|
| 1 | +--- |
| 2 | +title: 'Tutorial: Azure Active Directory integration with Cerner Central | Microsoft Docs' |
| 3 | +description: Learn how to configure single sign-on between Azure Active Directory and Cerner Central. |
| 4 | +services: active-directory |
| 5 | +documentationCenter: na |
| 6 | +author: jeevansd |
| 7 | +manager: femila |
| 8 | + |
| 9 | +ms.assetid: d2bc549d-d286-4679-854e-bb67c62b0475 |
| 10 | +ms.service: active-directory |
| 11 | +ms.workload: identity |
| 12 | +ms.tgt_pltfrm: na |
| 13 | +ms.devlang: na |
| 14 | +ms.topic: article |
| 15 | +ms.date: 04/14/2017 |
| 16 | +ms.author: jeedes |
| 17 | + |
| 18 | +--- |
| 19 | +# Tutorial: Azure Active Directory integration with Cerner Central |
| 20 | + |
| 21 | +In this tutorial, you learn how to integrate Cerner Central with Azure Active Directory (Azure AD). |
| 22 | + |
| 23 | +Integrating Cerner Central with Azure AD provides you with the following benefits: |
| 24 | + |
| 25 | +- You can control in Azure AD who has access to Cerner Central |
| 26 | +- You can enable your users to automatically get signed-on to Cerner Central (Single Sign-On) with their Azure AD accounts |
| 27 | +- You can manage your accounts in one central location - the Azure portal |
| 28 | + |
| 29 | +If you want to know more details about SaaS app integration with Azure AD, see [what is application access and single sign-on with Azure Active Directory](active-directory-appssoaccess-whatis.md). |
| 30 | + |
| 31 | +## Prerequisites |
| 32 | + |
| 33 | +To configure Azure AD integration with Cerner Central, you need the following items: |
| 34 | + |
| 35 | +- An Azure AD subscription |
| 36 | +- A Cerner Central single-sign on enabled subscription |
| 37 | + |
| 38 | +> [!NOTE] |
| 39 | +> To test the steps in this tutorial, we do not recommend using a production environment. |
| 40 | +
|
| 41 | +To test the steps in this tutorial, you should follow these recommendations: |
| 42 | + |
| 43 | +- Do not use your production environment, unless it is necessary. |
| 44 | +- If you don't have an Azure AD trial environment, you can get a one-month trial [here](https://azure.microsoft.com/pricing/free-trial/). |
| 45 | + |
| 46 | +## Scenario description |
| 47 | +In this tutorial, you test Azure AD single sign-on in a test environment. |
| 48 | +The scenario outlined in this tutorial consists of two main building blocks: |
| 49 | + |
| 50 | +1. Adding Cerner Central from the gallery |
| 51 | +2. Configuring and testing Azure AD single sign-on |
| 52 | + |
| 53 | +## Adding Cerner Central from the gallery |
| 54 | +To configure the integration of Cerner Central into Azure AD, you need to add Cerner Central from the gallery to your list of managed SaaS apps. |
| 55 | + |
| 56 | +**To add Cerner Central from the gallery, perform the following steps:** |
| 57 | + |
| 58 | +1. In the **[Azure portal](https://portal.azure.com)**, on the left navigation panel, click **Azure Active Directory** icon. |
| 59 | + |
| 60 | + ![Active Directory][1] |
| 61 | + |
| 62 | +2. Navigate to **Enterprise applications**. Then go to **All applications**. |
| 63 | + |
| 64 | + ![Applications][2] |
| 65 | + |
| 66 | +3. To add new application, click **New application** button on top of the dialog. |
| 67 | + |
| 68 | + ![Applications][3] |
| 69 | + |
| 70 | +4. In the search box, type **Cerner Central**. |
| 71 | + |
| 72 | +  |
| 73 | + |
| 74 | +5. In the results panel, select **Cerner Central**, and then click **Add** button to add the application. |
| 75 | + |
| 76 | +  |
| 77 | + |
| 78 | +## Configuring and testing Azure AD single sign-on |
| 79 | +In this section, you configure and test Azure AD single sign-on with Cerner Central based on a test user called "Britta Simon." |
| 80 | + |
| 81 | +For single sign-on to work, Azure AD needs to know what the counterpart user in Cerner Central is to a user in Azure AD. In other words, a link relationship between an Azure AD user and the related user in Cerner Central needs to be established. |
| 82 | + |
| 83 | +To configure and test Azure AD single sign-on with Cerner Central, you need to complete the following building blocks: |
