> ## Documentation Index
> Fetch the complete documentation index at: https://translations.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

> セットアップ、トラブルシューティング、ログへのアクセス、次のステップを含む、SharePoint 2010/2013 との統合方法。

# SharePoint 2010/2013 との統合

Auth0 を使用すると、SharePoint の認証プロセスを大幅に簡素化できます。このチュートリアルでは、Auth0 を使用して SharePoint に <Tooltip tip="シングルサインオン（SSO）: ユーザーが1つのアプリケーションにログインすると、他のアプリケーションにも自動的にログインできるようになるサービス。" cta="用語集を表示" href="/ja/docs/glossary?term=Single+Sign-on">シングルサインオン</Tooltip> (SSO) を追加する方法を学びます。ユーザーは、[ソーシャルIDプロバイダー](/ja/docs/authenticate/identity-providers/social-identity-providers) (Facebook、X、Github など) 、[エンタープライズプロバイダー](/ja/docs/authenticate/identity-providers/enterprise-identity-providers) (LDAP、Active Directory、ADFS など) 、またはユーザー名とパスワードを使用してログインできるようになります。

<Callout icon="file-lines" color="#0EA5E9" iconType="regular">
  Auth0 は、SharePoint 2010 / 2013 向けの Auth0Claims Provider のサポートを終了しました。このパッケージは既存のテナントでは非推奨であり、新しいテナントでは利用できません。
</Callout>

<div id="setup">
  ## 設定
</div>

<div id="step-1-adding-the-integration-to-your-account">
  ### ステップ 1. アカウントに統合を追加する
</div>

まず、Dashboard の [SSO Integrations](https://manage.auth0.com/#/externalapps/create) セクションに移動し、アプリ一覧から **SharePoint** を選択します。

<div id="step-2-follow-the-live-documentation">
  ### ステップ 2. Live Documentation に従ってください
</div>

<Callout icon="file-lines" color="#0EA5E9" iconType="regular">
  SharePoint サーバーがインターネットにアクセスできない場合は、インストール ファイルを手動でダウンロードしてください。([オフライン インストールの詳細](https://github.com/auth0/auth0-sharepoint/tree/master/auth0-authentication-provider))。
</Callout>

**Settings** タブでは、SharePoint Web Application の URL と外部 URL (通常は Alternate Access Mappings のインターネット エンドポイント) を入力する必要があります。

Live Documentation では、まず SharePoint 用の Auth0 CmdLets をインストールします。

<Frame>
  <img src="https://mintcdn.com/translations/raZlN0BXDjNonwyb/docs/images/cdy7uua7fh8z/10GyFjDBJS0PoXITPeh30v/4304616303b13441c0b306be2291271f/sharepoint-cmdlets-installation.png?fit=max&auto=format&n=raZlN0BXDjNonwyb&q=85&s=36b671f888eb26527c7d7d51216f0c39" alt="SharePoint Management Shell - cmdlets installation" width="1087" height="211" data-path="docs/images/cdy7uua7fh8z/10GyFjDBJS0PoXITPeh30v/4304616303b13441c0b306be2291271f/sharepoint-cmdlets-installation.png" />
</Frame>

これらをインストールすると、各 Web Application で Auth0 と Claims Provider を有効化または無効化できるようになります。まず、Auth0 による認証を有効にする必要があります。

<Frame>
  <img src="https://mintcdn.com/translations/mMSz-RNYLuOm2GmQ/docs/images/cdy7uua7fh8z/e3WetoxFwzfQ2uo7Rhum4/f53189f6fd8247ba2f472dbc10abe5dc/sharepoint-auth-installation.png?fit=max&auto=format&n=mMSz-RNYLuOm2GmQ&q=85&s=f11fe7ff1f5cd8a06c6c95d792b49ff5" alt="SharePoint Management Shell - Auth0 install - Enable Authentication" width="1087" height="799" data-path="docs/images/cdy7uua7fh8z/e3WetoxFwzfQ2uo7Rhum4/f53189f6fd8247ba2f472dbc10abe5dc/sharepoint-auth-installation.png" />
</Frame>

