!!! We have migrated this Cloud Instance to our own hosted Server instance !!!

Please follow this link to get to the content you wanted: 

https://wiki.resolution.de/doc/saml-sso/latest/confluence/setup-guides-for-saml-sso/azure-ad

Thanks for your understanding.



This guide describes how to complete the initial setup for SAML Single Sign On (SSO) for Confluence with Azure AD, applicable till plugin version 0.14.4. If you need any further support please feel free to contact us here.

Prerequisites

Confluence must be accessible via HTTPS

See https://confluence.atlassian.com/display/DOC/Running+Confluence+Over+SSL+or+HTTPS for instructions. This is necessary because Azure AD accepts only HTTPS-URLs for SAML endpoints.

Azure Active Directory Premium

If you already have an Azure AD account, but are not sure if your premium account is enabled

After signed in to your Azure AD account, click on Active Directory and choose the directory you want to use with SAML Single Sign On. After your chosen directory opened up, click on Licences on the right side. Then, under the Licence Plans you will see the licence type you have - Microsoft Azure Active Directory Premium, if it is enabled. Otherwise, see video provided above to enable it.


If your Azure premium account  is not yet enabled, find out how to enable Azure Active Directory Premium trial here. To improve the user experience of our plugin and reduce the costs of our customers from purchasing Azure Premium account, we already applied for being listed in Azure AD Application Gallery. Due to some internal reasons at Microsoft, this process is taking excessively long. If you are already a customer of Azure AD, your voice may help us speed up the process. Support us and request the plugin integration here: waadpartners@microsoft.com.

Installation Procedure

Step 1: Install the plugin

Step 2: Setup the Azure AD (Substep A-D)

Step 3: Configure the Plugin (Substep A-B)

Step 4: Test

Step 5: Enable login redirection



Step 1: Install the plugin  

Back to Top

Step 2: Setup the Azure AD  

Step 2 will be completed in Azure AD. 

Substep A : Select your directory and start application dialog

 

      















Substep B: Add a new application

Back to Top

Substep C: Configure the new application




Substep D: Grant access to users


Back to Top

Step 3: Configure the Plugin  

Substep A: Load Azure AD Metadata

Substep B: Configure general Confluence groups

If a user logs in using SAML, he will be added to the groups specified in the User Groups section. This applies to all users. The user is assigned to these groups in addition to the groups in the SAML-response's attribute. The standard group in Confluence is called "confluence-users".


 

Back to Top

Step 4: Test 

In a separate browser, open the URL https://<your-confluence>/plugins/servlet/samlsso.

You should be authenticated by your Azure AD and redirected to the Confluence Dashboard.

Step 5: Enable login redirection 

After testing, you can enable the login page redirection to finally activate the plugin. After checking the Enable SSO Redirect checkbox and clicking Save settings, requests to the Confluence login page should be redirected to the Azure AD.


If Enable SSO Redirect is enabled, you can login to Confluence manually by browsing https://<your-confluence>/login.action?nosso. Use this URL if you need to login a local user unknown to the Azure AD or if there are any issues with Single Sign On.

Back to Top

Note: To provide a greater user experience, we are going to release newer version of the SAML plugins with improved user interface in end Nov/early Dec 2016. The associated documentation can be found here.