Skip to content

Commit 5d36f71

Browse files
authored
Merge pull request #114610 from BobbySchmidt2/goodpractice-toolkit-tutorial
Edit pass: Goodpractice toolkit tutorial
2 parents f3e620e + a33470d commit 5d36f71

File tree

1 file changed

+67
-71
lines changed

1 file changed

+67
-71
lines changed

articles/active-directory/saas-apps/goodpractice-toolkit-tutorial.md

Lines changed: 67 additions & 71 deletions
Original file line numberDiff line numberDiff line change
@@ -21,142 +21,138 @@ ms.collection: M365-identity-device-management
2121
# Tutorial: Azure Active Directory integration with Mind Tools Toolkit
2222

2323
In this tutorial, you learn how to integrate Mind Tools Toolkit with Azure Active Directory (Azure AD).
24-
Integrating Mind Tools Toolkit with Azure AD provides you with the following benefits:
2524

26-
* You can control in Azure AD who has access to Mind Tools Toolkit.
27-
* You can enable your users to be automatically signed-in to Mind Tools Toolkit (Single Sign-On) with their Azure AD accounts.
28-
* You can manage your accounts in one central location - the Azure portal.
25+
With this integration, you can:
2926

30-
If you want to know more details about SaaS app integration with Azure AD, see [What is application access and single sign-on with Azure Active Directory](https://docs.microsoft.com/azure/active-directory/manage-apps/what-is-single-sign-on).
31-
If you don't have an Azure subscription, [create a free account](https://azure.microsoft.com/free/) before you begin.
27+
* Control in Azure AD who has access to Mind Tools Toolkit.
28+
* Enable your users to be automatically signed in to Mind Tools Toolkit (single sign-on) with their Azure AD accounts.
29+
* Manage your accounts in one central location: the Azure portal.
30+
31+
To learn more about software as a service (SaaS) app integration with Azure AD, see [What is application access and single sign-on with Azure Active Directory](https://docs.microsoft.com/azure/active-directory/manage-apps/what-is-single-sign-on).
3232

3333
## Prerequisites
3434

3535
To configure Azure AD integration with Mind Tools Toolkit, you need the following items:
3636

3737
* An Azure AD subscription. If you don't have a subscription, you can get a [free account](https://azure.microsoft.com/free/).
38-
* Mind Tools Toolkit single sign-on enabled subscription
38+
* A Mind Tools Toolkit subscription with single sign-on (SSO) enabled.
3939

4040
## Scenario description
4141

4242
In this tutorial, you configure and test Azure AD single sign-on in a test environment.
4343

44-
* Mind Tools Toolkit supports **SP** initiated SSO
45-
* Mind Tools Toolkit supports **Just In Time** user provisioning
46-
* Once you configure Mind Tools Toolkit you can enforce session control, which protect exfiltration and infiltration of your organizations sensitive data in real-time. Session control extend from Conditional Access. [Learn how to enforce session control with Microsoft Cloud App Security](https://docs.microsoft.com/cloud-app-security/proxy-deployment-any-app).
44+
* Mind Tools Toolkit supports SP-initiated SSO.
45+
* Mind Tools Toolkit supports just-in-time user provisioning.
46+
* After you configure Mind Tools Toolkit, you can enforce session control. This control protects exfiltration and infiltration of your organization's sensitive data in real time. Session control extends from conditional access. [Learn how to enforce session control with Microsoft Cloud App Security](https://docs.microsoft.com/cloud-app-security/proxy-deployment-any-app).
4747

48-
## Adding Mind Tools Toolkit from the gallery
48+
## Add Mind Tools Toolkit from the gallery
4949

5050
To configure the integration of Mind Tools Toolkit into Azure AD, you need to add Mind Tools Toolkit from the gallery to your list of managed SaaS apps.
5151

52-
1. Sign in to the [Azure portal](https://portal.azure.com) using either a work or school account, or a personal Microsoft account.
53-
1. On the left navigation pane, select the **Azure Active Directory** service.
54-
1. Navigate to **Enterprise Applications** and then select **All Applications**.
55-
1. To add new application, select **New application**.
56-
1. In the **Add from the gallery** section, type **Mind Tools Toolkit** in the search box.
57-
1. Select **Mind Tools Toolkit** from results panel and then add the app. Wait a few seconds while the app is added to your tenant.
52+
1. Sign in to the [Azure portal](https://portal.azure.com) by using either a work or school account, or a personal Microsoft account.
53+
1. On the leftmost navigation pane, select the **Azure Active Directory** service.
54+
1. Go to **Enterprise Applications**, and then select **All Applications**.
55+
1. To add a new application, select **New application**.
56+
1. In the **Add from the gallery** section, enter **Mind Tools Toolkit** in the search box.
57+
1. Select **Mind Tools Toolkit** from the search results, and then add the app. Wait a few seconds while the app is added to your tenant.
5858