次に、People Picker とアクセス許可が正しく機能するよう、Claims Provider をインストールします。

<Frame>
  <img src="https://mintcdn.com/translations/Dcx0M11uuptU53TX/docs/images/cdy7uua7fh8z/2WYY6vJdeRqFZUS9LfgzK5/5b35393140b7c818fc811afd0ddc3220/sharepoint-cp-installation.png?fit=max&auto=format&n=Dcx0M11uuptU53TX&q=85&s=e16c74ac225c67f32c139992cd766a5e" alt="SharePoint Management Shell - install claims provider" width="1087" height="267" data-path="docs/images/cdy7uua7fh8z/2WYY6vJdeRqFZUS9LfgzK5/5b35393140b7c818fc811afd0ddc3220/sharepoint-cp-installation.png" />
</Frame>

これらのスクリプトを実行したら、Central Administration で構成を完了します。

<Frame>
  <img src="https://mintcdn.com/translations/3nS3prIggmJG9TUI/docs/images/cdy7uua7fh8z/3VgxRGBz9YNbFaJP7Sgz8T/64673af31849333bf370c3f46b9687f1/sharepoint-central-admin.png?fit=max&auto=format&n=3nS3prIggmJG9TUI&q=85&s=f0d05baab84896a31bb0c30ce55ad828" alt="SharePoint central admin - complete configuration" width="750" height="514" data-path="docs/images/cdy7uua7fh8z/3VgxRGBz9YNbFaJP7Sgz8T/64673af31849333bf370c3f46b9687f1/sharepoint-central-admin.png" />
</Frame>

`Enable-Auth0` の呼び出しは、次のように調整できることに注意してください。

* ユーザーの一意の識別子 (メールアドレスやユーザー id など) を変更する
* 追加のクレームを SharePoint に渡せるようにする
* 既定の Windows 認証を有効または無効にする

次の例では、Role クレームもクレーム マッピングに追加し、Windows 認証を許可しています。

```powershell lines theme={null}
Enable-Auth0
  -auth0Domain:"fabrikam.auth0.com"
  -clientId:"bOFty3tWgpijnwMcltysNFqHgO1ziz1I"
  -webAppUrl:"http://fabrikam-sp/"
  -identifierClaimType:"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress"
  -claims:@(
    "Email|http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress",
    "Role|http://schemas.microsoft.com/ws/2008/06/identity/claims/role", "Client ID|http://schemas.auth0.com/clientID",
    "Given Name|http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname",
    "Surname|http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname", "Picture|http://schemas.auth0.com/picture")
  -allowWindowsAuth
```

<div id="step-3-you-now-have-sharepoint-configured">
  ### ステップ 3. SharePoint の設定が完了しました
</div>

これで、SharePoint は Auth0 を SSO ブローカーとして使用するよう設定されました。ユーザーがサイトにアクセスすると、そのアプリケーションで有効になっているすべての接続が表示されたログインページが表示されます。

Claims Provider のインストール時にマッピングしたクレームに応じて、以下の追加情報もユーザーの個人設定ページで利用できるようになります。

<Frame>
  <img src="https://mintcdn.com/translations/c0RQ9V0YAcT0-8l5/docs/images/cdy7uua7fh8z/7h2QeT1ama9IqZ2kDr4KT/5f689e49311471736c74a3eb5468c390/sharepoint-user-info.png?fit=max&auto=format&n=c0RQ9V0YAcT0-8l5&q=85&s=bca6a76d308429305796e17e2df29d2f" alt="SharePoint - ユーザー情報" width="750" height="533" data-path="docs/images/cdy7uua7fh8z/7h2QeT1ama9IqZ2kDr4KT/5f689e49311471736c74a3eb5468c390/sharepoint-user-info.png" />
</Frame>

