SAML SSO
๐ ืงืื ืคืืืืจืฆืืืช SAML SSO ืฉื Ruijie Cloud ืขื Microsoft Azure Active Directory
ืกืงืืจื ืืืืืชโ
ืืืืจ ืื ืืกืคืง ืืืจืืืช ืืืฆื ืืืืืืจ ืืช Azure Active Directory (Azure AD) ืืกืคืง ืืืืืืช (IdP) ืขืืืจ ืืืฉืื Ruijie Cloud. ืื ืขืืืจ ืืื ืืืื ืฉืจืืฆืื ืืืขืืืจ ืืช ื-Active Directory ืฉืืื ืืคืืืคืืจืืช ืขื ื ืืื Azure ืืื ืืฉืื SAML SSO ืขื ืืืฉืื Ruijie Cloud. ืืืืืฅ ืืื ืืืื ืืงืจืื ืืช "ืฉืืืื SAML ืืืื ืืืืื ืื" (SAML Integration for Dashboard) ืืคื ื ืฉืืืฉืืืื.
ืืจืืฉืืช ืืงืืืืืชโ
- ืขืืื ืืืืืช ืืขื ืืฉืืื Microsoft Azure AD.
- ืขืืื ืืืืืช ืืขื ืืฉืืื Ruijie Cloud. (ืืฉืืื Ruijie Cloud ืืฉืืฉ ืืืคืขืืช SAML SSO ืืืงืื ืคืืืืจืฆืื ืฉื ืชืคืงืืืื ืืขืืืื ืขื Azure AD).
ื ืืืโ
1. ืืชืงื ืช ืืืฉืื Ruijie Cloud ื-Azureโ
(1) ืืคืืจืื Azure, ืืืฅ ืขื Azure Active Directory.
(2) ืืฆื ืฉืืื, ืืืฅ ืขื Manage (ื ืืืื) > Enterprise applications (ืืืฉืืืื ืืจืืื ืืื).
(3) ืืืฅ ืขื New application (ืืืฉืื ืืืฉ).
(4) ืืืฅ ืขื Create your own application (ืฆืืจ ืืืฉืื ืืฉืื).
(5) ืืื Ruijie Cloud (ืื ืฉืืืช ืืืจืื ืื ืืชื ืื ืืืืืื ืืงืืืช), ืืืจ Integrate any other application you donโt find in the gallery (Non-gallery) (ืฉืื ืื ืืืฉืื ืืืจ ืฉืืื ื ืืืฆื ืืืืจืื), ืืืืฅ ืขื Create (ืฆืืจ).
(6) ื ืืื ืืืจื ืืืฃ Enterprise applications (ืืคื ืฉืืืฆื ืืฉืื (2)). ืืืืจ ืฉืืืฉืื Ruijie Cloud ืืืชืงื ืืืฆืืื, ืชืจืื ืืช Ruijie Cloud ืืจืฉืืืช ืืืืฉืืืื ืฉืื.
2. ืืฆืืจืช ืชืคืงืืื ืืืฉืื (App Roles) ืืชืื ืืืฉืื Ruijie Cloud ื-Azureโ
ืืฉ ืฉืชื ืฉืืืืช ืืืฆืืืจ ืขื ืชืคืงืืื ืืืฉืื ืืืืฆืขืืช ืคืืจืื Azure:
- ืชืคืงืืื ืืืฉืื ืืืืฆืขืืช ืืืฉืง ืืืฉืชืืฉ ืฉื ืคืืจืื Azure (ืืคื ืฉืืืฆื ืืืื).
- ืชืคืงืืื ืืืฉืื ืืืืฆืขืืช ืื ืืคืกื.
(1) ื ืืื ืื App registrations (ืจืืฉืืื ืืืฉืืืื).
(2) ืืืฅ ืขื All applications (ืื ืืืืฉืืืื).
(3) ืืืฅ ืขื Ruijie Cloud (ืื ืื ืฉื ืืืจ ืฉืืืืจืช ืืฉืื 1).
