Integrating Azure AD with MyVIP NexGen login portal.
Configure Azure AD Integration with MyVIP NexGen Self Service Portal
- Login to the Azure Portal as a Global Administrator
- Click on 'Azure Active Directory'
- Click on 'Enterprise applications'
- Click on 'New application'
- Click on 'Create your own application'
- Select 'Integrate any other application you don't find in the gallery (Non-gallery)'
- Add the name “MyVIP” (or similar) as the app name, then click 'Create'. The Application view will be displayed
Setup SAML configurations for the “MyVIP” Enterprise Application
- In the application view, on the left panel, Click on 'Single Sign-on'
- Select SAML as the Single Sign-on Method
- In a separate tab or browser window, download the metadata file from https://login.vip.symantec.com/viplogin/saml/metadata
- On the “Setup Single Sign-On with SAML” page, select 'Upload metadata file', then click 'Add'. The Basic SAML Configuration section should populate.
- Enter Relay State Value as https://login.vip.symantec.com/viplogin/home?successUrl=<organizations’s success url>?cancelUrl=< organizations’s cancel url >?errorUrl=< organizations’s error url>
Adding User Attributes to the SAML Configuration
- Click 'Edit' in the 'Attributes and Claims' Section
- Delete all the 'Additional claims'. Leave the predefined 'Unique User Identifier (Name ID)'
- Add an additional claim with 'Claim name' “EMAIL” mapped to user.userprincipalname
- Add an additional claim with 'Claim name' “PHONE” mapped to user.telephonenumber
Certificate Download and Azure AD Identifier
- Download the Base64 certificate from SAML Signing Certificate Section
- Copy the 'Azure AD Identifier' from “Set Up MyVIP” section and save it in a text editor
Users and Groups
- Click on 'Users and Groups' from the left-pane of the Application View.
- Add the Users/Groups in your organization that you would like to assign the MyVIP application.
Upload the Azure AD Identifier and certificate to VIP Manager
Complete the following steps in VIP Manager to add Azure AD Identifier ID and Azure AD certificate:
- In VIP Manager, click the Account tab.
- Under the Account tab, select 'Single Sign-on'.
- Click Edit next to IdP Service Settings.
- Enter the Azure AD Identifier URL that you saved earlier as the entity ID.
- Click Browse to select the certificate that you saved earlier.
- Click Submit.