Opción 1 -Vaya a la pestaña "Información general" y haga clic en el nombre de la aplicación (el enlace situado después de "Aplicación administrada"). +Vaya a la pestaña "Overview" y haga clic en el nombre de la aplicación (el enlace situado a continuación de "Managed application"). ##### Opción 2 -Diríjase a "Aplicaciones empresariales" y busque utilizando el nombre de la aplicación creada anteriormente. +Diríjase a "Enterprise applications" y busque utilizando el nombre de la aplicación creada anteriormente. -#### Authentication restriction to users assigned to the application +#### Restricción de la autenticación a los usuarios asignados a la aplicación -Indicate here the requirement for user assignment to the application to allow authentication: +Indique aquí la necesidad de una asignación del usuario a la aplicación para autorizar su autenticación: -#### Assigning users and groups to the application +#### Asignación de usuarios y grupos a la aplicación -Only the users and groups assigned to the application will be able to sign in to your Cloud Temple organization via the app registration. +Solo los grupos y usuarios asignados a la aplicación podrán conectarse a su organización Cloud Temple mediante el app registration. -Finally, you will only need to apply the assignment by clicking on "Assign". +Por último, aplique la asignación haciendo clic en "Assign". -From now on, the assigned users will be able to sign in to your Cloud Temple organization through the created application. +A partir de ahora, los usuarios asignados a la aplicación podrán conectarse a su organización Cloud Temple mediante la aplicación creada. -## Step 2: Request your organization's SSO (Single Sign-On) configuration +## Paso 2: Solicitar la configuración del SSO de su organización -This configuration step is performed at the organization level by the Cloud Temple team. +Esta parte de la configuración se realiza a nivel de la organización por parte del equipo de Cloud Temple. -To proceed, please __submit a support request__ in the console indicating your intention to set up Microsoft Entra ID SSO. +Para ello, presente __una solicitud de asistencia__ en la Consola indicando su deseo de configurar una federación Microsoft EntraID, precisando: -Include the following information in your support request: +- el nombre de su organización; +- el nombre de un contacto, con su correo electrónico y número de teléfono, para finalizar la configuración; +- el __Application (client) ID__ anotado en el paso 1; +- el __Directory (tenant) ID__ anotado en el paso 1. -- Name of your Organization -- Name of a contact person, along with their email address and phone number, to finalize the configuration -- Application ID (unique identifier associated with the previously created application) -- Directory ID (corresponds to the Azure AD tenant ID in Azure) -- Secret (secret associated with the previously created application) +Transmita el __secreto de cliente__ por el canal seguro indicado por su contacto, y no en el cuerpo de la solicitud. -Once the configuration is completed on the Console side, the designated contact will be notified. +En cuanto la configuración se realice en el lado de la Consola, se informará al contacto indicado, que recibirá la __"Redirect URL"__ que deberá declarar. -## Paso 3: Finalización de la configuración +## Paso 3: Declaración de la "Redirect URL" -En la página principal del registro de aplicaciones, en el menú Overview, haga clic en "Add a Redirect URL". +Si no indicó la "Redirect URL" durante la creación de la aplicación, añádala ahora. + +En la página de inicio del App Registration, en el menú "Overview", haga clic en "Add a Redirect URL". -A continuación, vaya al apartado "Add a platform" y agregue una plataforma del tipo Web. +A continuación, diríjase a "Add a platform" y añada una de tipo Web. -Solo necesita rellenar la "Redirect URL" proporcionada por el equipo de Productos de Aplicaciones. +Indique la "Redirect URL" proporcionada por Cloud Temple. -Una vez añadida la "Redirect URL", debería obtener este resultado. +Debería obtener este resultado una vez añadida la "Redirect URL". -La configuración de la "Redirect URL" puede tardar unos minutos en aplicarse. -Una vez completados todos los pasos, podrá autenticarse en su organización Cloud Temple mediante su SSO. +La configuración de la "Redirect URL" puede tardar unos minutos en ser efectiva. + +## Paso 4: Verificación + +Una vez realizados todos los pasos, puede autenticarse en su organización Cloud Temple mediante su SSO. + +:::info[Permisos de los nuevos usuarios] +La federación de identidad gestiona __la autenticación__, no las __autorizaciones__. Un usuario que se conecta por primera vez mediante el SSO no dispone de ningún permiso mientras un propietario de la organización no se lo haya atribuido desde la Consola. +::: + +## Renovación del secreto + +El secreto de cliente expira como máximo 24 meses después de su creación. Al vencimiento, la conexión SSO deja de funcionar para todos sus usuarios. Anticipe su renovación: + +1. en "Certificates & secrets", cree un __nuevo__ secreto sin eliminar el anterior; +2. transmita su valor a Cloud Temple por el canal seguro, abriendo una solicitud de asistencia; +3. una vez confirmada la conmutación por nuestros equipos, elimine el antiguo secreto desde el portal de Azure. + +Conservar ambos secretos durante la conmutación evita cualquier interrupción del servicio. + +## Buenas prácticas + +- __Gestione el acceso por grupos__ en lugar de por usuarios: la llegada o salida de un colaborador se trata entonces en su directorio, sin intervención en la Consola. +- __Active la autenticación multifactor__ en la aplicación desde sus directivas de acceso condicional de EntraID: se aplicará entonces al acceso a la Consola. +- __Programe una alerta__ ante la proximidad de la fecha de expiración del secreto. +- __Conserve al menos una cuenta propietaria local__ en su organización Cloud Temple, fuera de la federación, para mantener el acceso en caso de indisponibilidad de su directorio. + +## Resolución de problemas + +| Síntoma | Causa probable | +|---|---| +| `AADSTS50011`: la URL de redirección no coincide | La "Redirect URL" declarada en Azure difiere de la proporcionada por Cloud Temple. Verifíquela carácter por carácter, incluida la ausencia de `/` final. | +| `AADSTS7000215`: secreto no válido | El secreto ha expirado, o el valor transmitido era el "Secret ID" en lugar del "Value". | +| `AADSTS50105`: usuario no asignado | La opción "Assignment required" está activa y el usuario no está asignado a la aplicación. | +| El botón de conexión no aparece en la página | La configuración aún no está activa en el lado de Cloud Temple. | +| El usuario se autentica pero la Consola deniega el acceso | Falta el claim `email` en el token, o no se ha atribuido ningún permiso al usuario. | + +## Soporte + +Para cualquier duda sobre este procedimiento, abra una solicitud de asistencia desde su Consola. Indique el nombre de su organización así como la marca temporal de un intento de conexión fallido: esto permite localizar el rastro correspondiente. diff --git a/i18n/it/docusaurus-plugin-content-docs/current/console/iam/tutorials/sso_azuread.md b/i18n/it/docusaurus-plugin-content-docs/current/console/iam/tutorials/sso_azuread.md index 8ceaa7c9..de366009 100644 --- a/i18n/it/docusaurus-plugin-content-docs/current/console/iam/tutorials/sso_azuread.md +++ b/i18n/it/docusaurus-plugin-content-docs/current/console/iam/tutorials/sso_azuread.md @@ -1,5 +1,5 @@ --- -title: Esempio di federazione dell'identità con Microsoft EntraID +title: Esempio di federazione delle identità con Microsoft EntraID (Azure AD) tags: - iam - tutorials @@ -23,136 +23,218 @@ import ssoAad_016 from '@site/docs/console/iam/tutorials/images/sso_aad_016.png' import ssoAad_017 from '@site/docs/console/iam/tutorials/images/sso_aad_017.png' import ssoAad_018 from '@site/docs/console/iam/tutorials/images/sso_aad_018.png' -Ecco un esempio di configurazione del repository di autenticazione di un'organizzazione Cloud Temple con __Microsoft EntraID__ (Azure Active Directory). +Ecco un esempio di configurazione del repository di autenticazione di un'organizzazione Cloud Temple con __Microsoft EntraID__. -La configurazione del tuo repository Microsoft a livello di organizzazione Cloud Temple semplifica l'autenticazione degli utenti sulla Console. Ciò permette di evitare la moltiplicazione dei fattori di autenticazione e di ridurre la superficie di attacco. +La configurazione del vostro repository Microsoft a livello di un'organizzazione Cloud Temple facilita l'autenticazione dei vostri utenti sulla Console. Ciò consente di evitare la moltiplicazione dei fattori di autenticazione e di ridurre la superficie di attacco. Se i vostri utenti sono già autenticati sul loro account Microsoft, l'autenticazione ai servizi della Console sarà trasparente. -Se gli utenti sono autenticati con il loro account Microsoft, l'autenticazione ai servizi della Console avverrà in modo trasparente. +:::info[Azure AD e Microsoft EntraID] +Microsoft EntraID è il nuovo nome di Azure Active Directory (Azure AD) dal 2023. Si tratta dello stesso prodotto: questo tutorial si applica indifferentemente a entrambe le denominazioni. +::: -Di seguito sono riportati i diversi passaggi necessari per completare questa configurazione: +:::info[Protocollo utilizzato] +La federazione con EntraID viene realizzata tramite __OpenID Connect (OIDC)__. Non è necessaria alcuna configurazione SAML da parte vostra. +::: -## Step 1: SSO configuration on Microsoft Azure side +## Le informazioni scambiate -### Registration of a new Azure application (Azure portal) +L'implementazione si basa su uno scambio nei due sensi. Eccone il dettaglio fin da subito, per consentirvi di preparare tutto in un'unica volta. -To create the __app registration__, go to the Microsoft Azure portal, then navigate to Microsoft Entra ID, and select __"Add > App Registration"__. +### Ciò che dovete trasmetterci -In the "Register an application" page, please specify: +| Informazione | Nome nel portale Azure | A cosa serve | +|---|---|---| +| __Application (client) ID__ | *Application (client) ID* | Identifica l'applicazione presso EntraID | +| __Directory (tenant) ID__ | *Directory (tenant) ID* | Determina gli endpoint OpenID Connect della vostra directory | +| __Secret client__ | *Client secret* → colonna __Value__ | Autentica la Console presso EntraID | + +I due identificatori figurano nella scheda __"Overview"__ della vostra registrazione applicativa; il secret viene creato nella scheda __"Certificates & secrets"__. + +:::warning[Non trasmettete mai il secret nel corpo di una richiesta] +Il valore del secret client è una credenziale di autenticazione. Non inseritelo nel corpo di una richiesta di assistenza, né in un commento, né in un allegato non cifrato: vi resterebbe consultabile in modo duraturo. + +Indicate nella vostra richiesta che disponete del secret, e trasmettetelo tramite il canale sicuro che il vostro referente Cloud Temple vi indicherà. I due identificatori (Application ID e Directory ID) non sono sensibili e possono invece figurare nella richiesta. +::: + +### Ciò che Cloud Temple vi trasmette + +La __"Redirect URL"__, specifica della vostra organizzazione. Va dichiarata nella vostra registrazione applicativa EntraID (fase 3). + +:::tip[Richiedetela all'apertura della vostra domanda] +Questa URL dipende dalla vostra organizzazione e non può essere indovinata. Richiedendola all'apertura della vostra richiesta di assistenza, potrete realizzare tutta la configurazione Azure in un'unica volta, senza doverci ritornare. +::: + +## Fase 1: Configurazione dell'SSO lato Microsoft EntraID + +### Registrazione di una nuova applicazione Azure (portale Azure) + +Per la creazione dell'__app registration__, recatevi sul portale Microsoft Azure, poi in Microsoft EntraID, __"ADD > App Registration"__. + +Nella pagina "Register an application", indicate quanto segue: ``` -- __Name__ : Enter "__SHIVA__" -- __Supported account types__ : __Accounts in this organizational directory only__ (____ only - Single tenant) -- __Redirect URL__ : Do not configure this field at this stage. The URL will be provided by Cloud Temple support and should be added to this field later. +- Name: indicare "SHIVA" +- Supported account types: Accounts in this organizational directory only ( only - Single tenant) +- Redirect URL: indicare l'URL fornita da Cloud Temple. Se non ne disponete ancora, lasciate il campo vuoto e fate riferimento alla fase 3. ``` -The __Application (client) ID__ and __Directory (tenant) ID__ are the key details to provide in your support request to the Cloud Temple team to enable Microsoft Entra ID authentication for your organization. +Le informazioni __Application (client) ID__ e __Directory (tenant) ID__ sono visualizzate nella scheda "Overview". Annotatele: sono due delle tre informazioni da fornire nella vostra richiesta di assistenza. -### Definizione di un segreto - -Nella scheda "Certificates & secrets", creare un nuovo segreto. +### Definizione di un secret -*Nota: la data di scadenza del segreto non può essere superiore a 24 mesi, anche con una data di scadenza personalizzata.