Product DocsMenu

SharePoint Online (ADFS SSO) [Claims] Source Quick Setup

  1. Validate that your environment meets the requirements: 

  2. Create a user identity with a dedicated account that has access to all the SharePoint content that you want to index. [SharePoint] or [OneDrive for Business]

    Key parameter Value
    Name You must name your user identity.
    User A single sign-on Office 365 account in the username@domain.com form.
    Password The corresponding password.
  3. Ensure that the account of your user identity has the appropriate permissions:

    1. For content and permission indexing, incremental refresh, and site collection discovery, the account must have Administrator permission for all SharePoint Online site collections to index, but also the root site collection. [more]

    2. For personal site, user profile, and social tags indexing, the account must be owner of all personal sites collections. [more]

  4. Create a Claims for SharePoint Online security provider. [more]

    Key parameter Value
    Name You must name your security provider.
    Security Provider Type Claims for SharePoint Online
    User Identity When a claims-aware Coveo Search is used, select a user identity of any Windows account that can be used to authenticate to ADFS. Otherwise, select the user identity you just created. [more]
    SharePoint Web Application Url In the form https://domain.sharepoint.com
    Office 365 Native Users Domain(s) In the form domain.onmicrosoft.com[more]
    Allow Complex Identities Selected

    Notes: You can configure the security provider to operate:

    • When single sign-on is enabled in Office 365. [more]

    • When multiple ADFS servers are used to authenticate users in SharePoint. [more]

  5. Install the Windows Azure AD module on the Coveo Master server needed by the Office 365 security provider. [more]

  6. Create an Office 365 security provider. [more]

    Key parameter Value
    Name You must name your security provider.
    Security Provider Type Office 365
    User Identity The single sign-on Office 365 user identity you created.
    Users Security Provider The Claims for SharePoint Online security provider you just created.
    Windows Azure Active Directory Module for Windows PowerShell The installation path of the Microsoft Online Services Module for Windows PowerShell. [more]
  7. Create a SharePoint security provider. [more]

    Key parameter Value
    Name You must name your security provider.
    Security Provider Type SharePoint
    User Identity The single sign-on Office 365 user identity you created.
    Active Directory Security Provider (none)
    Security Provider for SharePoint Users The Claims for SharePoint Online security provider you just created.
    Security Provider for Domain Groups The Office 365 security provider you just created.
    SharePoint Server Url URL of the SharePoint Online site in the form https://domain.sharepoint.com/[path], where [path] is needed only when you want index a specific site collection, list, etc.
    AuthenticationType SpOnlineFederated
    AdfsServerUrl The URL of the ADFS server for which a trust is established with SharePoint.
    SharePointTrustIdentifier The Relying Party Trust identifier for the SharePoint web application, such as urn:federation:MicrosoftOnline. [more]

    Notes: You can configure the security provider to operate when multiple ADFS servers are used to authenticate users in SharePoint. [more]

  8. Create a SharePoint or OneDrive for Business source. [SharePoint] or [OneDrive for Business]

    Key parameter SharePoint OneDrive for Business
    Name You must name your source.  
    Source Type SharePoint (x64) OneDrive for Business
    Addresses The SharePoint Online server URL in the form https://domain.SharePoint.com. [more]

    The URL of the SharePoint Online site collection regrouping all the personal sites (in which are located the OneDrives for Business) that you want to index in the form https://domain-my.sharepoint.com. [more]

    Authentication Type SpOnlineFederated
    AdfsServerUrl
    (Hidden parameter)
    The URL of the ADFS server for which a trust is established with SharePoint.
    SharePointTrustIdentifier
    (Hidden parameter)
    The Relying Party Trust identifier for the SharePoint ADFS server. [more]
    Authentication The single sign-on Office 365 user identity you created.
    Security Provider The SharePoint security provider you just created.

    Notes: You can configure the source to operate when multiple ADFS servers are used to authenticate users in SharePoint. [SharePoint] or [OneDrive for Business]

  9. Rebuild the source and validate that documents are indexed.

People who viewed this topic also viewed