diff --git a/samples/features/security/azure-active-directory-auth/readme.md b/samples/features/security/azure-active-directory-auth/readme.md index 72d2a3ee..993af7cc 100644 --- a/samples/features/security/azure-active-directory-auth/readme.md +++ b/samples/features/security/azure-active-directory-auth/readme.md @@ -1,100 +1,79 @@ -# Token Authentication sample for Azure Active Directory +# Sample name ### Contents [About this sample](#about-this-sample)
+[Before you begin](#before-you-begin)
[Run this sample](#run-this-sample)
[Sample details](#sample-details)
+[Disclaimers](#disclaimers)
+[Related links](#related-links)
+ + +## About this sample + + +- **Applies to:** Azure SQL Database, Azure SQL Data Warehouse +- **Key features:** Azure Active Directory Authentication +- **Programming Language:** C# +- **Authors:** Mirek Sztajno [mireks-msft] ## About this sample -The Token project contains a simple console application that connects to Azure SQL database using a self-signed certificate. + + +## Before you begin + +To run this sample, you need the following prerequisites: **Software prerequisites:** +1. Visual Studio 2015 (or higher) with the latest SSDT installed (using .Net Framework 4.6 or higher) + + .Net Framework 4.6 must be set as the target framework for the Visual Studio project. To do this, double-click on Properties in Solution Explorer, then click the Application tab and check that the Target framework is set to .Net Framework 4.6 + + To install .Net Framework 4.6, see https://msdn.microsoft.com/library/5a4x27ek.aspx +2. Active Directory Authentication Library for SQL Server (ADALSQL.DLL) + + ADALSQL.DLL enables applications to authenticate to Microsoft Azure SQL Database using Azure Active Directory. The ADALSQL.DLL is not installed with Visual Studio so download the DLL at http://www.microsoft.com/en-us/download/details.aspx?id=48742 + + ADALSQL.DLL is automatically downloaded with Visual Studio 2015 Update 2, SQL Server Management Studio, and the newest version of SQL Server Data tools -1. The `makecert.exe` utility, which is included in the Windows SDK - + It is sometimes included in Visual Studio installations (depending on the selections made during installation). A search of your machine for `makecert.exe` would provide verification that the Windows SDK was installed. - + If the Windows SDK was not installed, you may [download it here](http://msdn.microsoft.com/en-US/windows/desktop/aa904949) - + You can learn more about the `makecert.exe` [utility here](https://msdn.microsoft.com/library/windows/desktop/aa386968.aspx) -2. PowerShell with Azure Active Directory Module - + To download the latest PowerShell version [see this page](https://azure.microsoft.com/en-us/documentation/articles/powershell-install-configure/#Install) - + [Install the Azure AD PowerShell Module](https://msdn.microsoft.com/en-us/library/azure/jj151815.aspx), if it is not already installed in your client machine. +1. Create Azure Active Directory (AD), or federate your domain with existing Azure AD + This allows either to use managed or federated accounts associated with a specific Azure AD +2. Create Azure AD administrator for Azure SQL DB using Azure portal, PowerShell command or Rest API +3. With help from T-SQL query interface (i.e. SSMS query editor), using Azure AD admin credentials for SQL DB & SQL DW, create an Azure AD user in a designated database. The database user represents your Azure AD principal (or one of the groups you belong to) and must exist in the database having CONNECT permission prior to executing a connection attempt + **Other Prerequisites** -TODO: Other Prerequisites +1. For Azure AD integrated authentication a computer joined to a domain that is federated with Azure Active Directory is required +2. An existing database created before a connection attempt is required. The database can be created using credentials for SQL administrator, or Azure AD SQL administrator + ## Run this sample -1. Create an application account in Azure AD for your service. - - Sign in to the Azure management portal. - - Click on Azure Active Directory in the left hand navigation - - Click the directory tenant where you wish to register the sample application. This must be the same directory that is associated with your database (the server hosting your database). - - Click the Applications tab - - In the drawer, click Add. - - Click "Add an application my organization is developing". - - Enter mytokentest as a friendly name for the application, select "Web Application and/or Web API", and click next. - - Assuming this application is a daemon/service and not a web