

Single Sign-On Service › SSO Getting Started Guide › How to Connect a CA CloudMinder Tenant to an Office 365 Tenant › Overview › The CSP Admin Tasks to Connect a CA CloudMinder Tenant to an Office 365 Tenant › CSP Tasks to Configure User Provisioning
CSP Tasks to Configure User Provisioning
Note: These procedures need to be performed by the CSP Administrator.
This section requires the following information:
- [attributeImmutableId]
- [attributeUPN]
- [tenantAdmin]
- [tenantId]
Import Role Definitions
As a CSP Administrator, use the following procedure to import the role definitions.
Follow these steps:
- Log in to the CA CloudMinder Management Console.
- Navigate to Environments, [tenantId], Role and Task Settings, Import.
- Select Office 365.
- Click Finish.
- When notified, restart the environment.
Configure Attribute Mappings
As a CSP Administrator, use the following procedure to configure attribute mappings.
Follow these steps:
- Log in to the CA CloudMinder Management Console.
- Navigate to Environments, [tenantId], Advanced Settings, Provisioning, Attribute Mappings
- Add Attribute Mapping:
- User Attribute: %IMMUTABLEID%
- Provisioning Attribute: [attributeImmutableId]
- Add Attribute Mapping:
- User Attribute: %UPN%
- Provisioning Attribute: [attributeUPN]
- When notified, restart the environment.
Enable Admin Roles for Provisioning
As CSP Administrator, you must enable the Admin Roles in the environment.
Follow these steps:
- Log in to the CA CloudMinder Console.
- Navigate to Roles and Tasks, Admin Roles, Enable/Disable Admin Role.
- Enable the following roles:
- CSP Provisioning Manager
- Endpoint Manager
- MSP Provisioning Manager
- Provisioning Role Manager
- Tenant Provisioning Manager
- Select and Modify the changes.
Assign Provisioning Manager Role
Assign Tenant Administrators the "Provisioning Manager for Office 365" role.
Follow these steps:
- Log in to the CA CloudMinder Console as CSP Adminsitrator.
- Navigate to Roles and Tasks, Admin Roles, Modify Admin Role Members.
- Select Provisioning Manager for Office 365.
- Add a user: Add a Tenant Administrator.
- Submit the modification.
Enable Policy Express Policies
You must create user attributes for provisioning and SSO to Office 365.
Follow these steps:
- Log in to the CA CloudMinder Console as CSP Administrator.
- Navigate to Policies, Policy Xpress, Enable/Disable Policy Xpress Policy.
- Enable policies:
- Get O365 Account Template
- Get O365 Endpoint
- Create Provisioning User
- Set ImmutableID
- Set UPN
- Select and Modify the policies.
Modify Policy Express Policy for ImmutableID
The policy must be created to accommodate cloud users and synchronized users. The policy should be triggered when the user is assigned the Office 365 Provisioning Role.
Follow these steps:
- Log in to the CA CloudMinder Console as CSP Administrator.
- Navigate to Policies, Policy Xpress, Modify Policy Xpress Policy.
- Select the policy: Set ImmutableID
- In Events, Add Event, configure the following:
- Event State: After
- Event Name: AssignUserToProvisioningRoleEvent
- Submit the modification.
Export Signing Certificate
When complete, this procedure will provide you with the following:
- [certificate], intended for the Tenant Administrator
- [certificateAlias]
Follow these steps:
- Log in to the CSP Console as a CSP Administrator.
- Navigate to Infrastructure, X509 Certificate Management, Trusted Certificates and Private Keys.
- Choose a certificate to sign federation assertions and record the [certificateAlias]. It must be of the type: Private Key and Certificate.
- If the required certificate type does not exist, request or create a certificate and import it.
- Select the Action: Export
- Make sure of the Format: X509-PEM.
- Click Export.
- Give the exported certificate [certificate] to the Tenant Administrator.
Copyright © 2015 CA Technologies.
All rights reserved.
 
|
|