Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Incorrect 8x8 configuration instructions #8409

Closed
tmaeller opened this issue May 10, 2018 — with docs.microsoft.com · 24 comments
Closed

Incorrect 8x8 configuration instructions #8409

tmaeller opened this issue May 10, 2018 — with docs.microsoft.com · 24 comments

Comments

Copy link

The following step in this tutorial directs the user to apply the wrong URL in their 8x8 SSO configuration:

  1. Copy SAML SSO URL, Single Sing Out Service URL and Issuer URL from Azure AD to Sign In URL, Sign Out URL and Issuer URL in 8x8 Virtual Office

Here's 8x8's KB article regarding the 8x8 side of this config:

https://support.8x8.com/us/products/virtual-office-integrations/how-do-i-configure-microsoft-azure-ad-8x8-virtual-office

This is correct, confirmed by an SSO engineer at 8x8.
"Enter https://sso.8x8.com/saml2 in the Identifier field and the Reply URL field."

This applies to both Account Manager and Configuration Manager platforms.

If you have any questions, please let me know.

Tony Maeller
8x8 Tier2 Integrations SME


Document Details

Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.

@MohitGargMSFT
Copy link
Member

@tmaeller Thanks for your feedback! We will investigate and update as appropriate.

@v-nagta
Copy link
Contributor

v-nagta commented May 11, 2018

@tmaeller In the current tutorial we have multiple Identifier and Reply URL patterns.

capture

Now you are saying to replace these URL values with the https://sso.8x8.com/saml2 value.
Identifier and Reply URL values fixed for all customers?

Copy link
Author

I'm not sure where the above URLs came from, and I don't know about the configuration on the Azure side of things, but according to our engineers, https://sso.8x8.com/saml2 is the correct Identifier and Reply URL for 8x8 Configuration Manager (the new platform) and Account Manager (the old one).

If you need anything else from me, just let me know.

~Tony

@v-nagta
Copy link
Contributor

v-nagta commented May 14, 2018

@tmaeller The existing identifier and Reply URL patterns were given to us by your team only at the time off initial testing and on boarding of the application to the gallery. we just want to conform that if we change the values to what you are saying now, are there any existing customers may get impact due to this change because after this change the old URL patterns will not be acceptable in Azure AD

@jeevansd
Copy link
Contributor

@v-nagta and @tmaeller correction here. Customer can use the old or new URL in the app although we update this. I think it is the question of right guidance here. can you please confirm that these are the correct new URLs and accordingly we will provide the same guidance in the UI and also in the documentation. Also there is no impact on the existing customers and connections which are already done.

@tmaeller
Copy link
Author

tmaeller commented May 15, 2018 via email

@jeevansd
Copy link
Contributor

jeevansd commented Aug 9, 2018

@chetansriv Can you please do the follow up?

@chetansriv
Copy link
Contributor

@tmaeller Hi Tony - Have you got the response from engineering team?

Copy link
Author

Hi Chetan, we are going to try cornering our SSO engineer again tomorrow. She had already confirmed that https://sso.8x8.com/saml2 is the correct URL, but I want to make absolutely sure before anyone changes anything.

Copy link
Author

tmaeller commented Sep 5, 2018

Hi folks, just letting you know (finally):

  1. I've confirmed with two SSO engineers here at 8x8 that the Identifier and Reply URLs in step 3 must both be entered as https://sso.8x8.com/saml2

  2. I have enough access to our test Azure account to see that Azure is either much different on our account, or more likely that the interface has changed significantly since this doc was published. You might want to look into that.

  3. We have a new-ish service platform called Configuration Manager which also will eventually replace Account Manager (which this doc was written for). It also supports SSO, and while the config is basically the same, the configuration steps are different.

If you have any questions, let me know.
Thanks,
~Tony

@jeevansd
Copy link
Contributor

jeevansd commented Sep 5, 2018

@chetansriv can you please make these changes in the doc?

