Azure Active Directory (ingliz tilidagi interfeys) sozlash
Yandex 360 xizmatlariga Azure Active Directory orqali yagona kirishni (SSO) tashkil etish uchun oldindan SAML ilovasini yaratish va sozlash kerak.
1-qadam. SAML ilovasini yarating va sozlang
- 
Azure Active Directory boshqaruv markaziga kiring. 
- 
Azure Active Directory bo‘limida panelning chap tomonidagi Enterprise applications varag‘iga o‘ting. 
- 
SAML ilovasini yarating: - 
New application tugmasini bosing. 
- 
Browse Azure AD Gallery sahifasida Create your own application tugmasini bosing. 
- 
Ochilgan oynaning o‘ng qismida ilova nomini kiriting, masalan, yandexsso.
- 
Ilova variantini tanlang: Integrate any other application you don't find in the gallery (Non-gallery). 
- 
Create tugmasini bosing. 
 Enterprise applications sahifasida All applications ro‘yxatida yaratilgan ilova qo‘shiladi. 
- 
- 
Ro‘yxatda ilovangizni tanlang. Agar yagona kirishdan (SSO) foydalana oladigan foydalanuvchilarni maxsus tayinlashni xohlamasangiz, Properties varag‘ida Assign Required parametri uchun No qiymatini tanlang. Sozlamalarni saqlash uchun varaq yuqorisidagi Save tugmasini bosing. Yagona kirishdan (SSO) foydalanish uchun alohida foydalanuvchilarni tayinlash uchun Properties varag‘ida Assign Required parametri uchun Yes qiymatini tanlang. Keyin Foydalanuvchilar va guruhlar varag‘iga o‘ting, Foydalanuvchi yoki guruh qo‘shish tugmasini bosing va kerakli foydalanuvchilarni kiriting. 
- 
Single sign-on varag‘iga kiring va SAML yagona kirish usulini tanlang. 
- 
Set up Single Sign-On with SAML oynasida Basic SAML Configuration bo‘limida Edit tugmasini bosing va parametrlarni o‘rnating: - 
Identifier (Entity ID): https://yandex.ru/(albatta oxirida qiyshiq chiziq bilan).
- 
Reply URL (Assertion Consumer Service URL): https://passport.yandex.ru/auth/sso/commit.
- 
Sign on URL (majburiy bo‘lmagan parametr): https://passport.yandex.ru/auth/sso/commit.
- 
Agar xodimlaringiz xizmatlardan faqat rus tilida foydalanmasa, Reply URL (Assertion Consumer Service URL) va Sign on URL maydonlarida qo‘shimcha ravishda boshqa til domenlarining URL manzillarini kiriting. Masalan: - 
https://passport.yandex.com/auth/sso/commit— ingliz tili uchun;https://passport.yandex.kz/auth/sso/commit— qozoq tili uchun;https://passport.yandex.uz/auth/sso/commit— o‘zbek tili uchun;https://passport.yandex.com.tr/auth/sso/commit— turk tili uchun.
 To‘liq ro‘yxat- 
https://passport.yandex.com/auth/sso/commithttps://passport.yandex.az/auth/sso/commithttps://passport.yandex.by/auth/sso/commithttps://passport.yandex.co.il/auth/sso/commithttps://passport.yandex.com/auth/sso/commithttps://passport.yandex.com.am/auth/sso/commithttps://passport.yandex.com.ge/auth/sso/commithttps://passport.yandex.com.tr/auth/sso/commithttps://passport.yandex.ee/auth/sso/commithttps://passport.yandex.eu/auth/sso/commithttps://passport.yandex.fi/auth/sso/commithttps://passport.yandex.fr/auth/sso/commithttps://passport.yandex.kg/auth/sso/commithttps://passport.yandex.kz/auth/sso/commithttps://passport.yandex.lt/auth/sso/commithttps://passport.yandex.lv/auth/sso/commithttps://passport.yandex.md/auth/sso/commithttps://passport.yandex.pl/auth/sso/commithttps://passport.yandex.ru/auth/sso/commithttps://passport.yandex.tj/auth/sso/commithttps://passport.yandex.tm/auth/sso/commithttps://passport.yandex.ua/auth/sso/commithttps://passport.yandex.uz/auth/sso/commit
 
- 
- 
Save tugmasini bosing. 