* +Nella scheda "Certificates & secrets", create un nuovo secret. -Il segreto generato dovrà essere fornito nella richiesta di supporto: +:::warning[Copiate il valore immediatamente] +Il valore del secret viene visualizzato una sola volta, subito dopo la sua creazione. Copiate il contenuto della colonna __"Value"__, e non quello della colonna __"Secret ID"__. Se perdete questo valore, dovrete generare un nuovo secret. +::: -### Definizione del token EntraID +:::caution[Validità limitata a 24 mesi] +La data di scadenza del secret non può essere superiore a 24 mesi, anche con una data di scadenza personalizzata. __Annotate fin da ora questa data__: alla scadenza, la connessione SSO cesserà di funzionare per tutti i vostri utenti. Vedere la sezione [Rinnovo del secret](#rinnovo-del-secret). +::: -Il token EntraID è necessario per la configurazione dell'autenticazione. +### Autorizzazione delle informazioni utilizzate dalla Console -Nel menu __"Token Configuration"__, fare clic su __"Add optional claim"__. Selezionare "ID" come tipo di token e selezionare la voce "email". +La Console identifica i vostri utenti a partire dalle informazioni trasportate dal token di identità. È necessaria una sola azione da parte vostra: __esporre l'indirizzo e-mail__. + +Nel menu __"Token Configuration"__, cliccate su __"Add optional claim"__. Selezionate "ID" come tipo di token e spuntate "email". -L'interfaccia Azure vi chiederà se desiderate aggiungere un'autorizzazione che vi permetterà di leggere l'email di un utente (Microsoft Graph email), selezionare la casella e confermare. +L'interfaccia Azure vi chiederà se desiderate aggiungere un'autorizzazione che consenta di leggere l'e-mail di un utente (Microsoft Graph email). Spuntate la casella e confermate. -Successivamente, recarsi su "API permissions" e fare clic su __"Grant admin consent for Cloud Temple"__. +Recatevi poi su "API permissions" e cliccate su __"Grant admin consent for <la vostra organizzazione>"__. -### Additional security configurations (optional but recommended) +A titolo informativo, ecco l'insieme delle informazioni consumate dalla Console: + +| Informazione | Utilizzo | Azione da parte vostra | +|---|---|---| +| `email` | Indirizzo di connessione dell'utente | __Sì__ — da dichiarare come claim opzionale (sopra) | +| `oid` | Collegamento stabile tra l'account Console e l'identità della vostra directory, anche se l'indirizzo e-mail cambia | Nessuna — emesso nativamente da EntraID | +| `given_name`, `family_name` | Nome e cognome visualizzati nella Console | Nessuna — inclusi nell'ambito `profile` | + +### Configurazioni di sicurezza supplementari (opzionale ma consigliato) -By default, Microsoft Entra ID, as configured, will allow any user from your Azure tenant to sign in to your Cloud Temple organization. -It is possible to restrict access at the __"App Registration"__ level, allowing only a specific list of users or groups to sign in to your Cloud Temple organization. +Per impostazione predefinita, Microsoft EntraID così configurato consentirà a qualsiasi utente del vostro tenant Azure di connettersi alla vostra organizzazione Cloud Temple. È possibile limitare a livello di __"App Registration"__ gli accessi per autorizzare solo un elenco di utenti o gruppi. -Follow these steps: +Ecco la procedura da seguire. -#### Accedere alle impostazioni aggiuntive "App Registration" +#### Accedere ai parametri supplementari "App Registration" ##### Opzione 1 -Vai sulla scheda "Overview" e fai clic sul nome dell'applicazione (il collegamento situato dopo "Managed application"). +Andate sulla scheda "Overview" e cliccate sul nome dell'applicazione (il link situato dopo "Managed application"). ##### Opzione 2 -Passare alle "Applicazioni aziendali" e cercare utilizzando il nome dell'applicazione creata in precedenza. +Recatevi nelle "Enterprise applications" e cercate utilizzando il nome dell'applicazione creata in precedenza. -#### Authentication restriction to users assigned to the application +#### Limitazione dell'autenticazione agli utenti assegnati all'applicazione -Indicate here the need for user assignment to the application to allow authentication: +Indicate qui la necessità di un'assegnazione dell'utente all'applicazione per autorizzarne l'autenticazione: -#### Assegnazione di utenti e gruppi all'applicazione +#### Assegnazione degli utenti e dei gruppi all'applicazione -Solo gli utenti e i gruppi assegnati all'applicazione potranno accedere alla vostra organizzazione Cloud Temple tramite la registrazione dell'applicazione. +Solo i gruppi e gli utenti assegnati all'applicazione potranno connettersi alla vostra organizzazione Cloud Temple tramite l'app registration. -Infine, dovrete applicare l'assegnazione facendo clic su "Assegna". +Infine, applicate l'assegnazione cliccando su "Assign". -A partire da ora, gli utenti assegnati all'applicazione potranno accedere alla vostra organizzazione Cloud Temple tramite l'applicazione creata. +Da questo momento gli utenti assegnati all'applicazione potranno connettersi alla vostra organizzazione Cloud Temple tramite l'applicazione creata. -## Step 2: Request your organization's SSO (Single Sign-On) configuration +## Fase 2: Richiedere la configurazione dell'SSO della vostra organizzazione -This configuration step is performed at the organization level by the Cloud Temple team. +Questa parte della configurazione viene effettuata a livello dell'organizzazione dal team Cloud Temple. -To proceed, please __submit a support request__ in the console indicating your intention to set up Microsoft Entra ID SSO. +A tal fine, presentate __una richiesta di assistenza__ nella Console indicando il vostro desiderio di configurare una federazione Microsoft EntraID, precisando: -Please include the following information in your support request: +- il nome della vostra organizzazione; +- il nome di un referente, con la sua e-mail e il suo numero di telefono, per finalizzare la configurazione; +- l'__Application (client) ID__ annotato alla fase 1; +- il __Directory (tenant) ID__ annotato alla fase 1. -- Name of your Organization -- Name of a contact person, along with their email address and phone number, to finalize the configuration -- Application ID (unique identifier associated with the previously created application) -- Directory ID (corresponds to the Azure AD tenant ID of your Azure environment) -- Secret (secret associated with the previously created application) +Trasmettete il __secret client__ tramite il canale sicuro indicato dal vostro referente, e non nel corpo della richiesta. -Once the configuration is completed on the Console side, the designated contact will be notified. +Non appena la configurazione sarà realizzata lato Console, il referente indicato ne sarà informato e riceverà la __"Redirect URL"__ da dichiarare. -## Step 3: Finalization of the configuration +## Fase 3: Dichiarazione della "Redirect URL" -On the App Registration home page, in the Overview menu, click on "Add a Redirect URL". +Se non avete indicato la "Redirect URL" al momento della creazione dell'applicazione, aggiungetela ora. + +Nella pagina iniziale dell'App Registration, nel menu "Overview", cliccate su "Add a Redirect URL". -Next, go to "Add a platform" and add one of type Web. +Dirigetevi poi verso "Add a platform" e aggiungetene una di tipo Web. -Enter the "Redirect URL" provided by the Applications Product Team. +Indicate la "Redirect URL" fornita da Cloud Temple. -You should see this result once the "Redirect URL" has been added. +Dovreste ottenere questo risultato una volta aggiunta la "Redirect URL". -The configuration of the "Redirect URL" may take a few minutes to take effect. -Once all steps are completed, you can authenticate to your Cloud Temple organization via your SSO. +La configurazione della "Redirect URL" può richiedere qualche minuto per diventare effettiva. + +## Fase 4: Verifica + +Una volta realizzate tutte le fasi, potete autenticarvi alla vostra organizzazione Cloud Temple tramite il vostro SSO. + +:::info[Diritti dei nuovi utenti] +La federazione delle identità gestisce __l'autenticazione__, non le __autorizzazioni__. Un utente che si connette per la prima volta tramite l'SSO non dispone di alcun diritto finché un proprietario dell'organizzazione non gliene ha attribuiti dalla Console. +::: + +## Rinnovo del secret + +Il secret client scade al più tardi 24 mesi dopo la sua creazione. Alla scadenza, la connessione SSO cessa di funzionare per tutti i vostri utenti. Anticipatene il rinnovo: + +1. in "Certificates & secrets", create un __nuovo__ secret senza eliminare il precedente; +2. trasmettetene il valore a Cloud Temple tramite il canale sicuro, aprendo una richiesta di assistenza; +3. una volta confermato il passaggio dai nostri team, eliminate il vecchio secret dal portale Azure. + +Conservare i due secret durante il passaggio evita qualsiasi interruzione di servizio. + +## Buone pratiche + +- __Gestite l'accesso per gruppi__ anziché per utenti: l'arrivo o la partenza di un collaboratore viene allora trattato nella vostra directory, senza intervento sulla Console. +- __Attivate l'autenticazione a più fattori__ sull'applicazione nelle vostre politiche di accesso condizionale EntraID: si applicherà allora all'accesso alla Console. +- __Programmate un avviso__ all'avvicinarsi della data di scadenza del secret. +- __Conservate almeno un account proprietario locale__ sulla vostra organizzazione Cloud Temple, al di fuori della federazione, per mantenere un accesso in caso di indisponibilità della vostra directory. + +## Risoluzione dei problemi + +| Sintomo | Causa probabile | +|---|---| +| `AADSTS50011`: l'URL di reindirizzamento non corrisponde | La "Redirect URL" dichiarata in Azure differisce da quella fornita da Cloud Temple. Verificatela carattere per carattere, compresa l'assenza di `/` finale. | +| `AADSTS7000215`: secret non valido | Il secret è scaduto, oppure il valore trasmesso era il "Secret ID" anziché il "Value". | +| `AADSTS50105`: utente non assegnato | L'opzione "Assignment required" è attiva e l'utente non è assegnato all'applicazione. | +| Il pulsante di connessione non appare nella pagina | La configurazione non è ancora attiva lato Cloud Temple. | +| L'utente è autenticato ma la Console rifiuta l'accesso | Il claim `email` è assente dal token, oppure nessun diritto è stato attribuito all'utente. | + +## Supporto + +Per qualsiasi domanda su questa procedura, aprite una richiesta di assistenza dalla vostra Console. Precisate il nome della vostra organizzazione nonché l'orario di un tentativo di connessione fallito: ciò consente di ritrovare la traccia corrispondente. diff --git a/scripts/translate_py/translation-meta.json b/scripts/translate_py/translation-meta.json index 31a782f0..6d7a6095 100644 --- a/scripts/translate_py/translation-meta.json +++ b/scripts/translate_py/translation-meta.json @@ -103,10 +103,10 @@ "it": "606b1e74af281a97dc6c45adc4a7e5fcf461776e0cdf2ea86945b3ceabe9d7d0" }, "console/iam/tutorials/sso_azuread.md": { - "en": "5f7663bd054a82964ede9dfe11dc45e6a2a79624c7b924bafce3f9fd91195fec", - "de": "5f7663bd054a82964ede9dfe11dc45e6a2a79624c7b924bafce3f9fd91195fec", - "es": "5f7663bd054a82964ede9dfe11dc45e6a2a79624c7b924bafce3f9fd91195fec", - "it": "5f7663bd054a82964ede9dfe11dc45e6a2a79624c7b924bafce3f9fd91195fec" + "en": "a2816415fe1eb55b7cf314d1906133321b7cd371bf5336a1b6d5b825f26d8203", + "de": "a2816415fe1eb55b7cf314d1906133321b7cd371bf5336a1b6d5b825f26d8203", + "es": "a2816415fe1eb55b7cf314d1906133321b7cd371bf5336a1b6d5b825f26d8203", + "it": "a2816415fe1eb55b7cf314d1906133321b7cd371bf5336a1b6d5b825f26d8203" }, "console/iam/tutorials/sso_intune.md": { "en": "2a5fc99951f052a2c71188580b1c2b51df998ab9b958fd09d4bd4d3160ec7878", From 16b21786f9efa125971aeae0177678d0f2f7a480 Mon Sep 17 00:00:00 2001 From: KChapron Date: Tue, 18 Aug 2026 16:45:41 +0200 Subject: [PATCH 2/3] =?UTF-8?q?docs(iam):=20=C3=A9tend=20le=20tutoriel=20E?= =?UTF-8?q?ntraID=20au=20protocole=20SAML=202.0?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Le tutoriel ne couvrait qu'OpenID Connect. Il couvre désormais les deux protocoles standards supportés par EntraID, dans une page unique plutôt que deux tutoriels séparés. - ajoute une section « Choisir le protocole » comparant ce que le client transmet, le secret échangé et ce qui est à entretenir dans la durée - dédouble « Les informations échangées » : trois valeurs en OpenID Connect, une URL de métadonnées publique en SAML - scinde l'étape 1 en deux voies, qui reconvergent sur la restriction d'accès commune aux deux protocoles - documente le NameID comme point de vigilance principal en SAML : par défaut EntraID émet l'adresse e-mail, ce qui fait perdre ses droits à un utilisateur dont l'adresse change - couvre le renouvellement du certificat de signature en plus du secret - ajoute une colonne « Protocole » au tableau de dépannage Les dix-sept captures d'écran restent rattachées à la voie OpenID Connect. Répercuté sur les cinq langues. --- docs/console/iam/tutorials/sso_azuread.md | 139 ++++++++++++++---- .../console/iam/tutorials/sso_azuread.md | 137 +++++++++++++---- .../console/iam/tutorials/sso_azuread.md | 139 ++++++++++++++---- .../console/iam/tutorials/sso_azuread.md | 139 ++++++++++++++---- .../console/iam/tutorials/sso_azuread.md | 139 ++++++++++++++---- 5 files changed, 564 insertions(+), 129 deletions(-) diff --git a/docs/console/iam/tutorials/sso_azuread.md b/docs/console/iam/tutorials/sso_azuread.md index 9b239f04..f94c9897 100644 --- a/docs/console/iam/tutorials/sso_azuread.md +++ b/docs/console/iam/tutorials/sso_azuread.md @@ -31,15 +31,25 @@ La configuration de votre référentiel Microsoft au niveau d'une organisation C Microsoft EntraID est le nouveau nom d'Azure Active Directory (Azure AD) depuis 2023. Il s'agit du même produit : ce tutoriel s'applique indifféremment aux deux appellations. ::: -:::info[Protocole utilisé] -La fédération avec EntraID est réalisée en __OpenID Connect (OIDC)__. Aucune configuration SAML n'est nécessaire de votre côté. -::: +## Choisir le protocole + +La fédération avec EntraID peut être réalisée avec l'un ou l'autre des deux protocoles standards. Les deux offrent un niveau de sécurité équivalent ; ils diffèrent principalement par ce que vous avez à nous transmettre et par ce qu'il faudra entretenir dans la durée. + +| | OpenID Connect | SAML 2.0 | +|---|---|---| +| Ce que vous nous transmettez | Deux identifiants et un secret | Une URL de métadonnées publique | +| Secret échangé | Oui, le secret client | Aucun | +| À entretenir dans le temps | Le secret client (24 mois maximum) | Le certificat de signature (3 ans par défaut) | + +__En l'absence de contrainte particulière, nous recommandons OpenID Connect__ : c'est le protocole que nous déployons par défaut. Retenez SAML si votre politique interne l'impose, ou si votre annuaire est raccordé à un concentrateur de fédération qui ne parle que ce protocole. + +Indiquez le protocole retenu dès l'ouverture de votre demande d'assistance. ## Les informations échangées La mise en place repose sur un échange dans les deux sens. En voici le détail d'emblée, pour vous permettre de tout préparer en une seule passe. -### Ce que vous devez nous transmettre +### Ce que vous devez nous transmettre — en OpenID Connect | Information | Nom dans le portail Azure | À quoi elle sert | |---|---|---| @@ -49,6 +59,26 @@ La mise en place repose sur un échange dans les deux sens. En voici le détail Les deux identifiants figurent dans l'onglet __"Overview"__ de votre inscription d'application ; le secret se crée dans l'onglet __"Certificates & secrets"__. +### Ce que vous devez nous transmettre — en SAML 2.0 + +Une seule information suffit dans le cas courant : + +| Information | Nom dans le portail Azure | À quoi elle sert | +|---|---|---| +| __URL des métadonnées de fédération__ | *App Federation Metadata Url* | Nous en dérivons l'identifiant de votre annuaire, ses points de terminaison et son certificat de signature | + +Elle se présente sous cette forme : + +``` +https://login.microsoftonline.com//federationmetadata/2007-06/federationmetadata.xml?appid= +``` + +Vous la trouvez dans __"Enterprise applications"__ → votre application → __"Single sign-on"__, section *SAML Certificates*. Elle est publique et ne contient aucun secret : elle peut figurer dans le corps de votre demande. + +:::tip[Pourquoi cette URL plutôt qu'une liste de paramètres] +Elle regroupe en une seule valeur l'ensemble des paramètres de votre annuaire et simplifie le suivi du renouvellement de votre certificat de signature. Si cette URL n'est pas joignable depuis Internet, transmettez à la place l'*Identity provider entity ID*, la *Single Sign-On service URL*, la *Single Logout service URL* et le certificat de signature au format __Certificate (Base64)__. +::: + :::warning[Ne transmettez jamais le secret dans le corps d'une demande] La valeur du secret client est un identifiant d'authentification. Ne la déposez pas dans le corps d'une demande