This document is intended to be paired with Cloud Streaming - SSO - SAML Configuration for users with Azure Entra ID to manage their users.
You must start a SAML app on your Azure Portal to obtain the necessary metadata to configure the Swank Cloud Streaming SAML SSO. It is best to configure both ends of this SAML handshake together with 2 open windows or tabs on your browser.
- One with your Azure Portal.
- A second with the Swank Cloud Streaming Portal SSO Configuration page.
Step 1 - Begin Azure SAML Application Configuration
- Navigate to Enterprise applications service within your Azure portal for your desired tenant.
- Click New Application
- Click Create your own application
- Complete the Create your own application form:
- Name of App: Swank Digital Campus or Swank Cloud Streaming is recommended
- Choose "Integrate any other application you don't find in the gallery (Non-gallery)
- Click Create
Step 2 – Assign Users and groups
- With the Overview page of your new app, select the first option under Getting Started, 1. Assign users and groups
- Select Add user/group
- Add Users and/or Groups as desired, completing clicking Select, then Assign
Step 3 – Setup Single sign-on
- Within the Overview page or the Manage menu, select Single sign-on to navigate to the SSO configuration page
- Select SAML as the sign-on method
- Within section 3 of the configuration, copy the App Federation Metadata Url
Step 4 - Configure Streaming Server SAML Authentication
- In a separate tab/window, login to your Swank Streaming portal with your registered Admin account.
- Select SSO Configuration from the left menu.
- Review the list of SSO Configurations for your portal
-
Legacy Providers: If you've previously configured SSO via SAML or Google OAuth, you'll find their configuration listed at the bottom here.
- Note: You cannot "upgrade" your existing SAML configuration to our new Identity Service host - you must create a new SAML configuration.
- The legacy configurations are deactivated automatically when a new SSO Identity Provider Configuration is activated. You can "fallback" to the legacy provider by deactivating the new provider(s).
-
SSO Configurations: At the top of the page, see the list of available providers. You can:
- Activate or Deactivate existing configurations via the Active toggle.
- Edit or Delete existing configurations via button actions
- Add new SSO Configurations via the button at the Top. (We'll continue this guide from this route)
-
- Click Add SSO Configuration
- Choose the Provider Type of SAML
- Enter a Display Name - This displays on the list of SSO Configurations as well as the button added to the Login page. (Suggested: Azure SAML)
- In your Portal's SSO Configuration, paste the App Federation Metadata Url copied from Azure into the Idp Metadata Address
- Save the Portal's SSO Configuration to generate the additional details
- Complete the SAML handshake:
- These values will be presented for you to copy and enter back into your SAML Identity Provider's configuration.
- SP EntityID - Required
- Callback Path (ACS Endpoint) - Required
- Once these values are saved at the Identity Provider end, the SAML handshake between your Portal and your Identity Provider should be complete.
- When copying and pasting this info, make sure there is no trailing "/" or spaces on the Azure side. This will result in errors. You must include the whole URL including the unique IDs redacted above
- These values will be presented for you to copy and enter back into your SAML Identity Provider's configuration.
Step 5 - Complete Azure SAML Application Configuration
- Copy the SSO Configuration details back into the Azure SSO Configuration
-
Click Edit of section 1 Basic SAML Configuration
-
In the Basic SAML Configuration add values copies from the Portal to complete the SSO handshake
- Identifier (Entity ID) as the SP EntityID
- Reply URL (Assertion Consumer Service URL) as the Callback Path (ACS Endpoint)
- Click Save
-
Click Edit of section 1 Basic SAML Configuration
- Update Attributes & Claims (section 2) by clicking Edit
- Verify Unique User Identifier Name ID is in an Email format.
- Go to the Attributes & Claims and edit the Additional claims as follows:
-

- Edit the Name values to match as follows to align with the Swank Streaming Portal
-
Required
-
Source attribute: user.userprincipalname OR user.mail
- Name: email
-
Namespace: (This should be blank)
- NOTE: If adding the Namespace for the schema you'll want to use 'emailaddress' instead of 'email' http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress
-
Source attribute: user.userprincipalname OR user.mail
-
Optional
-
Source attribute: user.givenname
- Name: given_name
- Namespace: (This should be blank)
-
Source attribute: user.surname
- Name: family_name
- Namespace: (This should be blank)
-
Source attribute: user.givenname
-
Required
- Edit the Name values to match as follows to align with the Swank Streaming Portal
-
Step 6
Role Mapping, User Authorization, and Permission Elevation
All successful authentications will be authorized at the "Basic" or "User" account levels (role) by default depending on the market. To elevate permissions to a higher permission level for Instructors or Administrators you will need to add Role Mappings to grant this elevation either by Attribute Value or Individual UserID. For more information on Account Level Permissions, please see the following article:
https://swankmp.zendesk.com/hc/en-us/articles/5723258435092-Cloud-Streaming-User-Account-Roles
There are 3 methods of providing roles and are respected in the following order - with the former values overriding any latter options.
- Mapping Roles on the Streaming Portal
- Claim/Attribute of "role" directly provided by your Identity Provider
- The Portal Default "User" or "Basic" role (Set by your Swank support)
Option 1: Mapping Roles on the Streaming Portal (Recommended)
To use this option,
- Log in to your streaming portal with an Admin account.
- Select Users from the menu
- Select the expand menu for the intended user and select Edit Profile
- Select the appropriate Role and click Save
Option 2: Identity Provider Role Assignment
In some cases, your Identity Provider can provide a Claim or Attribute for each User with the Name of "role" and the Value of one of our available user roles: "Admin", "Instructor", "User", or "Basic". This allows your Identity Provider Admin to set the roles based on policies and rules aligned with your organizations larger technology access strategy and to manage that access centrally at your User Directory.
Each Identity Provider has a different method for handling this action, please consult your identity provider to confirm the availability and documentation.
Note: You can verify you have the "Role" attribute provided by checking your diagnostics while logged in under the desired SSO setup. Log into your Portal's catalog, appending /diagnostics to the URL: (e.g.: https://digitalcampus.swankmp.net/[your site ID]/diagnostics or https://streaming.swankmp.net/[your site ID]/diagnostics)
Option 3: Portal Default Role
All successful authentications will be authorized at the "Basic" or "User" account levels (role) by default depending on the market.
Final Step
Make Configuration Active
Once you configured your SAML Identity Provider, and determined your User's roles, remember to click the Activate toggle on the SSO Configuration page for your chosen Provider(s). If you are currently viewing the SSO Configuration detail page, you can click the "Go Back" link at the top of the page or click SSO Configuration from the side menu.
- Toggle Active to the On position for your new SSO Configuration.
-

Comments
0 comments
Article is closed for comments.