This section describes how to add Azure AD information on TMWS to connect TMWS with the Azure AD
service for user authentication and synchronization.
Procedure
- Log on to the TMWS management console, and go to .
- Click here on the upper area of the screen.
- On the Authentication Method screen that appears, click Azure AD.
- Click On or Off to decide whether
to allow the AD users of your organization to visit websites through TMWS if their data is
not synchronized to TMWS.
Note
Users not synchronized from Azure AD can be authenticated only through known TMWS gateways or the dedicated port for your organization. - Configure Identity Provider Settings as follows:Service URLLogin URL on the Azure AD admin portalLogon name attributeUser claim name corresponding to the user.onpremisessamaccountname claim value on the Azure AD admin portalTMWS provides a pre-defined value sAMAccountName for this field. You can use this value or specify a different one. Trend Micro recommends keeping the pre-defined value. If you use a different value, make sure that the values here and in Azure AD are identical.Public SSL certificateCertificate (Base64) downloaded from the Azure AD admin portal
- Configure Synchronization Settings as follows:TenantDirectory (tenant) ID or Custom domain name on the Azure AD admin portalApplication IDApplication (client) ID on the Azure AD admin portalClient secret valueValue on the Client secrets screen on the Azure AD admin portalSynchronization scheduleSelect to synchronize with Azure AD manually or according to a schedule. If you choose Manually, whenever there are changes to Active Directory user information, remember to go back to the Directory Services screen and perform manual synchronization so that information in TMWS remains current.
Note
If you choose a schedule, the time to start automatic synchronization depends on the finish time of last synchronization. For example, for a daily schedule, the next synchronization would take place about 24 hours after the last synchronization is completed. - Click Test Connection to check whether the Azure AD service can be connected successfully.
- Click Save.
What to do next
To ensure successful user authentication between your Azure AD and TMWS, if you have
configured in Azure AD to use another authentication server, add the host where the
authentication server resides to either the proxy exception list of your browser or
to the skiphost list in the PAC files in use.