d'assistance, ni dans un commentaire, ni dans une pièce jointe non chiffrée : elle y resterait consultable de façon durable. @@ -57,15 +87,25 @@ Indiquez dans votre demande que vous disposez du secret, et transmettez-le par l ### Ce que Cloud Temple vous transmet -La __"Redirect URL"__, propre à votre organisation. Elle est à déclarer dans votre inscription d'application EntraID (étape 3). +Des valeurs propres à votre organisation, à déclarer dans votre application EntraID : + +| Notre terme | Terme Microsoft | Protocole | +|---|---|---| +| URL de redirection | *Redirect URL* | OpenID Connect | +| URL de redirection | *Reply URL (Assertion Consumer Service URL)* | SAML 2.0 | +| Identifiant du fournisseur de service | *Identifier (Entity ID)* | SAML 2.0 | -:::tip[Demandez-la dès l'ouverture de votre demande] -Cette URL dépend de votre organisation et ne peut pas être devinée. En la demandant dès l'ouverture de votre demande d'assistance, vous pourrez réaliser toute la configuration Azure en une seule fois, sans avoir à y revenir. +:::tip[Demandez-les dès l'ouverture de votre demande] +Ces valeurs dépendent de votre organisation et ne peuvent pas être devinées. En les demandant dès l'ouverture de votre demande d'assistance, vous pourrez réaliser toute la configuration Azure en une seule fois, sans avoir à y revenir. ::: ## Étape 1 : Configuration du SSO côté Microsoft EntraID -### Enregistrement d'une nouvelle application Azure (portail Azure) +Suivez la section correspondant au protocole retenu, puis la section « Configurations de sécurité supplémentaires », commune aux deux. + +### Voie OpenID Connect + +#### Enregistrement d'une nouvelle application Azure (portail Azure) Pour la création de l'__app registration__, rendez-vous sur le portail Microsoft Azure, puis dans Microsoft EntraID, __"ADD > App Registration"__. @@ -83,7 +123,7 @@ Les informations __Application (client) ID__ et __Directory (tenant) ID__ sont a -### Définition d'un secret +#### Définition d'un secret Dans l'onglet "Certificates & secrets", créez un nouveau secret. @@ -96,10 +136,10 @@ La valeur du secret n'est affichée qu'une seule fois, juste après sa création :::caution[Durée de validité limitée à 24 mois] -La date d'expiration du secret ne peut être supérieure à 24 mois, y compris avec une date d'expiration personnalisée. __Notez dès maintenant cette date__ : à son échéance, la connexion SSO cessera de fonctionner pour l'ensemble de vos utilisateurs. Voir la section [Renouvellement du secret](#renouvellement-du-secret). +La date d'expiration du secret ne peut être supérieure à 24 mois, y compris avec une date d'expiration personnalisée. __Notez dès maintenant cette date__ : à son échéance, la connexion SSO cessera de fonctionner pour l'ensemble de vos utilisateurs. Voir la section [Maintien de la fédération dans le temps](#maintien-de-la-fédération-dans-le-temps). ::: -### Autorisation des informations utilisées par la Console +#### Autorisation des informations utilisées par la Console La Console identifie vos utilisateurs à partir des informations transportées par le jeton d'identité. Une seule action est nécessaire de votre part : __exposer l'adresse e-mail__. @@ -123,6 +163,37 @@ Pour information, voici l'ensemble des informations consommées par la Console : | `oid` | Rattachement stable du compte Console à l'identité de votre annuaire, y compris si l'adresse e-mail change | Aucune — émis nativement par EntraID | | `given_name`, `family_name` | Prénom et nom affichés dans la Console | Aucune — inclus dans le périmètre `profile` | +### Voie SAML 2.0 + +#### Création de l'application d'entreprise + +Dans __Microsoft EntraID__, rendez-vous dans __"Enterprise applications"__, puis __"New application"__. Choisissez __"Create your own application"__, nommez-la, et sélectionnez *Integrate any other application you don't find in the gallery (Non-gallery)*. Validez avec __"Create"__. + +#### Configuration de l'authentification unique + +Dans votre application, ouvrez __"Single sign-on"__ et choisissez __"SAML"__. Dans __"Basic SAML Configuration"__, cliquez sur __"Edit"__ et renseignez avec les valeurs fournies par Cloud Temple : + +- __Identifier (Entity ID)__ ; +- __Reply URL (Assertion Consumer Service URL)__. + +Enregistrez. + +#### Attributs et revendications + +EntraID émet par défaut les revendications attendues par la Console. Vérifiez leur présence dans __"Attributes & Claims"__ : + +| Revendication | Usage | Action de votre part | +|---|---|---| +| `…/claims/emailaddress` | Adresse de connexion de l'utilisateur | Aucune — source `user.mail` | +| `http://schemas.microsoft.com/identity/claims/objectidentifier` | Rattachement stable du compte Console à l'identité de votre annuaire | Aucune | +| `…/claims/givenname`, `…/claims/surname` | Prénom et nom affichés dans la Console | Aucune | + +:::warning[Identifiant de nom (NameID) : le point le plus souvent manqué] +Dans __"Attributes & Claims"__ → __"Unique User Identifier (Name ID)"__, positionnez la source sur __user.objectid__ et le format sur __Persistent__. + +Par défaut, EntraID émet l'adresse e-mail comme NameID. Si un utilisateur change d'adresse, la Console le traiterait comme une personne différente et il perdrait ses droits. L'identifiant d'objet, lui, ne change jamais. +::: + ### Configurations de sécurité supplémentaires (optionnel mais recommandé) Par défaut, Microsoft EntraID tel que configuré donnera à n'importe quel utilisateur de votre tenant Azure la possibilité de se connecter à votre organisation Cloud Temple. Il est possible de restreindre au niveau de l'__"App Registration"__ les accès pour n'autoriser qu'une liste d'utilisateurs ou de groupes. @@ -168,18 +239,21 @@ Cette partie de la configuration se fait au niveau de l'organisation par l'équi Pour ce faire, faites __une demande d'assistance__ dans la Console indiquant votre souhait de configurer une fédération Microsoft EntraID, en précisant : - le nom de votre organisation ; +- __le protocole retenu__ : OpenID Connect ou SAML 2.0 ; - le nom d'un contact, avec son adresse e-mail et son numéro de téléphone, pour finaliser la configuration ; -- l'__Application (client) ID__ relevé à l'étape 1 ; -- le __Directory (tenant) ID__ relevé à l'étape 1. +- __en OpenID Connect__ : l'__Application (client) ID__ et le __Directory (tenant) ID__ relevés à l'étape 1 ; +- __en SAML 2.0__ : l'__URL des métadonnées de fédération__ de votre application. -Transmettez le __secret client__ par le canal sécurisé indiqué par votre contact, et non dans le corps de la demande. +En OpenID Connect, transmettez le __secret client__ par le canal sécurisé indiqué par votre contact, et non dans le corps de la demande. En SAML, aucun secret n'est échangé. -Dès que la configuration est réalisée côté Console, le contact indiqué en sera informé et recevra la __"Redirect URL"__ à déclarer. +Dès que la configuration est réalisée côté Console, le contact indiqué en sera informé. -## Étape 3 : Déclaration de la "Redirect URL" +## Étape 3 : Déclaration de la "Redirect URL" (OpenID Connect) Si vous n'avez pas renseigné la "Redirect URL" lors de la création de l'application, ajoutez-la maintenant. +En SAML 2.0, les URL équivalentes ont déjà été déclarées dans __"Basic SAML Configuration"__ à l'étape 1 : passez directement à l'étape 4. + Sur la page d'accueil de l'App Registration, dans le menu "Overview", cliquez sur "Add a Redirect URL". @@ -208,9 +282,13 @@ Une fois toutes les étapes réalisées, vous pouvez vous authentifier à votre La fédération d'identité gère __l'authentification__, pas les __autorisations__. Un utilisateur qui se connecte pour la première fois via le SSO ne dispose d'aucun droit tant qu'un propriétaire de l'organisation ne lui en a pas attribué depuis la Console. ::: -## Renouvellement du secret +## Maintien de la fédération dans le temps + +C'est le principal point de vigilance : quel que soit le protocole, un élément expire, et son expiration interrompt le SSO __pour l'ensemble de vos utilisateurs__. -Le secret client expire au plus tard 24 mois après sa création. À son échéance, la connexion SSO cesse de fonctionner pour l'ensemble de vos utilisateurs. Anticipez son renouvellement : +### En OpenID Connect : le secret client + +Le secret client expire au plus tard 24 mois après sa création. Anticipez son renouvellement : 1. dans "Certificates & secrets", créez un __nouveau__ secret sans supprimer l'ancien ; 2. transmettez sa valeur à Cloud Temple par le canal sécurisé, en ouvrant une demande d'assistance ; @@ -218,22 +296,31 @@ Le secret client expire au plus tard 24 mois après sa création. À son échéa Conserver les deux secrets le temps de la bascule évite toute interruption de service. +### En SAML 2.0 : le certificat de signature + +Le certificat de signature émis par EntraID a une durée de vie limitée, de trois ans par défaut. + +__Prévenez-nous avant toute rotation de certificat__, via une demande d'assistance, en respectant la période de recouvrement proposée par Microsoft. Si vous nous avez transmis un certificat sous forme de fichier plutôt que l'URL de métadonnées, joignez le nouveau certificat à votre demande. + ## Bonnes pratiques - __Pilotez l'accès par groupes__ plutôt que par utilisateurs : l'arrivée ou le départ d'un collaborateur se traite alors dans votre annuaire, sans intervention sur la Console. - __Activez l'authentification multifacteur__ sur l'application dans vos stratégies d'accès conditionnel EntraID : elle s'applique alors à l'accès à la Console. -- __Programmez une alerte__ à l'approche de la date d'expiration du secret. +- __Programmez une alerte__ à l'approche de la date d'expiration du secret client ou du certificat de signature, selon le protocole retenu. - __Conservez au moins un compte propriétaire local__ sur votre organisation Cloud Temple, non fédéré, afin de garder un accès en cas d'indisponibilité de votre annuaire. ## Dépannage -| Symptôme | Cause probable | -|---|---| -| `AADSTS50011` : l'URL de redirection ne correspond pas | La "Redirect URL" déclarée dans Azure diffère de celle fournie par Cloud Temple. Vérifiez-la caractère par caractère, y compris l'absence de `/` final. | -| `AADSTS7000215` : secret invalide | Le secret a expiré, ou la valeur transmise était le "Secret ID" au lieu de la "Value". | -| `AADSTS50105` : utilisateur non assigné | L'option "Assignment required" est active et l'utilisateur n'est pas assigné à l'application. | -| Le bouton de connexion n'apparaît pas sur la page | La configuration n'est pas encore active côté Cloud Temple. | -| L'utilisateur est authentifié mais la Console refuse l'accès | Le claim `email` est absent du jeton, ou aucun droit n'a été attribué à l'utilisateur. | +| Symptôme | Protocole | Cause probable | +|---|---|---| +| `AADSTS50011` : l'URL de redirection ne correspond pas | Les deux | L'URL déclarée dans Azure diffère de celle fournie par Cloud Temple. Vérifiez-la caractère par caractère, y compris l'absence de `/` final. | +| `AADSTS700016` : application introuvable | SAML 2.0 | L'*Entity ID* déclaré ne correspond pas à celui fourni par Cloud Temple. | +| `AADSTS7000215` : secret invalide | OpenID Connect | Le secret a expiré, ou la valeur transmise était le "Secret ID" au lieu de la "Value". | +| `AADSTS50105` : utilisateur non assigné | Les deux | L'option "Assignment required" est active et l'utilisateur n'est pas assigné à l'application. | +| Le bouton de connexion n'apparaît pas sur la page | Les deux | La configuration n'est pas encore active côté Cloud Temple. | +| L'utilisateur est authentifié mais la Console refuse l'accès | Les deux | L'adresse e-mail est absente du jeton, ou aucun droit n'a été attribué à l'utilisateur. | +| L'utilisateur apparaît comme un nouveau compte à chaque connexion | SAML 2.0 | Le NameID n'est pas positionné sur `user.objectid`. | +| Erreur de signature à l'arrivée sur la Console | SAML 2.0 | Le certificat de signature a été renouvelé côté Azure sans que nous en soyons informés. | ## Support diff --git a/i18n/de/docusaurus-plugin-content-docs/current/console/iam/tutorials/sso_azuread.md b/i18n/de/docusaurus-plugin-content-docs/current/console/iam/tutorials/sso_azuread.md index fc3bff7c..04807c5f 100644 --- a/i18n/de/docusaurus-plugin-content-docs/current/console/iam/tutorials/sso_azuread.md +++ b/i18n/de/docusaurus-plugin-content-docs/current/console/iam/tutorials/sso_azuread.md @@ -31,15 +31,25 @@ Die Konfiguration Ihres Microsoft-Verzeichnisses auf Ebene einer Cloud-Temple-Or Microsoft EntraID ist seit 2023 der neue Name von Azure Active Directory (Azure AD). Es handelt sich um dasselbe Produkt: Dieses Tutorial gilt gleichermaßen für beide Bezeichnungen. ::: -:::info[Verwendetes Protokoll] -Die Föderation mit EntraID erfolgt über __OpenID Connect (OIDC)__. Eine SAML-Konfiguration ist auf Ihrer Seite nicht erforderlich. -::: +## Auswahl des Protokolls + +Die Föderation mit EntraID lässt sich mit einem der beiden Standardprotokolle umsetzen. Beide bieten ein gleichwertiges Sicherheitsniveau; sie unterscheiden sich vor allem darin, was Sie uns übermitteln müssen und was dauerhaft zu pflegen ist. + +| | OpenID Connect | SAML 2.0 | +|---|---|---| +| Was Sie uns übermitteln | Zwei Kennungen und ein Secret | Eine öffentliche Metadaten-URL | +| Ausgetauschtes Secret | Ja, das Client Secret | Keines | +| Dauerhaft zu pflegen | Das Client Secret (höchstens 24 Monate) | Das Signaturzertifikat (standardmäßig 3 Jahre) | + +__Sofern keine besonderen Vorgaben bestehen, empfehlen wir OpenID Connect__: Es ist das Protokoll, das wir standardmäßig einsetzen. Wählen Sie SAML, wenn Ihre internen Richtlinien es vorschreiben oder wenn Ihr Verzeichnis an einen Föderationsdienst angebunden ist, der ausschließlich dieses Protokoll unterstützt. + +Geben Sie das gewählte Protokoll bereits beim Öffnen Ihrer Supportanfrage an. ## Die ausgetauschten Informationen Die Einrichtung beruht auf einem Austausch in beide Richtungen. Hier die Einzelheiten vorab, damit Sie alles in einem Durchgang vorbereiten können. -### Was Sie uns übermitteln müssen +### Was Sie uns übermitteln müssen — bei OpenID Connect | Information | Bezeichnung im Azure-Portal | Wozu sie dient | |---|---|---| @@ -49,6 +59,26 @@ Die Einrichtung beruht auf einem Austausch in beide Richtungen. Hier die Einzelh Beide Kennungen finden Sie auf der Registerkarte __"Overview"__ Ihrer App-Registrierung; das Secret wird auf der Registerkarte __"Certificates & secrets"__ erstellt. +### Was Sie uns übermitteln müssen — bei SAML 2.0 + +Im Regelfall genügt eine einzige Information: + +| Information | Bezeichnung im Azure-Portal | Wozu sie dient | +|---|---|---| +| __URL der Föderationsmetadaten__ | *App Federation Metadata Url* | Daraus leiten wir die Kennung Ihres Verzeichnisses, dessen Endpunkte und dessen Signaturzertifikat ab | + +Sie hat folgende Form: + +``` +https://login.microsoftonline.com//federationmetadata/2007-06/federationmetadata.xml?appid= +``` + +Sie finden sie unter __"Enterprise applications"__ → Ihre Anwendung → __"Single sign-on"__, Abschnitt *SAML Certificates*. Sie ist öffentlich und enthält kein Secret: Sie darf im Text Ihrer