(4) ืืืฅ ืขื App roles (ืชืคืงืืื ืืืฉืื).
(5) ืืืฅ ืขื Create app role (ืฆืืจ ืชืคืงืื ืืืฉืื).
(6) ืฆืืจ ืชืคืงืื ืืืืืจ ืืช Display name (ืฉื ืชืฆืืื), Allowed member types (ืกืืื ืืืจืื ืืืชืจืื) ื-Value (ืขืจื). ื-Value ืืื ืื ืฉืืืขืืจ ืืืฆืืจืช SAML.
(7) ืืืฅ ืขื Apply (ืืื).
(8) ืืืืจ ืขื ืฉืืืื (5) ืขื (7) ืขืืืจ ืื ืชืคืงืืื ืืืืฉืื ืืืจืืฉืื.
3. ืืืืจืช ืืฉืชืืฉืื ืืชืคืงืืืื (Users and Roles) ืืืืฉืื Ruijie Cloud ื-Azureโ
(1) ื ืืื ืื ืืฃ Enterprise applications (ืืคื ืฉืืืฆื ืืฉืื 1(2)).
(2) ืืืฅ ืขื Ruijie Cloud.
(3) ืืฆื ืฉืืื, ืืืฅ ืขื Manage (ื ืืืื) > Users and groups (ืืฉืชืืฉืื ืืงืืืฆืืช).
(4) ืืืฅ ืขื Add user/group (ืืืกืฃ ืืฉืชืืฉ/ืงืืืฆื).
(5) ืืืฅ ืขื None selected (ืื ื ืืืจ) ืืชืืื Users.
(6) ืืืจ ืืฉืชืืฉืื/ืงืืืฆืืช ืืืจืฉืืื ืืืืฅ ืขื Select (ืืืจ).
(7) ืืืฅ ืขื None selected (ืื ื ืืืจ) ืืชืืื Select a role (ืืืจ ืชืคืงืื).
(8) ืืืจ ืชืคืงืื ืืืจืฉืืื ืฉื ืืฆืจื ืืฉืื 2 ืืืืฅ ืขื Select (ืืืจ).
(9) ืืืฅ ืขื Assign (ืืงืฆื).
4. ืืืืจืช Single Sign-On (SSO) ืืืืฉืื Ruijie Cloud ื-Azureโ
(1) ื ืืื ืื ืืฃ Enterprise applications.
(2) ืืืฅ ืขื Ruijie Cloud.
(3) ืืฆื ืฉืืื, ืืืฅ ืขื Manage (ื ืืืื) > Single sign-on (ืื ืืกื ืืืืื).
(4) ืืืจ SAML.
(5) ืืืฅ ืขื Edit (ืขืจืื) ืืืืื ืืช Attributes & Claims (ืชืืื ืืช ืืชืืืขืืช).
(6) ืืืฅ ืขื Add new claim (ืืืกืฃ ืชืืืขื ืืืฉื).
(7) ืืื Role (ืชืคืงืื) ืืชืืื Name (ืฉื) ืืืืจ user.assignedroles (ืชืคืงืืืื ืฉืืืงืฆื ืืืฉืชืืฉ) ืืชืืื Source attribute (ืชืืื ืช ืืงืืจ). ืืืฅ ืขื Save (ืฉืืืจ).
(8) ืืืืจ ืฉื ืืกืคื ืืชืืืขื ืืืืฉื, ืืืฅ ืขื Add a group claim (ืืืกืฃ ืชืืืขืช ืงืืืฆื).
(9) ืืืจ All groups (ืื ืืงืืืฆืืช).
(10) ืืืฅ ืขื Download (ืืืจื) ืืื Federation Metadata XML (ืืื ื ืชืื ืื ืฉื ืคืืจืฆืื XML) ืืืืื ืืช SAML Signing Certificate (ืืืฉืืจ ืืชืืืช SAML). (ืงืืืฅ ืื ื ืืจืฉ ืืืคืขืืช SSO ื-Ruijie Cloud ืืฉืื 5).