<Frame>
  <img src="https://mintcdn.com/translations/3nS3prIggmJG9TUI/docs/images/cdy7uua7fh8z/3VgxRGBz9YNbFaJP7Sgz8T/64673af31849333bf370c3f46b9687f1/sharepoint-central-admin.png?fit=max&auto=format&n=3nS3prIggmJG9TUI&q=85&s=f0d05baab84896a31bb0c30ce55ad828" alt="SharePoint central admin - 完全な構成" width="750" height="514" data-path="docs/images/cdy7uua7fh8z/3VgxRGBz9YNbFaJP7Sgz8T/64673af31849333bf370c3f46b9687f1/sharepoint-central-admin.png" />
</Frame>

`Enable-Auth0` の呼び出しは、次のように調整できます。

* ユーザーの一意識別子を変更する (メールアドレスやユーザー id など)
* 追加のクレームを SharePoint に渡せるようにする
* 既定の Windows 認証 を有効または無効にする

この例では、クレームのマッピングに Role クレームも追加し、Windows 認証 も許可しています。

```powershell lines theme={null}
Enable-Auth0
  -auth0Domain:"fabrikam.auth0.com"
  -clientId:"bOFty3tWgpijnwMcltysNFqHgO1ziz1I"
  -webAppUrl:"http://fabrikam-sp/"
  -identifierClaimType:"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress"
  -claims:@(
    "Email|http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress",
    "Role|http://schemas.microsoft.com/ws/2008/06/identity/claims/role", "Client ID|http://schemas.auth0.com/clientID",
    "Given Name|http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname",
    "Surname|http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname", "Picture|http://schemas.auth0.com/picture")
  -allowWindowsAuth
```

SharePoint は今後、SSO ブローカーとして Auth0 を使用するようになります。

<div id="customizing-the-login-page">
  ## ログインページのカスタマイズ
</div>

[Auth0 Universal Login](/ja/docs/authenticate/login/auth0-universal-login) の手順に従って、ログインページをカスタマイズできます。

Auth0 を経由せずに、ユーザーが Windows 認証を使って SharePoint で認証できるようにしたい場合があります。その場合は、ログインページをカスタマイズして、Windows 認証エンドポイントへのリンク (通常は `https://yoursharepointserver/_windows/default.aspx?ReturnUrl=/_layouts/15/Authenticate.aspx` のような URL) を追加します。

その方法の 1 つは、jQuery を使用して Lock ウィジェットをカスタマイズし、Windows 認証エンドポイントへのリンクを追加することです。

カスタマイズしたログインページの `<body>` セクションの先頭に、jQuery の参照を追加する必要があります。

```html wrap lines theme={null}
<script src="https://code.jquery.com/jquery-3.3.1.slim.min.js"></script>
```

`lock.show()` を呼び出す前に、リンクを追加するための HTML DOM の変更コードを追加します。

```javascript lines expandable theme={null}
// Lockを構築する
// var lock = ...
[...]
// Windows認証ボタンを表示したいSharePointのクライアントIDを1つ以上指定する
var sharepointClientIDs = ['your_sharepoint_client_id'];

if (sharepointClientIDs.indexOf(config.clientID) >= 0) {
  lock.on('signin ready', function() { 
    var getParameterByName = function(name) {
      name = name.replace(/[\[]/, "\\\[").replace(/[\]]/, "\\\]");
      var regexS = "[\\?&]" + name + "=([^&#]*)";
      var regex = new RegExp(regexS);
      var results = regex.exec(window.location.search);
      if (results == null) return null;
      else return results[1];
    };
    // コールバックURLからホストを取得する
    var parser = document.createElement('a');
    parser.href = config.callbackURL;
    var host = parser.host;
    var windowsAuthURL = "https://" + host + "/_windows/default.aspx?ReturnUrl=/_layouts/15/Authenticate.aspx";
    var wctx = getParameterByName("wctx");
    if (wctx) {
      windowsAuthURL += "&Source=" + wctx;
    }

    $('.auth0-lock-tabs-container') 
    .after('<div><p class="auth0-lock-alternative" style="padding:5px 0;">' + 
      '<a class="auth0-lock-alternative-link" ' + 
      'href="'+ windowsAuthURL + '">' +
      'Login with Windows Authentication!!!</a>' + 
      '</p><p><span>or</span></p></div>').attr('href','https://nowhere');
  });
}

lock.show();
```