Anfrage stehen. + +:::tip[Warum diese URL statt einer Parameterliste] +Sie fasst sämtliche Parameter Ihres Verzeichnisses in einem einzigen Wert zusammen und erleichtert die Nachverfolgung der Erneuerung Ihres Signaturzertifikats. Falls diese URL aus dem Internet nicht erreichbar ist, übermitteln Sie stattdessen die *Identity provider entity ID*, die *Single Sign-On service URL*, die *Single Logout service URL* sowie das Signaturzertifikat im Format __Certificate (Base64)__. +::: + :::warning[Übermitteln Sie das Secret niemals im Text einer Anfrage] Der Wert des Client Secret ist ein Authentifizierungsmerkmal. Fügen Sie ihn nicht in den Text einer Supportanfrage, in einen Kommentar oder in einen unverschlüsselten Anhang ein: Dort bliebe er dauerhaft einsehbar. @@ -57,15 +87,25 @@ Geben Sie in Ihrer Anfrage an, dass Ihnen das Secret vorliegt, und übermitteln ### Was Cloud Temple Ihnen übermittelt -Die __"Redirect URL"__, die für Ihre Organisation spezifisch ist. Sie ist in Ihrer EntraID-App-Registrierung zu hinterlegen (Schritt 3). +Für Ihre Organisation spezifische Werte, die in Ihrer EntraID-Anwendung zu hinterlegen sind: + +| Unsere Bezeichnung | Microsoft-Bezeichnung | Protokoll | +|---|---|---| +| Weiterleitungs-URL | *Redirect URL* | OpenID Connect | +| Weiterleitungs-URL | *Reply URL (Assertion Consumer Service URL)* | SAML 2.0 | +| Kennung des Dienstanbieters | *Identifier (Entity ID)* | SAML 2.0 | :::tip[Fordern Sie sie beim Öffnen Ihrer Anfrage an] -Diese URL hängt von Ihrer Organisation ab und lässt sich nicht erraten. Wenn Sie sie beim Öffnen Ihrer Supportanfrage anfordern, können Sie die gesamte Azure-Konfiguration in einem Durchgang vornehmen, ohne später darauf zurückkommen zu müssen. +Diese Werte hängen von Ihrer Organisation ab und lassen sich nicht erraten. Wenn Sie sie beim Öffnen Ihrer Supportanfrage anfordern, können Sie die gesamte Azure-Konfiguration in einem Durchgang vornehmen, ohne später darauf zurückkommen zu müssen. ::: ## Schritt 1: SSO-Konfiguration auf Seite von Microsoft EntraID -### Registrierung einer neuen Azure-Anwendung (Azure-Portal) +Folgen Sie dem Abschnitt zum gewählten Protokoll und anschließend dem Abschnitt „Zusätzliche Sicherheitseinstellungen", der für beide gilt. + +### Weg über OpenID Connect + +#### Registrierung einer neuen Azure-Anwendung (Azure-Portal) Für die Erstellung der __App Registration__ rufen Sie das Microsoft-Azure-Portal auf und wählen dann in Microsoft EntraID __"ADD > App Registration"__. @@ -83,7 +123,7 @@ Die Angaben __Application (client) ID__ und __Directory (tenant) ID__ werden auf -### Festlegung eines Secret +#### Festlegung eines Secret Erstellen Sie auf der Registerkarte "Certificates & secrets" ein neues Secret. @@ -96,10 +136,10 @@ Der Wert des Secret wird nur ein einziges Mal angezeigt, unmittelbar nach seiner :::caution[Gültigkeit auf 24 Monate begrenzt] -Das Ablaufdatum des Secret darf 24 Monate nicht überschreiten, auch nicht mit einem benutzerdefinierten Ablaufdatum. __Notieren Sie sich dieses Datum bereits jetzt__: Nach Ablauf funktioniert die SSO-Anmeldung für sämtliche Benutzer nicht mehr. Siehe Abschnitt [Erneuerung des Secret](#erneuerung-des-secret). +Das Ablaufdatum des Secret darf 24 Monate nicht überschreiten, auch nicht mit einem benutzerdefinierten Ablaufdatum. __Notieren Sie sich dieses Datum bereits jetzt__: Nach Ablauf funktioniert die SSO-Anmeldung für sämtliche Benutzer nicht mehr. Siehe Abschnitt [Pflege der Föderation im Zeitverlauf](#pflege-der-föderation-im-zeitverlauf). ::: -### Freigabe der von der Konsole verwendeten Informationen +#### Freigabe der von der Konsole verwendeten Informationen Die Konsole identifiziert Ihre Benutzer anhand der im Identitätstoken übermittelten Informationen. Nur eine Maßnahme ist Ihrerseits erforderlich: __die E-Mail-Adresse bereitstellen__. @@ -123,6 +163,37 @@ Zur Information: Hier alle von der Konsole genutzten Informationen: | `oid` | Stabile Zuordnung des Konsolenkontos zur Identität in Ihrem Verzeichnis, auch bei Änderung der E-Mail-Adresse | Keine — wird von EntraID nativ ausgestellt | | `given_name`, `family_name` | In der Konsole angezeigter Vor- und Nachname | Keine — im Bereich `profile` enthalten | +### Weg über SAML 2.0 + +#### Erstellung der Unternehmensanwendung + +Rufen Sie in __Microsoft EntraID__ die __"Enterprise applications"__ auf und dann __"New application"__. Wählen Sie __"Create your own application"__, vergeben Sie einen Namen und wählen Sie *Integrate any other application you don't find in the gallery (Non-gallery)*. Bestätigen Sie mit __"Create"__. + +#### Konfiguration des einmaligen Anmeldens + +Öffnen Sie in Ihrer Anwendung __"Single sign-on"__ und wählen Sie __"SAML"__. Klicken Sie unter __"Basic SAML Configuration"__ auf __"Edit"__ und tragen Sie die von Cloud Temple bereitgestellten Werte ein: + +- __Identifier (Entity ID)__; +- __Reply URL (Assertion Consumer Service URL)__. + +Speichern Sie. + +#### Attribute und Ansprüche + +EntraID stellt die von der Konsole erwarteten Ansprüche standardmäßig aus. Prüfen Sie ihr Vorhandensein unter __"Attributes & Claims"__: + +| Anspruch | Verwendung | Maßnahme Ihrerseits | +|---|---|---| +| `…/claims/emailaddress` | Anmeldeadresse des Benutzers | Keine — Quelle `user.mail` | +| `http://schemas.microsoft.com/identity/claims/objectidentifier` | Stabile Zuordnung des Konsolenkontos zur Identität in Ihrem Verzeichnis | Keine | +| `…/claims/givenname`, `…/claims/surname` | In der Konsole angezeigter Vor- und Nachname | Keine | + +:::warning[Namenskennung (NameID): der am häufigsten übersehene Punkt] +Setzen Sie unter __"Attributes & Claims"__ → __"Unique User Identifier (Name ID)"__ die Quelle auf __user.objectid__ und das Format auf __Persistent__. + +Standardmäßig gibt EntraID die E-Mail-Adresse als NameID aus. Ändert sich die Adresse eines Benutzers, würde die Konsole ihn als andere Person behandeln und er verlöre seine Rechte. Die Objektkennung hingegen ändert sich nie. +::: + ### Zusätzliche Sicherheitseinstellungen (optional, aber empfohlen) Standardmäßig erlaubt Microsoft EntraID in dieser Konfiguration jedem Benutzer Ihres Azure-Tenants, sich an Ihrer Cloud-Temple-Organisation anzumelden. Sie können den Zugriff auf Ebene der __"App Registration"__ einschränken, sodass nur eine Liste von Benutzern oder Gruppen zugelassen ist. @@ -168,18 +239,21 @@ Dieser Teil der Konfiguration wird auf Ebene der Organisation vom Cloud-Temple-T Stellen Sie dazu __eine Supportanfrage__ in der Konsole, in der Sie Ihren Wunsch nach einer Microsoft-EntraID-Föderation angeben, und nennen Sie: - den Namen Ihrer Organisation; +- __das gewählte Protokoll__: OpenID Connect oder SAML 2.0; - den Namen eines Ansprechpartners mit E-Mail-Adresse und Telefonnummer für den Abschluss der Konfiguration; -- die in Schritt 1 notierte __Application (client) ID__; -- die in Schritt 1 notierte __Directory (tenant) ID__. +- __bei OpenID Connect__: die in Schritt 1 notierte __Application (client) ID__ und __Directory (tenant) ID__; +- __bei SAML 2.0__: die __URL der Föderationsmetadaten__ Ihrer Anwendung. -Übermitteln Sie das __Client Secret__ über den von Ihrem Ansprechpartner genannten sicheren Kanal und nicht im Text der Anfrage. +Übermitteln Sie bei OpenID Connect das __Client Secret__ über den von Ihrem Ansprechpartner genannten sicheren Kanal und nicht im Text der Anfrage. Bei SAML wird kein Secret ausgetauscht. -Sobald die Konfiguration auf Seite der Konsole abgeschlossen ist, wird der angegebene Ansprechpartner informiert und erhält die zu hinterlegende __"Redirect URL"__. +Sobald die Konfiguration auf Seite der Konsole abgeschlossen ist, wird der angegebene Ansprechpartner informiert. -## Schritt 3: Hinterlegung der "Redirect URL" +## Schritt 3: Hinterlegung der "Redirect URL" (OpenID Connect) Falls Sie die "Redirect URL" bei der Erstellung der Anwendung nicht angegeben haben, fügen Sie sie jetzt hinzu. +Bei SAML 2.0 wurden die entsprechenden URLs bereits in Schritt 1 unter __"Basic SAML Configuration"__ hinterlegt: Fahren Sie direkt mit Schritt 4 fort. + Klicken Sie auf der Startseite der App Registration im Menü "Overview" auf "Add a Redirect URL". @@ -208,9 +282,13 @@ Sobald alle Schritte abgeschlossen sind, können Sie sich über Ihr SSO an Ihrer Die Identitätsföderation regelt die __Authentifizierung__, nicht die __Berechtigungen__. Ein Benutzer, der sich zum ersten Mal über SSO anmeldet, verfügt über keinerlei Rechte, solange ein Eigentümer der Organisation ihm keine über die Konsole zugewiesen hat. ::: -## Erneuerung des Secret +## Pflege der Föderation im Zeitverlauf + +Dies ist der wichtigste Punkt: Unabhängig vom Protokoll läuft ein Element ab, und sein Ablauf unterbricht die SSO-Anmeldung __für sämtliche Benutzer__. -Das Client Secret läuft spätestens 24 Monate nach seiner Erstellung ab. Nach Ablauf funktioniert die SSO-Anmeldung für sämtliche Benutzer nicht mehr. Planen Sie die Erneuerung rechtzeitig: +### Bei OpenID Connect: das Client Secret + +Das Client Secret läuft spätestens 24 Monate nach seiner Erstellung ab. Planen Sie die Erneuerung rechtzeitig: 1. Erstellen Sie unter "Certificates & secrets" ein __neues__ Secret, ohne das alte zu löschen; 2. übermitteln Sie dessen Wert über den sicheren Kanal an Cloud Temple, indem Sie eine Supportanfrage stellen; @@ -218,22 +296,31 @@ Das Client Secret läuft spätestens 24 Monate nach seiner Erstellung ab. Nach A Indem Sie beide Secrets während der Umstellung beibehalten, vermeiden Sie jede Betriebsunterbrechung. +### Bei SAML 2.0: das Signaturzertifikat + +Das von EntraID ausgestellte Signaturzertifikat hat eine begrenzte Laufzeit, standardmäßig drei Jahre. + +__Informieren Sie uns vor jeder Zertifikatsrotation__ über eine Supportanfrage und halten Sie den von Microsoft vorgesehenen Überlappungszeitraum ein. Falls Sie uns ein Zertifikat als Datei statt der Metadaten-URL übermittelt haben, fügen Sie Ihrer Anfrage das neue Zertifikat bei. + ## Bewährte Vorgehensweisen - __Steuern Sie den Zugriff über Gruppen__ statt über einzelne Benutzer: Der Zugang oder Abgang einer Person wird dann in Ihrem Verzeichnis geregelt, ohne Eingriff in der Konsole. - __Aktivieren Sie die Multi-Faktor-Authentifizierung__ für die Anwendung in Ihren EntraID-Richtlinien für bedingten Zugriff: Sie gilt dann auch für den Zugang zur Konsole. -- __Richten Sie eine Erinnerung__ vor dem Ablaufdatum des Secret ein. +- __Richten Sie eine Erinnerung__ vor dem Ablaufdatum des Client Secret bzw. des Signaturzertifikats ein, je nach gewähltem Protokoll. - __Behalten Sie mindestens ein lokales Eigentümerkonto__ in Ihrer Cloud-Temple-Organisation außerhalb der Föderation, um bei Nichtverfügbarkeit Ihres Verzeichnisses weiterhin Zugang zu haben. ## Fehlerbehebung -| Symptom | Wahrscheinliche Ursache | -|---|---| -| `AADSTS50011`: Die Redirect-URL stimmt nicht überein | Die in Azure hinterlegte "Redirect URL" weicht von der durch Cloud Temple bereitgestellten ab. Prüfen Sie sie Zeichen für Zeichen, einschließlich eines fehlenden abschließenden `/`. | -| `AADSTS7000215`: ungültiges Secret | Das Secret ist abgelaufen, oder es wurde die "Secret ID" statt des "Value" übermittelt. | -| `AADSTS50105`: Benutzer nicht zugewiesen | Die Option "Assignment required" ist aktiv und der Benutzer ist der Anwendung nicht zugewiesen. | -| Die Anmeldeschaltfläche erscheint nicht auf der Seite | Die Konfiguration ist auf Seite von Cloud Temple noch nicht aktiv. | -| Der Benutzer wird authentifiziert, die Konsole verweigert jedoch den Zugriff | Der Claim `email` fehlt im Token, oder dem Benutzer wurden keine Rechte zugewiesen. | +| Symptom | Protokoll | Wahrscheinliche Ursache | +|---|---|---| +| `AADSTS50011`: Die Redirect-URL stimmt nicht überein | Beide | Die in Azure hinterlegte URL weicht von der durch Cloud Temple bereitgestellten ab. Prüfen Sie sie Zeichen für Zeichen, einschließlich eines fehlenden abschließenden `/`. | +| `AADSTS700016`: Anwendung nicht gefunden | SAML 2.0 | Die hinterlegte *Entity ID* stimmt nicht mit der von Cloud Temple bereitgestellten überein. | +| `AADSTS7000215`: ungültiges Secret | OpenID Connect | Das Secret ist abgelaufen, oder es wurde die "Secret ID" statt des "Value" übermittelt. | +| `AADSTS50105`: Benutzer nicht zugewiesen | Beide | Die Option "Assignment required" ist aktiv und der Benutzer ist der Anwendung nicht zugewiesen. | +| Die Anmeldeschaltfläche erscheint nicht auf der Seite | Beide | Die Konfiguration ist auf Seite von Cloud Temple noch nicht aktiv. | +| Der Benutzer wird authentifiziert, die Konsole verweigert jedoch den Zugriff | Beide | Die E-Mail-Adresse fehlt im Token, oder dem Benutzer wurden keine Rechte zugewiesen. | +| Der Benutzer erscheint bei jeder Anmeldung als neues Konto | SAML 2.0 | Die NameID ist nicht auf `user.objectid` gesetzt. | +| Signaturfehler bei der Ankunft in der Konsole | SAML 2.0 | Das Signaturzertifikat wurde auf Azure-Seite erneuert, ohne dass wir informiert wurden. | ## Support diff --git a/i18n/en/docusaurus-plugin-content-docs/current/console/iam/tutorials/sso_azuread.md b/i18n/en/docusaurus-plugin-content-docs/current/console/iam/tutorials/sso_azuread.md index ca449ac8..0307863e 100644 --- a/i18n/en/docusaurus-plugin-content-docs/current/console/iam/tutorials/sso_azuread.md +++ b/i18n/en/docusaurus-plugin-content-docs/current/console/iam/tutorials/sso_azuread.md @@ -31,15 +31,25 @@ Configuring your Microsoft identity provider at the Cloud Temple organization le Microsoft EntraID is the new name of Azure Active Directory (Azure AD) since 2023. It is the same product: this tutorial applies to both names interchangeably. ::: -:::info[Protocol used] -Federation with EntraID is performed using __OpenID Connect (OIDC)__. No SAML configuration is required on your side. -::: +## Choosing the protocol + +Federation with EntraID can be set up using either of the two standard protocols. Both offer an equivalent level of security; they differ mainly in what you need to send us and in what has to be maintained over time. + +| | OpenID Connect | SAML 2.0 | +|---|---|---| +| What you send us | Two identifiers and a secret | A public metadata URL | +| Secret exchanged | Yes, the client secret | None | +| To maintain over time | The client secret (24 months maximum) | The signing certificate (3 years by default) | + +__Unless you have a specific constraint, we recommend OpenID Connect__: it is the protocol we deploy by default. Choose SAML if your internal policy requires it, or if your directory is connected to a federation hub that only speaks that protocol. + +State the protocol you have chosen when you open your support request. ## Information exchanged Setting up the federation relies on a two-way exchange. Here are the details upfront, so you can prepare everything in a single pass. -### What you need to send us +### What you need to send us — with OpenID Connect | Information | Name in the Azure portal | What it is used for | |---|---|---| @@ -49,6 +59,26 @@ Setting up the federation relies on a two-way exchange. Here are the details upf Both identifiers appear in the __"Overview"__ tab of your app registration; the secret is