5. ืืืืจืช SSO ื-Ruijie Cloudโ
(1) ืืืื ืก ื-Ruijie Cloud ืื ืืื ืื SAML SSO > SAML Settings.
(2) ืืืฅ ืขื Upload XML (ืืขืื XML) ืืืขืื ืืช ืงืืืฅ ื-Federation Metadata XML ืฉืืืจื ืืฉืื 4.
(3) ืืืืจ ืืืขืืื, ืืืฅ ืขื Enable SAML SSO (ืืคืขื SAML SSO).
(4) ืืขืชืง ืืช ื-Consumer URL (ืืชืืืช URL ืืฆืจืื) ืืฉืืืจ ืืืชื ืืืืฉื.
(5) ืืืืจ ืืืฃ ืืืืช ืฉื ืคืืจืื Azure, ืืืฅ ืขื Manage (ื ืืืื) > Single sign-on (ืื ืืกื ืืืืื). ืืืืื ืืช Basic SAML Configuration (ืงืื ืคืืืืจืฆืืืช SAML ืืกืืกืืช), ืืืฅ ืขื Edit (ืขืจืื).
(6) ืืจืืก ืืช Reply URL (Assertion Consumer Service URL) (ืืชืืืช URL ืืืฉืื) ืืืืืืจ ืืืจืืจืช ืืืื ืืงืืื ืขื Consumer URL (ืืชืืืช URL ืืฆืจืื) ืืฉืื (4).
ืืฉืื Identifier (Entity ID) (ืืืื) ืืืืจ ืืืชืืื ืืืืืืืืช. ืื ืื, ืืื https://cloud-as.ruijienetworks.com ืืฉืื ืื. (ืืขืจื: ืืืืื ืืคืืฃ ืืขืจื ืืฉืื Reply URL).

6. ืืฆืืจืช ืชืคืงืืื ืื ืื SAML ื-Ruijie Cloudโ
(1) ืืืื ืก ื-Ruijie Cloud, ื ืืื ืื SAML SSO > SAML Roles Manager ืืืืฅ ืขื Add SAML role (ืืืกืฃ ืชืคืงืื SAML).
(2) ืฆืืจ ืชืคืงืื ืืืืจ ืืช ืืจืฉืืืช ืืืืฉื (Read-only - ืงืจืืื ืืืื ืื Read & Write - ืงืจืืื ืืืชืืื) ืขืืืจ ืชืคืงืื ืื.
ืฉื ื-Role (ืชืคืงืื) ืืืื ืืืชืืื ื-Value (ืขืจื) ืฉื ืชืคืงืื ืืืืฉืื ืฉืืืืืจ ื-Azure. ืืืจืช, ืืฉืชืืฉืื ืื ืืืืื ืืืชืืืจ ืืืืฆืขืืช SAML ืืืจืืื ืฉืืืืืจ.
(3) ืืืฅ ืขื Save (ืฉืืืจ). ืืืืจ ืขื ืฉืืืื (1) ืขื (3) ืขืืืจ ืื ืชืคืงืื SAML ื ืืกืฃ ืฉื ืืฆืจ ื-Azure.

ืืืืงืช ืืืืฉืื ื-Azure AD
https://myapps.microsoft.com/

ืฉืืืืช ื ืคืืฆืืช (FAQ)
- ืื ืชืคืงืื ื-Ruijie Cloud ืฉืื ื ืืื ืฉื-Azure, ืืืฉืชืืฉ ืื ืืฆืืื ืืืชืืืจ ืืืืฆืขืืช SAML.
- ืื ืืื ื ืืืื ืืืชืืืจ ืืืืฆืขืืช SAML, ืืื ืฉืืืคืืืงืฆืื ื-Azure AD ืืืืืจืช ืืจืืื ืืฉืืืฉืชืืฉ ืจืฉืื ืืืคืืืงืฆืื ื-Azure AD.