5959
## Configure and test Azure AD single sign-on
6060

61-
In this section, you configure and test Azure AD single sign-on with Mind Tools Toolkit based on a test user called **B.Simon**.
62-
For single sign-on to work, a link relationship between an Azure AD user and the related user in Mind Tools Toolkit needs to be established.
61+
In this section, you configure and test Azure AD single sign-on with Mind Tools Toolkit by using a test user called **B.Simon**. For single sign-on to work, you must establish a linked relationship between an Azure AD user and the related user in Mind Tools Toolkit.
6362

64-
To configure and test Azure AD single sign-on with Mind Tools Toolkit, you need to complete the following building blocks:
63+
To configure and test Azure AD single sign-on with Mind Tools Toolkit, complete the following building blocks:
6564

66-
1. **[Configure Azure AD SSO](#configure-azure-ad-sso)** - to enable your users to use this feature.
67-
* **[Create an Azure AD test user](#create-an-azure-ad-test-user)** - to test Azure AD single sign-on with B.Simon.
68-
* **[Assign the Azure AD test user](#assign-the-azure-ad-test-user)** - to enable B.Simon to use Azure AD single sign-on.
69-
1. **[Configure Mind Tools Toolkit SSO](#configure-mind-tools-toolkit-sso)** - to configure the single sign-on settings on application side.
70-
* **[Create Mind Tools Toolkit test user](#create-mind-tools-toolkit-test-user)** - to have a counterpart of B.Simon in Mind Tools Toolkit that is linked to the Azure AD representation of user.
71-
1. **[Test SSO](#test-sso)** - to verify whether the configuration works.
65+
1. **[Configure Azure AD SSO](#configure-azure-ad-sso)** to enable your users to use this feature.
66+
1. **[Create an Azure AD test user](#create-an-azure-ad-test-user)** to test Azure AD single sign-on with B.Simon.
67+
1. **[Assign the Azure AD test user](#assign-the-azure-ad-test-user)** to enable B.Simon to use Azure AD single sign-on.
68+
1. **[Configure Mind Tools Toolkit SSO](#configure-mind-tools-toolkit-sso)** to configure the single sign-on settings on the application side.
69+
1. **[Create a Mind Tools Toolkit test user](#create-a-mind-tools-toolkit-test-user)** to have a counterpart of B.Simon in Mind Tools Toolkit. This counterpart is linked to the Azure AD representation of the user.
70+
1. **[Test SSO](#test-sso)** to verify whether the configuration works.
7271

7372
### Configure Azure AD SSO
7473

75-
In this section, you enable Azure AD single sign-on in the Azure portal.
76-
77-
To configure Azure AD single sign-on with Mind Tools Toolkit, perform the following steps:
74+
In this section, you configure Azure AD single sign-on with Mind Tools Toolkit by following these steps:
7875

7976
1. In the [Azure portal](https://portal.azure.com/), on the **Mind Tools Toolkit** application integration page, select **Single sign-on**.
8077

81-
![Configure single sign-on link](common/select-sso.png)
78+
![The Manage section, with Single sign-on highlighted](common/select-sso.png)
8279

83-
2. On the **Select a Single sign-on method** dialog, select **SAML/WS-Fed** mode to enable single sign-on.
80+
1. In the **Select a Single sign-on method** dialog box, select **SAML/WS-Fed** to enable single sign-on.
8481

85-
![Single sign-on select mode](common/select-saml-option.png)
82+
![The Select a single sign-on method dialog box, with SAML highlighted](common/select-saml-option.png)
8683

87-
3. On the **Set up Single Sign-On with SAML** page, click **Edit** icon to open **Basic SAML Configuration** dialog.
84+
1. On the **Set up Single Sign-On with SAML** page, select the pencil icon for **Basic SAML Configuration** to edit the settings.
8885

89-
![Edit Basic SAML Configuration](common/edit-urls.png)
86+
![The Set up Single Sign-On with SAML page, with the pencil icon for Basic SAML Configuration highlighted](common/edit-urls.png)
9087

91-
4. On the **Basic SAML Configuration** section, perform the following steps:
88+
1. In the **Basic SAML Configuration** section, in the **Sign-on URL** box, enter a URL having the pattern `https://app.goodpractice.net/#/<subscriptionUrl>/s/<locationId>`.
9289

