Set Up Single Sign-On for Vantagepoint with Microsoft Azure Active Directory
Microsoft Azure Active Directory’s single sign-on (SSO) feature enables users to log on to Vantagepoint using their Windows usernames and passwords, instead of using separate Vantagepoint usernames and passwords.
Vantagepoint supports the single-tenant and multi-tenant options for registering an application within the Azure portal. This includes invited users from another tenant or domain. Application registrations using personal Microsoft accounts (for example, Skype or Xbox) are not supported.
Alternative Approach
The most common single sign-on model used by Vantagepoint customers is to synchronize users and passwords to Windows Azure Active Directory.
An alternative method is to set up Windows Azure Active Directory to federate back to your local Active Directory via ADFS (Active Directory Federation Services), to authenticate users via your on-premises Active Directory. With this model, you do not need to synchronize users and passwords to Windows Azure Active Directory.
Important Information to Know
Periodically, Microsoft may change the behavior and the management of settings in the Microsoft Azure portal. Deltek strives to maintain accuracy in documenting the steps for configuring the Deltek applications that use the Azure Portal. Sometimes, the changes made in the portal may occur prior to the respective updates in the Deltek documentation. If this occurs, please contact a Deltek Customer Care Rep to ensure that you have the updated steps.
On-Premises Deployments
The steps to configure Vantagepoint with SSO for on-premise deployments are the same as Vantagepoint hosted in the deltekfirst.com cloud with one difference: the Vantagepoint launch page URL (https://<FQDN>/vantagepoint) will be used in place of the customer URL that is specified in the reply URL settings (https://abcengineers.deltekfirst.com/abcengineers).
For example, if your Vantagepoint server is named webserver1 in your applebartlett.com domain, then your customer URL per the instructions would be https://webserver1.applebartlett.com/vantagepoint.
- Related Topics:
- Support for Multi-Factor Authentication
Windows Azure Active Directory supports multi-factor authentication. - Configure Single Sign-On using Azure AD
To set up single sign-on, a Vantagepoint administrator must complete some configuration steps. - Sign Up for a Microsoft Azure AD Account
If your firm does not already have a Microsoft Azure AD account, you can sign up for a free account. - Configure Azure AD Connect
The first step in configuring single sign-on is to configure Azure AD Connect. - Add and Configure Vantagepoint Applications in Windows Azure Active Directory
You must add and configure two applications for Vantagepoint in Azure AD: Vantagepoint and Vantagepoint (Client). - Add and Configure the Vantagepoint Application
You must add and configure the Vantagepoint application in Azure AD. - Set Up Trust Between the Vantagepoint and Vantagepoint Client Applications
You must set up trust between the Vantagepoint application and the Vantagepoint client application. - Add and Configure the Vantagepoint Client Application
You must add and configure the Vantagepoint Client application in Azure AD. - Complete Trust Between the Vantagepoint and Vantagepoint Client Applications
You must perform some final steps to set up trust between the Vantagepoint application and the Vantagepoint client application. - Complete Azure AD Configuration in Vantagepoint
After you complete single sign-on configuration in Azure AD, you must complete configuration steps in Vantagepoint. - Complete User Configuration in Vantagepoint
When you set up users and passwords in Vantagepoint, you must also configure any user who will use single sign-on (SSO). - Log In Using Windows Authentication
After the Vantagepoint Administrator sets up single sign-on, each user must follow a set of login steps to enable Windows Authentication.