created in the __"Certificates & secrets"__ tab. +### What you need to send us — with SAML 2.0 + +A single piece of information is enough in the usual case: + +| Information | Name in the Azure portal | What it is used for | +|---|---|---| +| __Federation metadata URL__ | *App Federation Metadata Url* | We derive from it your directory identifier, its endpoints and its signing certificate | + +It takes the following form: + +``` +https://login.microsoftonline.com//federationmetadata/2007-06/federationmetadata.xml?appid= +``` + +You will find it under __"Enterprise applications"__ → your application → __"Single sign-on"__, in the *SAML Certificates* section. It is public and contains no secret: it may appear in the body of your request. + +:::tip[Why this URL rather than a list of parameters] +It gathers all your directory parameters into a single value and simplifies tracking the renewal of your signing certificate. If this URL is not reachable from the internet, send instead the *Identity provider entity ID*, the *Single Sign-On service URL*, the *Single Logout service URL* and the signing certificate in __Certificate (Base64)__ format. +::: + :::warning[Never send the secret in the body of a request] The client secret value is an authentication credential. Do not place it in the body of a support request, in a comment, or in an unencrypted attachment: it would remain readable there permanently. @@ -57,15 +87,25 @@ State in your request that you have the secret, and send it through the secure c ### What Cloud Temple sends you -The __"Redirect URL"__, specific to your organization. You must declare it in your EntraID app registration (step 3). +Values specific to your organization, to be declared in your EntraID application: + +| Our term | Microsoft term | Protocol | +|---|---|---| +| Redirect URL | *Redirect URL* | OpenID Connect | +| Redirect URL | *Reply URL (Assertion Consumer Service URL)* | SAML 2.0 | +| Service provider identifier | *Identifier (Entity ID)* | SAML 2.0 | -:::tip[Ask for it when you open your request] -This URL depends on your organization and cannot be guessed. By requesting it when you open your support request, you can complete the entire Azure configuration in one pass, without having to come back to it. +:::tip[Ask for them when you open your request] +These values depend on your organization and cannot be guessed. By requesting them when you open your support request, you can complete the entire Azure configuration in one pass, without having to come back to it. ::: ## Step 1: SSO configuration on the Microsoft EntraID side -### Registering a new Azure application (Azure portal) +Follow the section matching the protocol you have chosen, then the "Additional security settings" section, which is common to both. + +### OpenID Connect path + +#### Registering a new Azure application (Azure portal) To create the __app registration__, go to the Microsoft Azure portal, then in Microsoft EntraID, __"ADD > App Registration"__. @@ -83,7 +123,7 @@ The __Application (client) ID__ and __Directory (tenant) ID__ are displayed on t -### Creating a secret +#### Creating a secret In the "Certificates & secrets" tab, create a new secret. @@ -96,10 +136,10 @@ The secret value is displayed only once, right after it is created. Copy the con :::caution[Validity limited to 24 months] -The secret expiry date cannot exceed 24 months, even with a custom expiry date. __Make a note of this date now__: once it is reached, SSO will stop working for all your users. See the [Renewing the secret](#renewing-the-secret) section. +The secret expiry date cannot exceed 24 months, even with a custom expiry date. __Make a note of this date now__: once it is reached, SSO will stop working for all your users. See the [Maintaining the federation over time](#maintaining-the-federation-over-time) section. ::: -### Authorising the information used by the Console +#### Authorising the information used by the Console The Console identifies your users from the information carried by the identity token. Only one action is required on your side: __exposing the email address__. @@ -123,6 +163,37 @@ For reference, here is all the information consumed by the Console: | `oid` | Stable link between the Console account and the identity in your directory, even if the email address changes | None — issued natively by EntraID | | `given_name`, `family_name` | First name and last name shown in the Console | None — included in the `profile` scope | +### SAML 2.0 path + +#### Creating the enterprise application + +In __Microsoft EntraID__, go to __"Enterprise applications"__, then __"New application"__. Choose __"Create your own application"__, name it, and select *Integrate any other application you don't find in the gallery (Non-gallery)*. Confirm with __"Create"__. + +#### Configuring single sign-on + +In your application, open __"Single sign-on"__ and choose __"SAML"__. In __"Basic SAML Configuration"__, click __"Edit"__ and fill in the values provided by Cloud Temple: + +- __Identifier (Entity ID)__; +- __Reply URL (Assertion Consumer Service URL)__. + +Save. + +#### Attributes and claims + +EntraID issues by default the claims expected by the Console. Check that they are present under __"Attributes & Claims"__: + +| Claim | Usage | Action on your side | +|---|---|---| +| `…/claims/emailaddress` | User's sign-in address | None — source `user.mail` | +| `http://schemas.microsoft.com/identity/claims/objectidentifier` | Stable link between the Console account and the identity in your directory | None | +| `…/claims/givenname`, `…/claims/surname` | First name and last name shown in the Console | None | + +:::warning[Name identifier (NameID): the most commonly missed step] +Under __"Attributes & Claims"__ → __"Unique User Identifier (Name ID)"__, set the source to __user.objectid__ and the format to __Persistent__. + +By default, EntraID issues the email address as the NameID. If a user's address changes, the Console would treat them as a different person and they would lose their permissions. The object identifier, by contrast, never changes. +::: + ### Additional security settings (optional but recommended) By default, Microsoft EntraID as configured will allow any user of your Azure tenant to sign in to your Cloud Temple organization. You can restrict access at the __"App Registration"__ level so that only a list of users or groups is authorised. @@ -168,18 +239,21 @@ This part of the configuration is carried out at the organization level by the C To do so, submit __a support request__ in the Console stating that you wish to configure Microsoft EntraID federation, specifying: - your organization name; +- __the protocol you have chosen__: OpenID Connect or SAML 2.0; - the name of a contact, with their email address and phone number, to finalise the configuration; -- the __Application (client) ID__ noted in step 1; -- the __Directory (tenant) ID__ noted in step 1. +- __with OpenID Connect__: the __Application (client) ID__ and the __Directory (tenant) ID__ noted in step 1; +- __with SAML 2.0__: the __federation metadata URL__ of your application. -Send the __client secret__ through the secure channel indicated by your contact, not in the body of the request. +With OpenID Connect, send the __client secret__ through the secure channel indicated by your contact, not in the body of the request. With SAML, no secret is exchanged. -Once the configuration is complete on the Console side, the contact you provided will be informed and will receive the __"Redirect URL"__ to declare. +Once the configuration is complete on the Console side, the contact you provided will be informed. -## Step 3: Declaring the "Redirect URL" +## Step 3: Declaring the "Redirect URL" (OpenID Connect) If you did not enter the "Redirect URL" when creating the application, add it now. +With SAML 2.0, the equivalent URLs were already declared under __"Basic SAML Configuration"__ in step 1: go straight to step 4. + On the App Registration home page, in the "Overview" menu, click "Add a Redirect URL". @@ -208,9 +282,13 @@ Once all the steps are complete, you can authenticate to your Cloud Temple organ Identity federation handles __authentication__, not __authorisation__. A user signing in for the first time through SSO has no permissions until an organization owner grants them from the Console. ::: -## Renewing the secret +## Maintaining the federation over time + +This is the main point to watch: whatever the protocol, one element expires, and its expiry interrupts SSO __for all your users__. -The client secret expires no later than 24 months after it is created. Once it expires, SSO stops working for all your users. Plan its renewal ahead: +### With OpenID Connect: the client secret + +The client secret expires no later than 24 months after it is created. Plan its renewal ahead: 1. in "Certificates & secrets", create a __new__ secret without deleting the old one; 2. send its value to Cloud Temple through the secure channel, by opening a support request; @@ -218,22 +296,31 @@ The client secret expires no later than 24 months after it is created. Once it e Keeping both secrets during the switchover avoids any service interruption. +### With SAML 2.0: the signing certificate + +The signing certificate issued by EntraID has a limited lifetime, three years by default. + +__Let us know before any certificate rotation__, through a support request, respecting the overlap period offered by Microsoft. If you sent us a certificate as a file rather than the metadata URL, attach the new certificate to your request. + ## Best practices - __Manage access through groups__ rather than individual users: a colleague joining or leaving is then handled in your directory, with no action needed on the Console. - __Enable multi-factor authentication__ on the application in your EntraID conditional access policies: it then applies to Console access. -- __Set a reminder__ ahead of the secret expiry date. +- __Set a reminder__ ahead of the expiry date of the client secret or the signing certificate, depending on the protocol chosen. - __Keep at least one local owner account__ on your Cloud Temple organization, outside the federation, so you retain access if your directory becomes unavailable. ## Troubleshooting -| Symptom | Likely cause | -|---|---| -| `AADSTS50011`: redirect URL mismatch | The "Redirect URL" declared in Azure differs from the one provided by Cloud Temple. Check it character by character, including the absence of a trailing `/`. | -| `AADSTS7000215`: invalid secret | The secret has expired, or the value sent was the "Secret ID" instead of the "Value". | -| `AADSTS50105`: user not assigned | The "Assignment required" option is enabled and the user is not assigned to the application. | -| The sign-in button does not appear on the page | The configuration is not yet active on the Cloud Temple side. | -| The user authenticates but the Console denies access | The `email` claim is missing from the token, or no permissions have been granted to the user. | +| Symptom | Protocol | Likely cause | +|---|---|---| +| `AADSTS50011`: redirect URL mismatch | Both | The URL declared in Azure differs from the one provided by Cloud Temple. Check it character by character, including the absence of a trailing `/`. | +| `AADSTS700016`: application not found | SAML 2.0 | The *Entity ID* declared does not match the one provided by Cloud Temple. | +| `AADSTS7000215`: invalid secret | OpenID Connect | The secret has expired, or the value sent was the "Secret ID" instead of the "Value". | +| `AADSTS50105`: user not assigned | Both | The "Assignment required" option is enabled and the user is not assigned to the application. | +| The sign-in button does not appear on the page | Both | The configuration is not yet active on the Cloud Temple side. | +| The user authenticates but the Console denies access | Both | The email address is missing from the token, or no permissions have been granted to the user. | +| The user appears as a new account at every sign-in | SAML 2.0 | The NameID is not set to `user.objectid`. | +| Signature error on arrival at the Console | SAML 2.0 | The signing certificate was renewed on the Azure side without us being informed. | ## Support diff --git a/i18n/es/docusaurus-plugin-content-docs/current/console/iam/tutorials/sso_azuread.md b/i18n/es/docusaurus-plugin-content-docs/current/console/iam/tutorials/sso_azuread.md index 8bd7feae..6bd7ffa6 100644 --- a/i18n/es/docusaurus-plugin-content-docs/current/console/iam/tutorials/sso_azuread.md +++ b/i18n/es/docusaurus-plugin-content-docs/current/console/iam/tutorials/sso_azuread.md @@ -31,15 +31,25 @@ La configuración de su repositorio Microsoft a nivel de una organización Cloud Microsoft EntraID es el nuevo nombre de Azure Active Directory (Azure AD) desde 2023. Se trata del mismo producto: este tutorial se aplica indistintamente a ambas denominaciones. ::: -:::info[Protocolo utilizado] -La federación con EntraID se realiza mediante __OpenID Connect (OIDC)__. No se requiere ninguna configuración SAML por su parte. -::: +## Elegir el protocolo + +La federación con EntraID puede realizarse con cualquiera de los dos protocolos estándar. Ambos ofrecen un nivel de seguridad equivalente; se diferencian principalmente en lo que debe transmitirnos y en lo que habrá que mantener a lo largo del tiempo. + +| | OpenID Connect | SAML 2.0 | +|---|---|---| +| Lo que nos transmite | Dos identificadores y un secreto | Una URL de metadatos pública | +| Secreto intercambiado | Sí, el secreto de cliente | Ninguno | +| A mantener en el tiempo | El secreto de cliente (24 meses máximo) | El certificado de firma (3 años por defecto) | + +__Salvo restricción específica, recomendamos OpenID Connect__: es el protocolo que desplegamos de forma predeterminada. Opte por SAML si su política interna lo impone, o si su directorio está conectado a un concentrador de federación que solo admite ese protocolo. + +Indique el protocolo elegido al abrir su solicitud de asistencia. ## Información intercambiada La implementación se basa en un intercambio en ambos sentidos. Estos son los detalles desde el principio, para que pueda prepararlo todo de una sola vez. -### Lo que debe transmitirnos +### Lo que debe transmitirnos — con OpenID Connect | Información | Nombre en el portal de Azure | Para qué sirve | |---|---|---| @@ -49,6 +59,26 @@ La implementación se basa en un intercambio en ambos sentidos. Estos son los de Ambos identificadores figuran en la pestaña __"Overview"__ de su registro de aplicación; el secreto se crea en la pestaña __"Certificates & secrets"__. +### Lo que debe transmitirnos — con SAML 2.0 + +Una sola información basta en el caso habitual: + +| Información | Nombre en el portal de Azure | Para qué sirve | +|---|---|---| +| __URL de los metadatos de federación__ | *App Federation Metadata Url* | De ella derivamos el identificador de su directorio, sus puntos de conexión y su certificado de firma | + +Se presenta de la siguiente forma: + +``` +https://login.microsoftonline.com//federationmetadata/2007-06/federationmetadata.xml?appid= +``` + +La