| 84 | + |
| 85 | +1. **[Configuring Azure AD Single Sign-On](#configuring-azure-ad-single-sign-on)** - to enable your users to use this feature. |
| 86 | +2. **[Creating an Azure AD test user](#creating-an-azure-ad-test-user)** - to test Azure AD single sign-on with Britta Simon. |
| 87 | +3. **[Creating a Cerner Central test user](#creating-a-cerner-central-test-user)** - to have a counterpart of Britta Simon in Cerner Central that is linked to the Azure AD representation of the user. |
| 88 | +4. **[Assigning the Azure AD test user](#assigning-the-azure-ad-test-user)** - to enable Britta Simon to use Azure AD single sign-on. |
| 89 | +5. **[Testing Single Sign-On](#testing-single-sign-on)** - to verify whether the configuration works. |
| 90 | + |
| 91 | +### Configuring Azure AD single sign-on |
| 92 | + |
| 93 | +In this section, you enable Azure AD single sign-on in the Azure portal and configure single sign-on in your Cerner Central application. |
| 94 | + |
| 95 | +**To configure Azure AD single sign-on with Cerner Central, perform the following steps:** |
| 96 | + |
| 97 | +1. In the Azure portal, on the **Cerner Central** application integration page, click **Single sign-on**. |
| 98 | + |
| 99 | + ![Configure Single Sign-On][4] |
| 100 | + |
| 101 | +2. On the **Single sign-on** dialog, select **Mode** as **SAML-based Sign-on** to enable single sign-on. |
| 102 | + |
| 103 | +  |
| 104 | + |
| 105 | +3. On the **Cerner Central Domain and URLs** section, perform the following steps: |
| 106 | + |
| 107 | +  |
| 108 | + |
| 109 | + a. In the **Identifier** textbox, type the value using the following pattern: `https://<instancename>.cernercentral.com/session-api/protocol/saml2/metadata` |
| 110 | + |
| 111 | + b. In the **Reply URL** textbox, type a URL using the following pattern: `https://<instancename>.cernercentral.com/session-api/protocol/saml2/sso` |
| 112 | + |
| 113 | + > [!NOTE] |
| 114 | + > These values are not the real. Update these values with the actual Identifier and reply URL. Here we suggest you to use the unique value of string in the Identifier. Contact [Cerner Central support team](https://www.cerner.com/support) to get these values. |
| 115 | + |
| 116 | +5. Click **Save** button. |
| 117 | + |
| 118 | +  |
| 119 | + |
| 120 | +6. To generate the **Metadata** url, perform the following steps: |
| 121 | + |
| 122 | + a. Click **App registrations**. |
| 123 | + |
| 124 | +  |
| 125 | + |
| 126 | + b. Click **Endpoints** to open **Endpoints** dialog box. |
| 127 | + |
| 128 | +  |
| 129 | + |
| 130 | + c. Click the copy button to copy **FEDERATION METADATA DOCUMENT** url and paste it into notepad. |
| 131 | + |
| 132 | +  |
| 133 | + |
| 134 | + d. Now go to the property page of **Cerner Central** and copy the **Application Id** using **Copy** button and paste it into notepad. |
| 135 | + |
| 136 | +  |
| 137 | + |
| 138 | + e. Generate the **Metadata URL** using the following pattern: `<FEDERATION METADATA DOCUMENT url>?appid=<application id>` |
| 139 | + |
| 140 | +7. To configure single sign-on on **Cerner Central** side, you need to send the **Metadata URL** to [Cerner Central support](https://www.cerner.com/support). They configure the SSO on application side to complete the integration. |
| 141 | + |
| 142 | +> [!TIP] |
| 143 | +> You can now read a concise version of these instructions inside the [Azure portal](https://portal.azure.com), while you are setting up the app! After adding this app from the **Active Directory > Enterprise Applications** section, simply click the **Single Sign-On** tab and access the embedded documentation through the **Configuration** section at the bottom. You can read more about the embedded documentation feature here: [Azure AD embedded documentation]( https://go.microsoft.com/fwlink/?linkid=845985) |
| 144 | +> |
| 145 | +
|
| 146 | +### Creating an Azure AD test user |
| 147 | +The objective of this section is to create a test user in the Azure portal called Britta Simon. |
| 148 | + |
| 149 | +![Create Azure AD User][100] |
| 150 | + |
| 151 | +**To create a test user in Azure AD, perform the following steps:** |