 
- 
2-qadam. Foydalanuvchi atributlarini taqqoslashni sozlang
- 
Foydalanuvchi atributlarini Azure Active Directory va Yandex 360 bilan sinxronlash uchun Enterprise applications → All applications → → SAML-based Sign-on rukniga kiring. 
- 
Attributes & Claims bo‘limida Unique User Identifier (Name ID) bandini tanlang. 
- 
Foydalanuvchining ismi va familiyasi Yandex 360 platformasida bexato ko‘rsatilishi uchun Required claim sozlamalar guruhining Source attribute maydoniga user.mailkiriting, keyin esa Save tugmasini bosing.
- 
Additional claims sozlamalar guruhida mavjud da’volarni o‘zgartiring yoki ularni o‘chirib tashlang va qaytadan yarating: Claim name Value User.EmailAddress user.mail User.Firstname user.givenname User.Surname user.surname SAML so‘rov namunasi: <Attribute Name="User.EmailAddress"> <AttributeValue>email@test.com</AttributeValue> </Attribute> <Attribute Name="User.Surname"> <AttributeValue>Surname</AttributeValue> </Attribute> <Attribute Name="User.Firstname"> <AttributeValue>Firstname</AttributeValue> </Attribute>
3-qadam. Sertifikatni saqlab oling
- 
Enterprise applications → All applications → → SAML-based Sign-on rukniga kiring. 
- 
SAML Signing Certificate bo‘limida Certificate (Base64) parametri yonida Download tugmasini bosing. Faylni qattiq diskka saqlab oling. 
 .cerkengaytmali saqlangan faylni istalgan matn muharririda ochish mumkin.
4-qadam. Yandex 360 platformasiga uzatilishi kerak bo‘lgan ma’lumotlarni to‘plang
Keyinchalik Yandex 360 platformasida sozlash uchun sizga 3-bosqichda olingan sertifikat va konfiguratsiya parametrlarining qiymatlari kerak bo‘ladi:
- 
Login URL 
- 
Azure AD Identifier 
Parametr qiymatini saqlash uchun:
- 
Enterprise applications → All applications → → SAML-based Sign-on → Set up bo‘limiga o‘ting. 
- 
Istalgan qulay joyga Login URL va Azure AD Identifier maydonlari qiymatini nusxalang. 
Bundan keyin Biznes uchun Yandex 360 sozlashga o‘ting.
Sozlama bilan aloqador muammolarni hal qilish
Agar sertifikat provayderini sozlash jarayonida noto‘g‘ri qiymatlar berilgan bo‘lsa, SSO orqali kirishga uringaningizda “Avtorizatsiya muvaffaqiyatsiz” xabarini va xato kodini ko‘rasiz:
email.no_in_response
- User.Firstname,- User.Surname,- User.EmailAddressformatida atribut nomlari kiriting. Agar boshqa format, masalan,- Ismberilsa, avtorizatsiya qilinmaydi.
request_your_admin
- Tashkilotingiz foydalanuvchilari katalogi administratori hisob uchun Yandex 360 platformasiga kirishni cheklagan bo‘lsa, xatolik yuz beradi. Batafsil ma’lumot olish uchun tashkilotingizning texnik yordam mutaxassislariga murojaat qiling.
samlresponse.invalid
- Agar kirish sahifasi URL, guvohnomalar emitenti yoki tekshiruv sertifikati noto‘g‘ri ko‘rsatilgan bo‘lsa, xatolik yuz beradi. Shuningdek, u tekshiruv sertifikatining amal qilish muddati tugashidan oldin yoki uning amal qilish muddati tugagandan keyin 14 kun ichida yuzaga kelishi mumkin. Biznes uchun Yandex 360 SSO sozlamalari to‘g‘riligini tekshiring.
unsupportable_domain
- User.EmailAddresspochta atributidagi domen SAML javobidagi asosiy domen yoki Yandex 360 tashkilotining alias domenlaridan biri bilan bir xil ekanligini tekshiring. Agar ular mos kelmasa, xato haqida xabar ko‘rasiz.