encontrará en __"Enterprise applications"__ → su aplicación → __"Single sign-on"__, sección *SAML Certificates*. Es pública y no contiene ningún secreto: puede figurar en el cuerpo de su solicitud. + +:::tip[Por qué esta URL en lugar de una lista de parámetros] +Reúne en un solo valor el conjunto de parámetros de su directorio y simplifica el seguimiento de la renovación de su certificado de firma. Si esta URL no es accesible desde Internet, transmita en su lugar el *Identity provider entity ID*, la *Single Sign-On service URL*, la *Single Logout service URL* y el certificado de firma en formato __Certificate (Base64)__. +::: + :::warning[Nunca transmita el secreto en el cuerpo de una solicitud] El valor del secreto de cliente es una credencial de autenticación. No lo incluya en el cuerpo de una solicitud de asistencia, ni en un comentario, ni en un archivo adjunto sin cifrar: permanecería allí consultable de forma duradera. @@ -57,15 +87,25 @@ Indique en su solicitud que dispone del secreto y transmítalo por el canal segu ### Lo que Cloud Temple le transmite -La __"Redirect URL"__, propia de su organización. Debe declararla en su registro de aplicación EntraID (paso 3). +Valores propios de su organización, que debe declarar en su aplicación EntraID: + +| Nuestro término | Término de Microsoft | Protocolo | +|---|---|---| +| URL de redirección | *Redirect URL* | OpenID Connect | +| URL de redirección | *Reply URL (Assertion Consumer Service URL)* | SAML 2.0 | +| Identificador del proveedor de servicio | *Identifier (Entity ID)* | SAML 2.0 | -:::tip[Solicítela al abrir su petición] -Esta URL depende de su organización y no puede deducirse. Al solicitarla en el momento de abrir su solicitud de asistencia, podrá realizar toda la configuración de Azure de una sola vez, sin tener que volver sobre ella. +:::tip[Solicítelos al abrir su petición] +Estos valores dependen de su organización y no pueden deducirse. Al solicitarlos en el momento de abrir su solicitud de asistencia, podrá realizar toda la configuración de Azure de una sola vez, sin tener que volver sobre ella. ::: ## Paso 1: Configuración del SSO en el lado de Microsoft EntraID -### Registro de una nueva aplicación de Azure (portal de Azure) +Siga la sección correspondiente al protocolo elegido y, a continuación, la sección «Configuraciones de seguridad adicionales», común a ambos. + +### Vía OpenID Connect + +#### Registro de una nueva aplicación de Azure (portal de Azure) Para crear el __app registration__, diríjase al portal de Microsoft Azure y, a continuación, en Microsoft EntraID, __"ADD > App Registration"__. @@ -83,7 +123,7 @@ Los datos __Application (client) ID__ y __Directory (tenant) ID__ se muestran en -### Definición de un secreto +#### Definición de un secreto En la pestaña "Certificates & secrets", cree un nuevo secreto. @@ -96,10 +136,10 @@ El valor del secreto solo se muestra una vez, justo después de su creación. Co :::caution[Validez limitada a 24 meses] -La fecha de expiración del secreto no puede ser superior a 24 meses, incluso con una fecha de expiración personalizada. __Anote esta fecha desde ahora__: al alcanzarla, la conexión SSO dejará de funcionar para todos sus usuarios. Consulte la sección [Renovación del secreto](#renovación-del-secreto). +La fecha de expiración del secreto no puede ser superior a 24 meses, incluso con una fecha de expiración personalizada. __Anote esta fecha desde ahora__: al alcanzarla, la conexión SSO dejará de funcionar para todos sus usuarios. Consulte la sección [Mantenimiento de la federación a lo largo del tiempo](#mantenimiento-de-la-federación-a-lo-largo-del-tiempo). ::: -### Autorización de la información utilizada por la Consola +#### Autorización de la información utilizada por la Consola La Consola identifica a sus usuarios a partir de la información transportada por el token de identidad. Solo se requiere una acción por su parte: __exponer la dirección de correo electrónico__. @@ -123,6 +163,37 @@ A título informativo, esta es toda la información consumida por la Consola: | `oid` | Vinculación estable de la cuenta de la Consola con la identidad de su directorio, incluso si cambia la dirección de correo | Ninguna — emitido de forma nativa por EntraID | | `given_name`, `family_name` | Nombre y apellidos mostrados en la Consola | Ninguna — incluidos en el ámbito `profile` | +### Vía SAML 2.0 + +#### Creación de la aplicación empresarial + +En __Microsoft EntraID__, diríjase a __"Enterprise applications"__ y luego a __"New application"__. Elija __"Create your own application"__, asígnele un nombre y seleccione *Integrate any other application you don't find in the gallery (Non-gallery)*. Valide con __"Create"__. + +#### Configuración del inicio de sesión único + +En su aplicación, abra __"Single sign-on"__ y elija __"SAML"__. En __"Basic SAML Configuration"__, haga clic en __"Edit"__ e indique los valores proporcionados por Cloud Temple: + +- __Identifier (Entity ID)__; +- __Reply URL (Assertion Consumer Service URL)__. + +Guarde. + +#### Atributos y notificaciones + +EntraID emite de forma predeterminada las notificaciones esperadas por la Consola. Compruebe su presencia en __"Attributes & Claims"__: + +| Notificación | Uso | Acción por su parte | +|---|---|---| +| `…/claims/emailaddress` | Dirección de conexión del usuario | Ninguna — origen `user.mail` | +| `http://schemas.microsoft.com/identity/claims/objectidentifier` | Vinculación estable de la cuenta de la Consola con la identidad de su directorio | Ninguna | +| `…/claims/givenname`, `…/claims/surname` | Nombre y apellidos mostrados en la Consola | Ninguna | + +:::warning[Identificador de nombre (NameID): el punto que más se olvida] +En __"Attributes & Claims"__ → __"Unique User Identifier (Name ID)"__, establezca el origen en __user.objectid__ y el formato en __Persistent__. + +De forma predeterminada, EntraID emite la dirección de correo electrónico como NameID. Si un usuario cambia de dirección, la Consola lo trataría como una persona distinta y perdería sus permisos. El identificador de objeto, en cambio, nunca cambia. +::: + ### Configuraciones de seguridad adicionales (opcional pero recomendado) De forma predeterminada, Microsoft EntraID tal como está configurado permitirá que cualquier usuario de su tenant de Azure se conecte a su organización Cloud Temple. Es posible restringir los accesos a nivel de __"App Registration"__ para autorizar únicamente a una lista de usuarios o grupos. @@ -168,18 +239,21 @@ Esta parte de la configuración se realiza a nivel de la organización por parte Para ello, presente __una solicitud de asistencia__ en la Consola indicando su deseo de configurar una federación Microsoft EntraID, precisando: - el nombre de su organización; +- __el protocolo elegido__: OpenID Connect o SAML 2.0; - el nombre de un contacto, con su correo electrónico y número de teléfono, para finalizar la configuración; -- el __Application (client) ID__ anotado en el paso 1; -- el __Directory (tenant) ID__ anotado en el paso 1. +- __con OpenID Connect__: el __Application (client) ID__ y el __Directory (tenant) ID__ anotados en el paso 1; +- __con SAML 2.0__: la __URL de los metadatos de federación__ de su aplicación. -Transmita el __secreto de cliente__ por el canal seguro indicado por su contacto, y no en el cuerpo de la solicitud. +Con OpenID Connect, transmita el __secreto de cliente__ por el canal seguro indicado por su contacto, y no en el cuerpo de la solicitud. Con SAML, no se intercambia ningún secreto. -En cuanto la configuración se realice en el lado de la Consola, se informará al contacto indicado, que recibirá la __"Redirect URL"__ que deberá declarar. +En cuanto la configuración se realice en el lado de la Consola, se informará al contacto indicado. -## Paso 3: Declaración de la "Redirect URL" +## Paso 3: Declaración de la "Redirect URL" (OpenID Connect) Si no indicó la "Redirect URL" durante la creación de la aplicación, añádala ahora. +Con SAML 2.0, las URL equivalentes ya se declararon en __"Basic SAML Configuration"__ en el paso 1: pase directamente al paso 4. + En la página de inicio del App Registration, en el menú "Overview", haga clic en "Add a Redirect URL". @@ -208,9 +282,13 @@ Una vez realizados todos los pasos, puede autenticarse en su organización Cloud La federación de identidad gestiona __la autenticación__, no las __autorizaciones__. Un usuario que se conecta por primera vez mediante el SSO no dispone de ningún permiso mientras un propietario de la organización no se lo haya atribuido desde la Consola. ::: -## Renovación del secreto +## Mantenimiento de la federación a lo largo del tiempo + +Este es el principal punto de vigilancia: sea cual sea el protocolo, un elemento expira, y su expiración interrumpe el SSO __para todos sus usuarios__. -El secreto de cliente expira como máximo 24 meses después de su creación. Al vencimiento, la conexión SSO deja de funcionar para todos sus usuarios. Anticipe su renovación: +### Con OpenID Connect: el secreto de cliente + +El secreto de cliente expira como máximo 24 meses después de su creación. Anticipe su renovación: 1. en "Certificates & secrets", cree un __nuevo__ secreto sin eliminar el anterior; 2. transmita su valor a Cloud Temple por el canal seguro, abriendo una solicitud de asistencia; @@ -218,22 +296,31 @@ El secreto de cliente expira como máximo 24 meses después de su creación. Al Conservar ambos secretos durante la conmutación evita cualquier interrupción del servicio. +### Con SAML 2.0: el certificado de firma + +El certificado de firma emitido por EntraID tiene una vida útil limitada, de tres años por defecto. + +__Avísenos antes de cualquier rotación de certificado__, mediante una solicitud de asistencia, respetando el periodo de solapamiento propuesto por Microsoft. Si nos transmitió un certificado en forma de archivo en lugar de la URL de metadatos, adjunte el nuevo certificado a su solicitud. + ## Buenas prácticas - __Gestione el acceso por grupos__ en lugar de por usuarios: la llegada o salida de un colaborador se trata entonces en su directorio, sin intervención en la Consola. - __Active la autenticación multifactor__ en la aplicación desde sus directivas de acceso condicional de EntraID: se aplicará entonces al acceso a la Consola. -- __Programe una alerta__ ante la proximidad de la fecha de expiración del secreto. +- __Programe una alerta__ ante la proximidad de la fecha de expiración del secreto de cliente o del certificado de firma, según el protocolo elegido. - __Conserve al menos una cuenta propietaria local__ en su organización Cloud Temple, fuera de la federación, para mantener el acceso en caso de indisponibilidad de su directorio. ## Resolución de problemas -| Síntoma | Causa probable | -|---|---| -| `AADSTS50011`: la URL de redirección no coincide | La "Redirect URL" declarada en Azure difiere de la proporcionada por Cloud Temple. Verifíquela carácter por carácter, incluida la ausencia de `/` final. | -| `AADSTS7000215`: secreto no válido | El secreto ha expirado, o el valor transmitido era el "Secret ID" en lugar del "Value". | -| `AADSTS50105`: usuario no asignado | La opción "Assignment required" está activa y el usuario no está asignado a la aplicación. | -| El botón de conexión no aparece en la página | La configuración aún no está activa en el lado de Cloud Temple. | -| El usuario se autentica pero la Consola deniega el acceso | Falta el claim `email` en el token, o no se ha atribuido ningún permiso al usuario. | +| Síntoma | Protocolo | Causa probable | +|---|---|---| +| `AADSTS50011`: la URL de redirección no coincide | Ambos | La URL declarada en Azure difiere de la proporcionada por Cloud Temple. Verifíquela carácter por carácter, incluida la ausencia de `/` final. | +| `AADSTS700016`: aplicación no encontrada | SAML 2.0 | El *Entity ID* declarado no corresponde al proporcionado por Cloud Temple. | +| `AADSTS7000215`: secreto no válido | OpenID Connect | El secreto ha expirado, o el valor transmitido era el "Secret ID" en lugar del "Value". | +| `AADSTS50105`: usuario no asignado | Ambos | La opción "Assignment required" está activa y el usuario no está asignado a la aplicación. | +| El botón de conexión no aparece en la página | Ambos | La configuración aún no está activa en el lado de Cloud Temple. | +| El usuario se autentica pero la Consola deniega el acceso | Ambos | Falta la dirección de correo en el token, o no se ha atribuido ningún permiso al usuario. | +| El usuario aparece como una cuenta nueva en cada conexión | SAML 2.0 | El NameID no está establecido en `user.objectid`. | +| Error de firma al llegar a la Consola | SAML 2.0 | El certificado de firma se renovó en Azure sin que se nos informara. | ## Soporte diff --git a/i18n/it/docusaurus-plugin-content-docs/current/console/iam/tutorials/sso_azuread.md b/i18n/it/docusaurus-plugin-content-docs/current/console/iam/tutorials/sso_azuread.md index de366009..2a43259e 100644 --- a/i18n/it/docusaurus-plugin-content-docs/current/console/iam/tutorials/sso_azuread.md +++ b/i18n/it/docusaurus-plugin-content-docs/current/console/iam/tutorials/sso_azuread.md @@ -31,15 +31,25 @@ La configurazione del vostro repository Microsoft a livello di un'organizzazione Microsoft EntraID è il nuovo nome di Azure Active Directory (Azure AD) dal 2023. Si tratta dello stesso prodotto: questo tutorial si applica indifferentemente a entrambe le denominazioni. ::: -:::info[Protocollo utilizzato] -La federazione con EntraID viene realizzata tramite __OpenID Connect (OIDC)__. Non è necessaria alcuna configurazione SAML da parte vostra. -::: +## Scegliere il protocollo + +La federazione con EntraID può essere realizzata con uno o l'altro dei due protocolli standard. Entrambi offrono un livello di sicurezza equivalente; si differenziano principalmente per ciò che dovete trasmetterci e per ciò che sarà da mantenere nel tempo. + +| | OpenID Connect | SAML 2.0 | +|---|---|---| +| Ciò che ci trasmettete | Due identificatori e un secret | Un URL di metadati pubblico | +| Secret scambiato | Sì, il secret client | Nessuno | +| Da mantenere nel tempo | Il secret client (24 mesi massimo) | Il certificato di firma (3 anni per impostazione predefinita) | + +__In assenza di vincoli particolari, raccomandiamo OpenID Connect__: è il protocollo che distribuiamo per impostazione predefinita. Scegliete SAML se la vostra politica interna lo impone, o se la vostra directory è collegata a un concentratore di federazione che supporta solo questo protocollo. + +Indicate il protocollo scelto fin dall'apertura della vostra richiesta di assistenza. ## Le informazioni scambiate L'implementazione si basa su uno scambio nei due sensi. Eccone il dettaglio fin da subito, per consentirvi di preparare tutto in un'unica volta. -### Ciò che dovete trasmetterci +### Ciò che dovete trasmetterci — con OpenID Connect | Informazione | Nome nel portale Azure | A cosa serve | |---|---|---| @@ -49,6 +59,26 @@ L'implementazione si basa su uno scambio nei due sensi. Eccone il dettaglio fin I due identificatori figurano nella scheda __"Overview"__ della vostra registrazione applicativa; il secret