<div id="troubleshooting">
  ## トラブルシューティング
</div>

追加のクレームや認可を扱う際は、現在のユーザーのクレームを確認すると役立つことがあります。Microsoft の専門家 [Liam Clearly](https://helloitsliam.com/) による記事 [Claims Viewer Web Part](https://sharepointobservations.wordpress.com/2013/08/21/sharepoint-2013-and-adfs-2-0-test-with-claims-viewer-web-part/) を使用すると、ユーザーのクレームに関する問題をトラブルシューティングできます。

<div id="logs-in-sp2010">
  ### SP2010 のログ
</div>

エラーと警告は SharePoint の Unified Logging Service に記録されます。Claims Provider の使用時に発生する問題をトラブルシューティングするには、ULS Viewer などのツールを使用できます。

ULS Viewer の詳細と入手方法については、Microsoft のドキュメント [ULS Viewer](https://www.microsoft.com/en-us/download/details.aspx?id=44020) を参照してください。

<div id="logs-in-sp2013">
  ### SP2013 のログ
</div>

SharePoint 2013 では、ログに Unified Logging Service は使用されなくなり、代わりに Event Tracing for Windows を使用しています。これにより、パフォーマンスが向上し、記録されたすべてのイベントを取得する方法も複数利用できます。

ログをリアルタイムで表示するには、GitHub から Auth0 の [Logs Processor](https://github.com/auth0/auth0-sharepoint/releases) をダウンロードできます。このツールを SharePoint Server 上で実行すると、SharePoint が Claims Provider に対して行うすべての呼び出しを確認できます。

<div id="next-steps">
  ## 次のステップ
</div>

<div id="authorization">
  ### 認可
</div>

Auth0 から渡される クレーム は、SharePoint での認可にも利用できます。たとえば、Role claim に **Fabrikam HR** が含まれているユーザーには、特定のサイトへのアクセス権を付与したり、そのサイトの共同作成者にしたりできます。

Azure AD を例に見てみましょう。この Cloud Directory では、ユーザーはグループに所属でき、David は Fabrikam HR に所属しています。

David が Azure AD アカウントでログインすると (その接続で Security Groups 属性が有効になっている場合) 、グループ メンバーシップはユーザーのユーザープロファイルの `groups` 属性に格納されます。

これらのグループを SharePoint で Roles として利用できるようにするには、これを <Tooltip tip="Security Assertion Markup Language (SAML): パスワードなしで 2 つの当事者が認証情報を交換できるようにする標準化されたプロトコル。" cta="用語集を見る" href="/ja/docs/glossary?term=SAML">SAML</Tooltip> 設定に追加する [Rule](https://manage.auth0.com/#/rules) を作成する必要があります。この Rule は、**Fabrikam Intranet (SharePoint)** という名前のアプリケーションに対してのみ実行されます。

```javascript lines theme={null}
function (user, context, callback) {
  if (context.clientName === 'Fabrikam Intranet (SharePoint)') {
    context.samlConfiguration.mappings = {
        'http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier': 'user_id',
        'http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress': 'email',
        'http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name': 'name',
        'http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname': 'given_name',
        'http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname': 'family_name',
        'http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn': 'upn',
        'http://schemas.microsoft.com/ws/2008/06/identity/claims/role': 'groups'
    };
  }

  callback(null, user, context);
}
```

