Users with the Manage Users and Permissions user permission can set up single sign-on with Azure. The SAML Azure integration is the recommended SSO option for Microsoft users.
This integration creates accounts as users log in for the first time and gives them the option to log in with Microsoft.
This is a three-step process:
- In Azure, create a SAML application.
- In Facilities Drawing, set up the integration.
- In Facilities Drawings, set default roles for users who log in via Azure.
| Important: Because of the technical knowledge required, your district's IT administrator will most likely need to perform this procedure. |
Step 1: In Microsoft Azure, create a SAML application.
Step 2: In Facilities Drawings, set up the integration.
a. In Drawings, select Admin > Single Sign On > SAML Configuration. The SAML Integration Admin page appears.
b. Next to Azure, click . A pop-up appears.
c. Do the following:
|
i. Under Issuer, enter the IDP Metadata URL.
ii. Enter the Login Link, if desired. iii. Under Certificate, enter the IDP Certificate.
iv. Select the Classification for Users Group. v. Click Generate Metadata XML file.
|
d. Click Save.
Step 3: In Drawings, set default roles for users who log in via Azure.
| Note: You can create as many SAML groups as you want. When a user first logs in, they are assigned a role based on the group they belong to. You can also manage additional roles in Drawings, but cannot remove these default roles. |
a. Select Admin > Single Sign On > SAML Group Settings. The Manage SAML Groups page appears.
b. Click +Add SAML Group. A pop-up appears.
c. Do any of the following:
|
i. Enter a Group Name.
ii. Select the desired Roles. iii. Select the desired Systems.
iv. Select the desired Asset Types.
|
d. Click Save.
e. Repeat steps 2-4 for each group you want to add.
Comments
0 comments
Please sign in to leave a comment.