This article describes how to configure single sign-on (SSO) between Microsoft Entra ID (previously Azure Active Directory (AD)) as a third-party IdP to provide seamless authentication into VMware Identity Manager.
JIT provisioning automates the creation of user accounts for web applications. It leverages the SAML (Security Assertion Markup Language) protocol to transfer data from the identity provider to the web applications. Upon a new user's initial login attempt to an authorized app, the identity provider transmits the necessary information to the app for the account creation process.
Microsoft Entra ID, find Enterprise Applications in the list under Manage, and then click New Application. Enterprise applications.Create.Single Sign On. SAML to start configuring the app. Catalog > Web apps > Settings > Click SP metadata. .xml file.xmlUsers and Groups and assign it to your users. Any user assigned to this application is automatically provisioned in VMware Identity Manager. NameID value to userPrincipalName. urn:oasis:names:tc:SAML:2.0:ac:classes:unspecifiedAADSTS75011: Authentication method 'MultiFactor, PasswordlessPhoneSignIn' by which the user authenticated with the service doesn't match requested authentication method 'Password'. default_access_policy_set > Rule 1 (Web Browser):EntraID PasswordPassword (Local Directory)NOTE: Whenever we change certificate on Microsoft Entra ID we will have to reprocess the idp metadata in vIDM or else saml validation will fail.
JIT Group Provisioning in vIDM 3.3.7 is not supported. This feature is only available on the SaaS version of vIDM/Workspace One