これにより、`groups` を含む追加の送信クレーム `http://schemas.microsoft.com/ws/2008/06/identity/claims/role` が追加され、SharePoint はこれを認可に使用します。

Claims Provider をインストールする際は、Role クレームが SharePoint に渡されるよう、クレーム mapping list に追加する必要があります。

```powershell lines theme={null}
Enable-Auth0
  -auth0Domain:"fabrikam.auth0.com"
  ...
  -claims:@(
    "Email|http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress",
    "Role|http://schemas.microsoft.com/ws/2008/06/identity/claims/role",
    ...)
  ...
  -Verbose
```

既定では、ユーザーはサイトにアクセスできません。

ここで、特定のユーザーを SharePoint Group (例: Contributors) に追加する代わりに、**Role** を SharePoint Group に追加できるようになりました。以下は、"Fabrikam HR" のメンバーを Contributors グループに追加する方法を示す PowerShell スクリプトの例です。

```powershell lines theme={null}
$webName = "http://fabrikam-sp"
$groupName = "Contributors"
$roleClaim = "Fabrikam HR"

$sts = Get-SPTrustedIdentityTokenIssuer "Auth0"
$claimPrincipal = New-SPClaimsPrincipal -ClaimValue $roleClaim -ClaimType "http://schemas.microsoft.com/ws/2008/06/identity/claims/role" -TrustedIdentityTokenIssuer $sts

$web = Get-SPWeb $webName
$user = New-SPUser -UserAlias $claimPrincipal.ToEncodedString() -Web $web

$group = $web.SiteGroups[$groupName]
$group.AddUser($user)
```

このクレーム値を Contributors グループに追加すると、David はサイトにアクセスして内容を編集できるようになります。

<div id="user-profile-synchronization">
  ### ユーザープロファイルの同期
</div>

既定では、SharePoint は Active Directory 由来のユーザープロファイル情報を同期できます。現在は、Auth0 の導入により、ユーザーがさまざまな種類の接続 (ソーシャルからエンタープライズまで) 経由で来る可能性があるため、ユーザープロファイルの同期には別のアプローチが必要になります。

1 つ目のアプローチとしては、数時間おきに実行されるタイマー ジョブを作成し、Auth0 Users Endpoint を照会して、対象ユーザーのユーザープロファイル情報を同期する方法があります。

```csharp lines expandable theme={null}
using System;

using Microsoft.SharePoint;
using Microsoft.SharePoint.Administration;

using Microsoft.Office.Server;
using Microsoft.Office.Server.UserProfiles;

namespace UserProfileSync
{
    class Program
    {
        static void Main(string[] args)
        {
            // Auth0 Management API を呼び出す - https://docs.auth0.com/api/v2

            using (var site = new SPSite("http://servername"))
            {
                var context = SPServiceContext.GetContext(site);
                var profileManager = new UserProfileManager(context);

                var accountName = "i:05.t|auth0|john@example.org";
                var userProfile = profileManager.GetUserProfile(accountName);
                userProfile[PropertyConstants.HomePhone].Value = "+1 594 9392";
                userProfile.Commit();
            }
        }
    }
}
```

別の方法として、このロジックはユーザーがログインするたびに実行される HttpModule として実装することもできます：

```csharp lines theme={null}
public class PersistUserClaimsHttpModule : IHttpModule
{
    private SPFederationAuthenticationModule FederationModule
    {
        get { return HttpContext.Current.ApplicationInstance.Modules["FederatedAuthentication"] as SPFederationAuthenticationModule; }   
    }

    public void Init(HttpApplication context)
    {
        FederationModule.SecurityTokenValidated += OnFederationSecurityTokenValidated;
    }

    private void OnFederationSecurityTokenValidated(object sender, SecurityTokenValidatedEventArgs e)
    {
        // e.ClaimsPrincipal を使用する
    }
}
```