viene creato nella scheda __"Certificates & secrets"__. +### Ciò che dovete trasmetterci — con SAML 2.0 + +Nel caso corrente è sufficiente una sola informazione: + +| Informazione | Nome nel portale Azure | A cosa serve | +|---|---|---| +| __URL dei metadati di federazione__ | *App Federation Metadata Url* | Ne ricaviamo l'identificatore della vostra directory, i suoi endpoint e il suo certificato di firma | + +Si presenta nella forma seguente: + +``` +https://login.microsoftonline.com//federationmetadata/2007-06/federationmetadata.xml?appid= +``` + +La trovate in __"Enterprise applications"__ → la vostra applicazione → __"Single sign-on"__, sezione *SAML Certificates*. È pubblica e non contiene alcun secret: può figurare nel corpo della vostra richiesta. + +:::tip[Perché questo URL anziché un elenco di parametri] +Riunisce in un unico valore l'insieme dei parametri della vostra directory e semplifica il monitoraggio del rinnovo del vostro certificato di firma. Se questo URL non è raggiungibile da Internet, trasmettete invece l'*Identity provider entity ID*, la *Single Sign-On service URL*, la *Single Logout service URL* e il certificato di firma in formato __Certificate (Base64)__. +::: + :::warning[Non trasmettete mai il secret nel corpo di una richiesta] Il valore del secret client è una credenziale di autenticazione. Non inseritelo nel corpo di una richiesta di assistenza, né in un commento, né in un allegato non cifrato: vi resterebbe consultabile in modo duraturo. @@ -57,15 +87,25 @@ Indicate nella vostra richiesta che disponete del secret, e trasmettetelo tramit ### Ciò che Cloud Temple vi trasmette -La __"Redirect URL"__, specifica della vostra organizzazione. Va dichiarata nella vostra registrazione applicativa EntraID (fase 3). +Valori specifici della vostra organizzazione, da dichiarare nella vostra applicazione EntraID: + +| Il nostro termine | Termine Microsoft | Protocollo | +|---|---|---| +| URL di reindirizzamento | *Redirect URL* | OpenID Connect | +| URL di reindirizzamento | *Reply URL (Assertion Consumer Service URL)* | SAML 2.0 | +| Identificatore del fornitore di servizio | *Identifier (Entity ID)* | SAML 2.0 | -:::tip[Richiedetela all'apertura della vostra domanda] -Questa URL dipende dalla vostra organizzazione e non può essere indovinata. Richiedendola all'apertura della vostra richiesta di assistenza, potrete realizzare tutta la configurazione Azure in un'unica volta, senza doverci ritornare. +:::tip[Richiedeteli all'apertura della vostra domanda] +Questi valori dipendono dalla vostra organizzazione e non possono essere indovinati. Richiedendoli all'apertura della vostra richiesta di assistenza, potrete realizzare tutta la configurazione Azure in un'unica volta, senza doverci ritornare. ::: ## Fase 1: Configurazione dell'SSO lato Microsoft EntraID -### Registrazione di una nuova applicazione Azure (portale Azure) +Seguite la sezione corrispondente al protocollo scelto, poi la sezione «Configurazioni di sicurezza supplementari», comune a entrambi. + +### Via OpenID Connect + +#### Registrazione di una nuova applicazione Azure (portale Azure) Per la creazione dell'__app registration__, recatevi sul portale Microsoft Azure, poi in Microsoft EntraID, __"ADD > App Registration"__. @@ -83,7 +123,7 @@ Le informazioni __Application (client) ID__ e __Directory (tenant) ID__ sono vis -### Definizione di un secret +#### Definizione di un secret Nella scheda "Certificates & secrets", create un nuovo secret. @@ -96,10 +136,10 @@ Il valore del secret viene visualizzato una sola volta, subito dopo la sua creaz :::caution[Validità limitata a 24 mesi] -La data di scadenza del secret non può essere superiore a 24 mesi, anche con una data di scadenza personalizzata. __Annotate fin da ora questa data__: alla scadenza, la connessione SSO cesserà di funzionare per tutti i vostri utenti. Vedere la sezione [Rinnovo del secret](#rinnovo-del-secret). +La data di scadenza del secret non può essere superiore a 24 mesi, anche con una data di scadenza personalizzata. __Annotate fin da ora questa data__: alla scadenza, la connessione SSO cesserà di funzionare per tutti i vostri utenti. Vedere la sezione [Mantenimento della federazione nel tempo](#mantenimento-della-federazione-nel-tempo). ::: -### Autorizzazione delle informazioni utilizzate dalla Console +#### Autorizzazione delle informazioni utilizzate dalla Console La Console identifica i vostri utenti a partire dalle informazioni trasportate dal token di identità. È necessaria una sola azione da parte vostra: __esporre l'indirizzo e-mail__. @@ -123,6 +163,37 @@ A titolo informativo, ecco l'insieme delle informazioni consumate dalla Console: | `oid` | Collegamento stabile tra l'account Console e l'identità della vostra directory, anche se l'indirizzo e-mail cambia | Nessuna — emesso nativamente da EntraID | | `given_name`, `family_name` | Nome e cognome visualizzati nella Console | Nessuna — inclusi nell'ambito `profile` | +### Via SAML 2.0 + +#### Creazione dell'applicazione aziendale + +In __Microsoft EntraID__, recatevi in __"Enterprise applications"__, poi __"New application"__. Scegliete __"Create your own application"__, assegnatele un nome e selezionate *Integrate any other application you don't find in the gallery (Non-gallery)*. Confermate con __"Create"__. + +#### Configurazione dell'autenticazione unica + +Nella vostra applicazione, aprite __"Single sign-on"__ e scegliete __"SAML"__. In __"Basic SAML Configuration"__, cliccate su __"Edit"__ e inserite i valori forniti da Cloud Temple: + +- __Identifier (Entity ID)__; +- __Reply URL (Assertion Consumer Service URL)__. + +Salvate. + +#### Attributi e attestazioni + +EntraID emette per impostazione predefinita le attestazioni attese dalla Console. Verificatene la presenza in __"Attributes & Claims"__: + +| Attestazione | Utilizzo | Azione da parte vostra | +|---|---|---| +| `…/claims/emailaddress` | Indirizzo di connessione dell'utente | Nessuna — origine `user.mail` | +| `http://schemas.microsoft.com/identity/claims/objectidentifier` | Collegamento stabile tra l'account Console e l'identità della vostra directory | Nessuna | +| `…/claims/givenname`, `…/claims/surname` | Nome e cognome visualizzati nella Console | Nessuna | + +:::warning[Identificatore di nome (NameID): il punto più spesso trascurato] +In __"Attributes & Claims"__ → __"Unique User Identifier (Name ID)"__, impostate l'origine su __user.objectid__ e il formato su __Persistent__. + +Per impostazione predefinita, EntraID emette l'indirizzo e-mail come NameID. Se un utente cambia indirizzo, la Console lo tratterebbe come una persona diversa e perderebbe i suoi diritti. L'identificatore di oggetto, invece, non cambia mai. +::: + ### Configurazioni di sicurezza supplementari (opzionale ma consigliato) Per impostazione predefinita, Microsoft EntraID così configurato consentirà a qualsiasi utente del vostro tenant Azure di connettersi alla vostra organizzazione Cloud Temple. È possibile limitare a livello di __"App Registration"__ gli accessi per autorizzare solo un elenco di utenti o gruppi. @@ -168,18 +239,21 @@ Questa parte della configurazione viene effettuata a livello dell'organizzazione A tal fine, presentate __una richiesta di assistenza__ nella Console indicando il vostro desiderio di configurare una federazione Microsoft EntraID, precisando: - il nome della vostra organizzazione; +- __il protocollo scelto__: OpenID Connect o SAML 2.0; - il nome di un referente, con la sua e-mail e il suo numero di telefono, per finalizzare la configurazione; -- l'__Application (client) ID__ annotato alla fase 1; -- il __Directory (tenant) ID__ annotato alla fase 1. +- __con OpenID Connect__: l'__Application (client) ID__ e il __Directory (tenant) ID__ annotati alla fase 1; +- __con SAML 2.0__: l'__URL dei metadati di federazione__ della vostra applicazione. -Trasmettete il __secret client__ tramite il canale sicuro indicato dal vostro referente, e non nel corpo della richiesta. +Con OpenID Connect, trasmettete il __secret client__ tramite il canale sicuro indicato dal vostro referente, e non nel corpo della richiesta. Con SAML, non viene scambiato alcun secret. -Non appena la configurazione sarà realizzata lato Console, il referente indicato ne sarà informato e riceverà la __"Redirect URL"__ da dichiarare. +Non appena la configurazione sarà realizzata lato Console, il referente indicato ne sarà informato. -## Fase 3: Dichiarazione della "Redirect URL" +## Fase 3: Dichiarazione della "Redirect URL" (OpenID Connect) Se non avete indicato la "Redirect URL" al momento della creazione dell'applicazione, aggiungetela ora. +Con SAML 2.0, gli URL equivalenti sono già stati dichiarati in __"Basic SAML Configuration"__ alla fase 1: passate direttamente alla fase 4. + Nella pagina iniziale dell'App Registration, nel menu "Overview", cliccate su "Add a Redirect URL". @@ -208,9 +282,13 @@ Una volta realizzate tutte le fasi, potete autenticarvi alla vostra organizzazio La federazione delle identità gestisce __l'autenticazione__, non le __autorizzazioni__. Un utente che si connette per la prima volta tramite l'SSO non dispone di alcun diritto finché un proprietario dell'organizzazione non gliene ha attribuiti dalla Console. ::: -## Rinnovo del secret +## Mantenimento della federazione nel tempo + +È il principale punto di vigilanza: qualunque sia il protocollo, un elemento scade, e la sua scadenza interrompe l'SSO __per tutti i vostri utenti__. -Il secret client scade al più tardi 24 mesi dopo la sua creazione. Alla scadenza, la connessione SSO cessa di funzionare per tutti i vostri utenti. Anticipatene il rinnovo: +### Con OpenID Connect: il secret client + +Il secret client scade al più tardi 24 mesi dopo la sua creazione. Anticipatene il rinnovo: 1. in "Certificates & secrets", create un __nuovo__ secret senza eliminare il precedente; 2. trasmettetene il valore a Cloud Temple tramite il canale sicuro, aprendo una richiesta di assistenza; @@ -218,22 +296,31 @@ Il secret client scade al più tardi 24 mesi dopo la sua creazione. Alla scadenz Conservare i due secret durante il passaggio evita qualsiasi interruzione di servizio. +### Con SAML 2.0: il certificato di firma + +Il certificato di firma emesso da EntraID ha una durata di vita limitata, di tre anni per impostazione predefinita. + +__Avvisateci prima di qualsiasi rotazione di certificato__, tramite una richiesta di assistenza, rispettando il periodo di sovrapposizione proposto da Microsoft. Se ci avete trasmesso un certificato sotto forma di file anziché l'URL dei metadati, allegate il nuovo certificato alla vostra richiesta. + ## Buone pratiche - __Gestite l'accesso per gruppi__ anziché per utenti: l'arrivo o la partenza di un collaboratore viene allora trattato nella vostra directory, senza intervento sulla Console. - __Attivate l'autenticazione a più fattori__ sull'applicazione nelle vostre politiche di accesso condizionale EntraID: si applicherà allora all'accesso alla Console. -- __Programmate un avviso__ all'avvicinarsi della data di scadenza del secret. +- __Programmate un avviso__ all'avvicinarsi della data di scadenza del secret client o del certificato di firma, a seconda del protocollo scelto. - __Conservate almeno un account proprietario locale__ sulla vostra organizzazione Cloud Temple, al di fuori della federazione, per mantenere un accesso in caso di indisponibilità della vostra directory. ## Risoluzione dei problemi -| Sintomo | Causa probabile | -|---|---| -| `AADSTS50011`: l'URL di reindirizzamento non corrisponde | La "Redirect URL" dichiarata in Azure differisce da quella fornita da Cloud Temple. Verificatela carattere per carattere, compresa l'assenza di `/` finale. | -| `AADSTS7000215`: secret non valido | Il secret è scaduto, oppure il valore trasmesso era il "Secret ID" anziché il "Value". | -| `AADSTS50105`: utente non assegnato | L'opzione "Assignment required" è attiva e l'utente non è assegnato all'applicazione. | -| Il pulsante di connessione non appare nella pagina | La configurazione non è ancora attiva lato Cloud Temple. | -| L'utente è autenticato ma la Console rifiuta l'accesso | Il claim `email` è assente dal token, oppure nessun diritto è stato attribuito all'utente. | +| Sintomo | Protocollo | Causa probabile | +|---|---|---| +| `AADSTS50011`: l'URL di reindirizzamento non corrisponde | Entrambi | L'URL dichiarato in Azure differisce da quello fornito da Cloud Temple. Verificatelo carattere per carattere, compresa l'assenza di `/` finale. | +| `AADSTS700016`: applicazione non trovata | SAML 2.0 | L'*Entity ID* dichiarato non corrisponde a quello fornito da Cloud Temple. | +| `AADSTS7000215`: secret non valido | OpenID Connect | Il secret è scaduto, oppure il valore trasmesso era il "Secret ID" anziché il "Value". | +| `AADSTS50105`: utente non assegnato | Entrambi | L'opzione "Assignment required" è attiva e l'utente non è assegnato all'applicazione. | +| Il pulsante di connessione non appare nella pagina | Entrambi | La configurazione non è ancora attiva lato Cloud Temple. | +| L'utente è autenticato ma la Console rifiuta l'accesso | Entrambi | L'indirizzo e-mail è assente dal token, oppure nessun diritto è stato attribuito all'utente. | +| L'utente appare come un nuovo account a ogni connessione | SAML 2.0 | Il NameID non è impostato su `user.objectid`. | +| Errore di firma all'arrivo sulla Console | SAML 2.0 | Il certificato di firma è stato rinnovato lato Azure senza che ne fossimo informati. | ## Supporto From 2343e8569d2b81bb7aa89917dd47eaf29602c4f5 Mon Sep 17 00:00:00 2001 From: KChapron Date: Tue, 18 Aug 2026 16:45:41 +0200 Subject: [PATCH 3/3] =?UTF-8?q?fix(iam):=20corrige=20le=20lien=20mort=20de?= =?UTF-8?q?=20la=20carte=20=C2=AB=20Tutoriels=20=C2=BB=20de=20la=20page=20?= =?UTF-8?q?IAM?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit La carte « Tutoriels » de la vue d'ensemble IAM pointait vers ./iam/tutorials/sso_aad, un document qui n'existe pas : le tutoriel concerné s'appelle sso_azuread. Le lien renvoyait donc vers une page introuvable, dans les cinq langues. Le lien vise désormais l'index de la catégorie plutôt qu'un tutoriel particulier, ce qui correspond à l'intitulé de la carte et évite qu'un renommage futur ne le casse à nouveau. Le slug de la catégorie étant identique dans les cinq locales et trailingSlash valant false, la forme relative résout correctement pour chacune. Les fichiers i18n/*/console/security.md portent le même lien erroné mais n'ont pas de source française : Docusaurus ne les rend pas. Ils relèvent d'un nettoyage distinct des traductions orphelines. --- docs/console/iam/iam.md | 2 +- .../current/console/iam/iam.md | 2 +- .../current/console/iam/iam.md | 2 +- .../current/console/iam/iam.md | 2 +- .../current/console/iam/iam.md | 2 +- scripts/translate_py/translation-meta.json | 16 ++++++++-------- 6 files changed, 13 insertions(+), 13 deletions(-) diff --git a/docs/console/iam/iam.md b/docs/console/iam/iam.md index c4d90c2b..cae44283 100644 --- a/docs/console/iam/iam.md +++ b/docs/console/iam/iam.md @@ -21,6 +21,6 @@ Il permet d’administrer des comptes locaux tout en supportant une hybridation