@chetansriv
Copy link
Contributor

@tmaeller Thanks for the confirmation. We are working on first two points however not very sure about the third point. As per my understanding, we have two apps in gallery - Virtual Office and Account Manager and this tutorial talks about configuring Virtual office. So, I am assuming that if you have new platform which is replacing Account Manager, we may need another tutorial for the same. Also, does it need the gallery app to be refreshed with any required change? Please let me know if my understanding is not right.
cc: @jeevansd

@jeevansd
Copy link
Contributor

jeevansd commented Sep 6, 2018

@tmaeller Please note that 8x8 Account Manager is the Password SSO app in our gallery where as 8x8 Virtual Office is the federated SAML app. So do you want us to merge both of them in one or do you want us to enable the federation in the Account Manager app also? I am not sure about the action here.

cc: @chetansriv

@tmaeller
Copy link
Author

tmaeller commented Sep 7, 2018

@jeevansd @chetansriv I can see both apps available in Azure / Enterprise applications, but the link "Read how to configure password single sign-on apps" provided there for configuring the Account Manager app points to a general Azure SSO config page.

The Virtual Office configuration is specifically for users of VOD to log in, and the other (which I wasn't aware of) would be used to log in to Account Manager (of course).

So honestly I'm not sure that I can answer that question.

@jeevansd
Copy link
Contributor

jeevansd commented Sep 7, 2018

@tmaeller Yes, for Password SSO apps there is no app specific documentation but there is a common documentation available for them.

The Virtual Office is SAML integration and this is why we have tutorial for it. Can you confirm that Account Manager also support SAML integration? Same or different?

@tmaeller
Copy link
Author

It should.

http://www.get8x8.com/8x8WebHelp/8x8Account_Manager/Default.htm#2SetupPhoneSystem/SSO.htm

SAML and Google Federated Single Sign-On
Customers with identity management systems like Okta, OneLogin, Ping Identity, and Microsoft ADFS require their employees to authenticate to 8x8 apps using their company ID instead of an 8x8 username and password. In this release, we support SAML 2.0 & Google OAuth Federated Single Sign-On (SSO) for the following 8x8 applications that use the shared 8x8 login page:

  • Account Manager
  • Virtual Contact Center
  • Virtual Office desktop app
  • Virtual Office online app
  • Virtual Office mobile app
  • Virtual Office Analytics
  • Switchboard Pro

With support for Federated SSO, users can log in to 8x8 applications through their company's identity management system.

@chetansriv
Copy link
Contributor

@tmaeller before making any change, I would like to get on a call with you so that we discuss and ensure that right guidance is provided in the tutorial. Please provide your work email and preferred timing if this works for you and I'll send an invite.

@jeevansd
Copy link
Contributor

@tmaeller Please send the email to SaaSApplicationIntegrations@service.microsoft.com and then we can talk in details.

Copy link
Author

@chetansriv @jeevansd This document as is will work for Account Manager if you change the URLs in step 3. I know that you want to make sure the documentation is correct, but I've already confirmed with the SSO engineers here. If you have more specific questions, let me know and I'll bring them into this. I need something concrete to give them, as they're always extremely busy.

@jeevansd
Copy link
Contributor

@tmaeller What is the change you are expecting in step 3 here? Can you please provide the details?

@chetansriv
Copy link
Contributor

@tmaeller Can you please confirm on above

@tmaeller
Copy link
Author

@chetansriv @jeevansd
This is the only change that would need to be made. The URLs supplied in your guide are not correct.


Configuring and testing Azure AD single sign-on

  1. In the 8x8 Virtual Office Domain and URLs section, add https://sso.8x8.com/saml2 to the Identifier and Reply URL fields.

image

@chetansriv
Copy link
Contributor

@tmaeller Tutorial updated

#please-close

@BryanTrach-MSFT
Copy link
Member

@tmaeller We will now proceed to close this thread. If there are further questions regarding this matter, please tag me in your reply. We will gladly continue the discussion and we will reopen the issue.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

7 participants