| 152 | + |
| 153 | +1. In the **Azure portal**, on the left navigation pane, click **Azure Active Directory** icon. |
| 154 | + |
| 155 | +  |
| 156 | + |
| 157 | +2. To display the list of users, go to **Users and groups** and click **All users**. |
| 158 | + |
| 159 | +  |
| 160 | + |
| 161 | +3. To open the **User** dialog, click **Add**. |
| 162 | + |
| 163 | +  |
| 164 | + |
| 165 | +4. On the **User** dialog page, perform the following steps: |
| 166 | + |
| 167 | +  |
| 168 | + |
| 169 | + a. In the **Name** textbox, type **BrittaSimon**. |
| 170 | + |
| 171 | + b. In the **User name** textbox, type the **email address** of Britta Simon. |
| 172 | + |
| 173 | + c. Select **Show Password** and write down the value of the **Password**. |
| 174 | + |
| 175 | + d. Click **Create**. |
| 176 | + |
| 177 | +### Creating a Cerner Central test user |
| 178 | + |
| 179 | +In order to enable Azure AD users to log in to Cerner Central, they must be provisioned into Cerner Central. There are many ways to create users in Cerner Central application. To manually create the user in Cerner Central application please work with the [Cerner Central support](https://www.cerner.com/support) team. |
| 180 | + |
| 181 | +### Assigning the Azure AD test user |
| 182 | + |
| 183 | +In this section, you enable Britta Simon to use Azure single sign-on by granting access to Cerner Central. |
| 184 | + |
| 185 | +![Assign User][200] |
| 186 | + |
| 187 | +**To assign Britta Simon to Cerner Central, perform the following steps:** |
| 188 | + |
| 189 | +1. In the Azure portal, open the applications view, and then navigate to the directory view and go to **Enterprise applications** then click **All applications**. |
| 190 | + |
| 191 | + ![Assign User][201] |
| 192 | + |
| 193 | +2. In the applications list, select **Cerner Central**. |
| 194 | + |
| 195 | +  |
| 196 | + |
| 197 | +3. In the menu on the left, click **Users and groups**. |
| 198 | + |
| 199 | + ![Assign User][202] |
| 200 | + |
| 201 | +4. Click **Add** button. Then select **Users and groups** on **Add Assignment** dialog. |
| 202 | + |
| 203 | + ![Assign User][203] |
| 204 | + |
| 205 | +5. On **Users and groups** dialog, select **Britta Simon** in the Users list. |
| 206 | + |
| 207 | +6. Click **Select** button on **Users and groups** dialog. |
| 208 | + |
| 209 | +7. Click **Assign** button on **Add Assignment** dialog. |
| 210 | + |
| 211 | +### Testing single sign-on |
| 212 | + |
| 213 | +In this section, you test your Azure AD single sign-on configuration using the Access Panel. |
| 214 | + |
| 215 | +When you click the Cerner Central tile in the Access Panel, you should get automatically signed-on to your Cerner Central application. For more information about the Access Panel, see [Introduction to the Access Panel](https://msdn.microsoft.com/library/dn308586). |
| 216 | + |
| 217 | +## Additional resources |
| 218 | + |
| 219 | +* [List of Tutorials on How to Integrate SaaS Apps with Azure Active Directory](active-directory-saas-tutorial-list.md) |
| 220 | +* [What is application access and single sign-on with Azure Active Directory?](active-directory-appssoaccess-whatis.md) |
| 221 | + |
| 222 | + |
| 223 | + |
| 224 | +<!--Image references--> |
| 225 | + |
| 226 | +[1]: ./media/active-directory-saas-cernercentral-tutorial/tutorial_general_01.png |
| 227 | +[2]: ./media/active-directory-saas-cernercentral-tutorial/tutorial_general_02.png |
| 228 | +[3]: ./media/active-directory-saas-cernercentral-tutorial/tutorial_general_03.png |
| 229 | +[4]: ./media/active-directory-saas-cernercentral-tutorial/tutorial_general_04.png |
| 230 | + |
| 231 | +[100]: ./media/active-directory-saas-cernercentral-tutorial/tutorial_general_100.png |
| 232 | + |
| 233 | +[200]: ./media/active-directory-saas-cernercentral-tutorial/tutorial_general_200.png |
| 234 | +[201]: ./media/active-directory-saas-cernercentral-tutorial/tutorial_general_201.png |
| 235 | +[202]: ./media/active-directory-saas-cernercentral-tutorial/tutorial_general_202.png |
| 236 | +[203]: ./media/active-directory-saas-cernercentral-tutorial/tutorial_general_203.png |
| 237 | + |
0 commit comments