application, it doesn't have a sign-in URL or app ID URI. For these two fields, enter http://mytokentest - - While still in the Azure portal, click the Configure tab of your application. - - Find the Client ID value and copy it into a text editor, you will need this later when configuring your application ( i.e. a4bbfe26-dbaa-4fec-8ef5-223d229f647d /see the snapshot below/) -![active directory portal Client ID image](img/azure-active-directory-application-portal.png) + -2. Logon to your Azure SQL Server’s user database as an Azure AD admin and using a T-SQL command provision a contained database user for your application principal: - ```sql - CREATE USER [mytokentest] FROM EXTERNAL PROVIDER - ``` - - [See this link](https://azure.microsoft.com/en-us/documentation/articles/sql-database-aad-authentication/) for more details on how to create an Azure Ad admin and a contained database user. +[Integrated Demo](integrated) -3. On the machine you are going to run the project on, generate and install a self-signed certificate. - - To complete this step, you will need to use `Makecert.exe` - - Open a command prompt window - - Navigate to a folder where you want to generate a certificate file ( such as the folder where the demo files are) and change the following command for your environment - ``` - \makecert.exe -r -pe -n "CN=Cert_name" -ss My -len 2048 Cert_name.cer - ``` - for example, like so: - ``` - c:/"Program Files (x86)/Windows Kits/8.1/bin/x64"/makecert -r -pe -n "CN=mytokentestCert" -ss My -len 2048 mytokentestCert.cer - ``` -4. Add the certificate as a key for the application you created in Azure AD. - - Click the Microsoft Azure Active Directory Module for Windows PowerShell shortcut on desktop to open a Windows PowerShell workspace that has the Azure AD cmdlets. - - Copy the following code snippet to a text editor. - ``` - connect-msolservice - - $cer = New-Object System.Security.Cryptography.X509Certificates.X509Certificate - $cer.Import("\Cert_name.cer") - $binCert = $cer.GetRawCertData() - $credValue = [System.Convert]::ToBase64String($binCert); - New-MsolServicePrincipalCredential -AppPrincipalId "" -Type asymmetric -Value $credValue -Usage verify - ``` - + Replace with the path to your certificate and Cert_name with your Certificate name that you used in step 3 above. - + Replace with the client ID you copied in step 1. - + Copy and paste your snippet into the powershell window and run it. - - The following command will verify that you added the certificate to your application's Active Directory Registration - ``` Get-MsolServicePrincipalCredential –ServicePrincipalName "URL"-ReturnKeyValues 0 ``` +[Password Demo](password) -5. Configure the certificate and your application account in the *app.config* file in the project. - + In Visual Studio, open *app.config* in the Solution Explorer - ![App.config file highlights](img/app-config-key-value-example.png) - - Find the app key `ida:Tenant` and replace the value with your AAD tenant name (your AAD domain) - - Find the app key `ida:ClientID` and replace the value with the Client ID for the application registration from the Azure Portal (the value from step 1). - - Find the app key `ida:Cert_Name` and replace the value with the subject name (CN) of the self-signed certificate you created - - For example: - ```csharp - //this is the AAD domain - //this is the Client ID - //this is the Cert_name use by makecert.exe - ``` - + In Visual Studio, open *Program.cs* in the Solution Explorer - ![Program.cs field highlights](img/program-cs-builder-highlight.png) - - Make the following changes: - ```csharp - builder["Data Source"] = "aad-managed-demo.database.windows.net"; // replace with your server name - builder["Initial Catalog"] = "demo"; // replace with your database name - ``` -6. Run the demo. (Click *Run* or press *F5*) - + A successful authorization should result in a message that states "Connected to the database" similar to the following: - ![succesful auth](token-press-any-key-to-stop.png) + + +## Sample details + +This demo provides a simple tool for exploring Azure Active Directory authentication to Azure SQL DB or Azure SQL DW. + +Azure Active Directory authentication with Azure SQL Database V12 supports the following authentication methods: +- User/password authentication +- Integrated authentication +- Application token authentication [Demo coming soon!] + + + +## Disclaimers +The code included in this sample is only intended to provide a method to demonstrate sucessful authentication to Azure SQL Database or Azure SQL Data Warehouse via Azure Active Directory authentication methods. + + +## Related Links + + +