Tutorials

Apprenez étape par étape à configurer et utiliser nos services avec des guides détaillés.

- Découvrir les tutoriels → + Découvrir les tutoriels →
diff --git a/i18n/de/docusaurus-plugin-content-docs/current/console/iam/iam.md b/i18n/de/docusaurus-plugin-content-docs/current/console/iam/iam.md index 58f01e58..990ea987 100644 --- a/i18n/de/docusaurus-plugin-content-docs/current/console/iam/iam.md +++ b/i18n/de/docusaurus-plugin-content-docs/current/console/iam/iam.md @@ -21,6 +21,6 @@ Es ermöglicht die Verwaltung lokaler Konten und unterstützt gleichzeitig die H

Tutorials

Lernen Sie Schritt für Schritt die Konfiguration und Nutzung unserer Dienste anhand detaillierter Anleitungen.

- Tutorials entdecken → + Tutorials entdecken →
\ No newline at end of file diff --git a/i18n/en/docusaurus-plugin-content-docs/current/console/iam/iam.md b/i18n/en/docusaurus-plugin-content-docs/current/console/iam/iam.md index fdc7d20d..8f661561 100644 --- a/i18n/en/docusaurus-plugin-content-docs/current/console/iam/iam.md +++ b/i18n/en/docusaurus-plugin-content-docs/current/console/iam/iam.md @@ -21,6 +21,6 @@ It enables the administration of local accounts while supporting hybrid configur

Tutorials

Learn step by step how to configure and use our services with detailed guides.

- Discover tutorials → + Discover tutorials →
\ No newline at end of file diff --git a/i18n/es/docusaurus-plugin-content-docs/current/console/iam/iam.md b/i18n/es/docusaurus-plugin-content-docs/current/console/iam/iam.md index 1db02a43..13ae1e1f 100644 --- a/i18n/es/docusaurus-plugin-content-docs/current/console/iam/iam.md +++ b/i18n/es/docusaurus-plugin-content-docs/current/console/iam/iam.md @@ -21,6 +21,6 @@ Permite administrar cuentas locales al tiempo que admite la hibridación con con

Tutoriales

Aprenda paso a paso a configurar y utilizar nuestros servicios con guías detalladas.

- Descubrir los tutoriales → + Descubrir los tutoriales →
\ No newline at end of file diff --git a/i18n/it/docusaurus-plugin-content-docs/current/console/iam/iam.md b/i18n/it/docusaurus-plugin-content-docs/current/console/iam/iam.md index 4b9e5abb..1bc17b91 100644 --- a/i18n/it/docusaurus-plugin-content-docs/current/console/iam/iam.md +++ b/i18n/it/docusaurus-plugin-content-docs/current/console/iam/iam.md @@ -21,6 +21,6 @@ Consente di amministrare account locali supportando al contempo un'integrazione

Tutorial

Impara passo dopo passo a configurare e utilizzare i nostri servizi con guide dettagliate.

- Scopri i tutorial → + Scopri i tutorial →
\ No newline at end of file diff --git a/scripts/translate_py/translation-meta.json b/scripts/translate_py/translation-meta.json index 6d7a6095..568131d1 100644 --- a/scripts/translate_py/translation-meta.json +++ b/scripts/translate_py/translation-meta.json @@ -85,10 +85,10 @@ "it": "1b52c385e0e00c19a63588dc81ea75e21417da5a1356cea502171fc8b38ea454" }, "console/iam/iam.md": { - "en": "484e52649550098662ce7e64419dd94d10c20b10e5e2d2bee7e987d53841c949", - "de": "484e52649550098662ce7e64419dd94d10c20b10e5e2d2bee7e987d53841c949", - "es": "484e52649550098662ce7e64419dd94d10c20b10e5e2d2bee7e987d53841c949", - "it": "484e52649550098662ce7e64419dd94d10c20b10e5e2d2bee7e987d53841c949" + "en": "6343fe83b77f396e23d9f8e15b4c9dfd68aa19572825d091d94a100558b61b14", + "de": "6343fe83b77f396e23d9f8e15b4c9dfd68aa19572825d091d94a100558b61b14", + "es": "6343fe83b77f396e23d9f8e15b4c9dfd68aa19572825d091d94a100558b61b14", + "it": "6343fe83b77f396e23d9f8e15b4c9dfd68aa19572825d091d94a100558b61b14" }, "console/iam/quickstart.md": { "en": "3b3a44b3e281fa129a58463c3dae6336fd8ee4809d2ba091f693f65850739434", @@ -103,10 +103,10 @@ "it": "606b1e74af281a97dc6c45adc4a7e5fcf461776e0cdf2ea86945b3ceabe9d7d0" }, "console/iam/tutorials/sso_azuread.md": { - "en": "a2816415fe1eb55b7cf314d1906133321b7cd371bf5336a1b6d5b825f26d8203", - "de": "a2816415fe1eb55b7cf314d1906133321b7cd371bf5336a1b6d5b825f26d8203", - "es": "a2816415fe1eb55b7cf314d1906133321b7cd371bf5336a1b6d5b825f26d8203", - "it": "a2816415fe1eb55b7cf314d1906133321b7cd371bf5336a1b6d5b825f26d8203" + "en": "72f752096aee9255e48d816010882035b50add83ea687e2690cb61b48d03176d", + "de": "72f752096aee9255e48d816010882035b50add83ea687e2690cb61b48d03176d", + "es": "72f752096aee9255e48d816010882035b50add83ea687e2690cb61b48d03176d", + "it": "72f752096aee9255e48d816010882035b50add83ea687e2690cb61b48d03176d" }, "console/iam/tutorials/sso_intune.md": { "en": "2a5fc99951f052a2c71188580b1c2b51df998ab9b958fd09d4bd4d3160ec7878",