在 Azure Active Directory 中向应用程序分配用户Assign users to an application in Azure Active Directory

本文介绍如何将用户分配到 Azure Active Directory (Azure AD) 中的应用程序。This article shows you how to assign users to an application in Azure Active Directory (Azure AD). 首先必须将用户分配给应用程序,然后管理员才能授予这些用户访问权限以执行以下操作:Users must first be assigned to an application before an administrator can grant them access to do the following:

  • 通过直接导航到应用程序的 URL(也称为 SP 发起的登录)访问应用程序。Access an application by navigating to the application’s URL directly (also known as SP-initiated sign-on).

  • 通过使用应用程序的“属性” 页上的“用户访问 URL” (也称为 IDP 发起的登录)访问应用程序。Access an application by using the User Access URL on an application’s Properties page (also known as IDP-initiated sign on).

  • 查看显示在其 Office 365 应用程序启动器中的应用程序。See an application appear on their Office 365 Application Launcher.

先决条件Prerequisites

在将用户分配到应用程序之前,必须要求用户分配。Before you can assign users to an application, you must require user assignment. 若要要求用户分配,请执行以下操作:To require user assignment:

  1. 使用管理员帐户登录到 Azure 门户。Log in to the Azure portal with an administrator account.
  2. 在主菜单中单击“所有服务” 项。Click on the All services item in the main menu.
  3. 选择要用于应用程序的目录。Choose the directory you are using for the application.
  4. 单击“企业应用程序”选项卡 。Click on the Enterprise applications tab.
  5. 从与此目录关联的应用程序列表中选择应用程序。Select the application from the list of applications associated with this directory.
  6. 单击“属性” 选项卡。Click the Properties tab.
  7. 将“需要进行用户分配?”切换为“是” 。Change the User assignment required? toggle to Yes.
  8. 单击屏幕顶部的“保存” 按钮。Click the Save button at the top of the screen.

分配用户Assign users

要直接将一个或多个用户分配到应用程序,请按照以下步骤操作:To assign one or more users to an application directly, follow the steps below:

  1. 打开 Azure 门户,并以“全局管理员” 身份登录。Open the Azure portal and sign in as a Global Administrator.

  2. 选择“Azure Active Directory” 。Select Azure Active Directory.

  3. 在 Azure Active Directory 的左侧导航菜单中,单击“企业应用程序” 。click Enterprise Applications from the Azure Active Directory left hand navigation menu.

  4. 单击“所有应用程序” ,查看所有应用程序的列表。click All Applications to view a list of all your applications.

    • 如果未看到要在此处显示的应用程序,请使用“所有应用程序列表” 顶部的“筛选器” 控件,并将“显示” 选项设置为“所有应用程序” 。If you do not see the application you want show up here, use the Filter control at the top of the All Applications List and set the Show option to All Applications.
  5. 从列表中选择要向其分配用户的应用程序。Select the application you want to assign a user to from the list.

  6. 在应用程序加载后,在应用程序的左侧导航菜单中单击“用户和组” 。Once the application loads, click Users and Groups from the application’s left hand navigation menu.

  7. 单击“用户和组” 列表顶部的“添加用户” 按钮,以打开“添加分配” 窗格。Click the Add user button on top of the Users and Groups list to open the Add Assignment pane.

  8. 在“添加分配” 窗格中,单击“用户” 选择器。click the Users selector from the Add Assignment pane.

  9. 在“按名称或电子邮件地址搜索” 搜索框中,键入要分配的用户的全名电子邮件地址Type in the full name or email address of the user you are interested in assigning into the Search by name or email address search box.

  10. 将鼠标悬停在列表中的“用户” 上方以显示“复选框” 。Hover over the user in the list to reveal a checkbox. 单击用户个人资料头像或徽标旁边的复选框,将用户添加到“已选择” 列表。Click the checkbox next to the user’s profile photo or logo to add your user to the Selected list.

  11. 可选: 如果要“添加多个用户”,请在“按名称或电子邮件地址搜索”搜索框中键入其他“全名”或“电子邮件地址”,然后单击复选框以将此用户添加到“已选择”列表 。Optional: If you would like to add more than one user, type in another full name or email address into the Search by name or email address search box, and click the checkbox to add this user to the Selected list.

  12. 在完成用户的选择后,单击“选择” 按钮将他们添加到要分配给应用程序的用户列表。When you are finished selecting users, click the Select button to add them to the list of users to be assigned to the application.

  13. 可选: 单击“添加分配” 窗格中的“选择角色” 选择器,选择一个角色来分配给所选用户。Optional: click the Select Role selector in the Add Assignment pane to select a role to assign to the users you have selected.

  14. 单击“分配” 按钮,将应用程序分配给选定用户。Click the Assign button to assign the application to the selected users.

经过一小段时间后,所选用户将能够使用解决方案描述部分中所述的方法启动这些应用程序。After a short period of time, the users you have selected will be able to launch these applications using the methods described in the solution description section.