93-
In the **Sign-on URL** text box, type a URL using the following pattern:
94-
`https://app.goodpractice.net/#/<subscriptionUrl>/s/<locationId>`.
90+
> [!NOTE]
91+
> The **Sign-on URL** value isn't real. Update the value with the actual sign-on URL. Contact the [Mind Tools Toolkit Client support team](mailto:support@goodpractice.com) to get the value.
9592
96-
> [!Note]
97-
> The Sign-on URL value is not real. Update the value with the actual Sign-On URL. Contact [Mind Tools Toolkit Client support team](mailto:[email protected]) to get the value.
93+
1. On the **Set-up Single Sign-On with SAML** page, go to the **SAML Signing Certificate** section. To the right of **Federation Metadata XML**, select **Download** to download the XML text and save it on your computer. The XML contents depend on the options you select.
9894

99-
5. On the **Set up Single Sign-On with SAML** page, in the **SAML Signing Certificate** section, click **Download** to download the **Federation Metadata XML** from the given options as per your requirement and save it on your computer.
95+
![The SAML Signing Certificate section, with Download highlighted next to Federation Metadata XML](common/metadataxml.png)
10096

101-
![The Certificate download link](common/metadataxml.png)
97+
1. In the **Set up Mind Tools Toolkit** section, copy whichever of the following URLs you need.
10298

103-
6. On the **Set up Mind Tools Toolkit** section, copy the appropriate URL(s) as per your requirement.
99+
* **Login URL**
104100

105-
![Copy configuration URLs](common/copy-configuration-urls.png)
101+
* **Azure AD Identifier**
106102

107-
a. Login URL
103+
* **Logout URL**
108104

109-
b. Azure AD Identifier
110-
111-
c. Logout URL
105+
![The Set up Mind Tools Toolkit section, with the configuration URLs highlighted](common/copy-configuration-urls.png)
112106

113107
### Create an Azure AD test user
114108

115-
In this section, you'll create a test user in the Azure portal called B.Simon.
109+
In this section, you create a test user called B.Simon in the Azure portal:
116110

117-
1. From the left pane in the Azure portal, select **Azure Active Directory**, select **Users**, and then select **All users**.
118-
1. Select **New user** at the top of the screen.
111+
1. On the leftmost side of the Azure portal, select **Azure Active Directory** > **Users** > **All users**.
112+
1. At the top of the screen, select **New user**.
119113
1. In the **User** properties, follow these steps:
120-
1. In the **Name** field, enter `B.Simon`.
121-
1. In the **User name** field, enter the [email protected]. For example, `[email protected]`.
122-
1. Select the **Show password** check box, and then write down the value that's displayed in the **Password** box.
123-
1. Click **Create**.
114+
1. In the **Name** field, enter **B.Simon**.
115+
1. In the **User name** field, enter **B.Simon@**_companydomain_**.**_extension_. For example, [email protected].
116+
1. Select the **Show password** check box, and then write down the value that's shown in the **Password** box.
117+
1. Select **Create**.
124118

125119
### Assign the Azure AD test user
126120

127-
In this section, you'll enable B.Simon to use Azure single sign-on by granting access to Mind Tools Toolkit.
121+
In this section, you enable B.Simon to use Azure single sign-on by granting access to Mind Tools Toolkit.
128122

129-
1. In the Azure portal, select **Enterprise Applications**, and then select **All applications**.
123+
1. In the Azure portal, select **Enterprise Applications** > **All applications**.
130124
1. In the applications list, select **Mind Tools Toolkit**.
131-
1. In the app's overview page, find the **Manage** section and select **Users and groups**.
125+
1. In the app's overview page, go to the **Manage** section, and select **Users and groups**.
132126

133-
![The "Users and groups" link](common/users-groups-blade.png)
127+
![The Manage section, with Users and groups highlighted](common/users-groups-blade.png)
134128

135-
1. Select **Add user**, then select **Users and groups** in the **Add Assignment** dialog.
129+
1. Select **Add user**. In the **Add Assignment** dialog box, select **Users and groups**.
136130

137-
![The Add User link](common/add-assign-user.png)
131+
![The Users and groups window, with Add user highlighted](common/add-assign-user.png)
138132

139-
1. In the **Users and groups** dialog, select **B.Simon** from the Users list, then click the **Select** button at the bottom of the screen.
140-
1. If you're expecting any role value in the SAML assertion, in the **Select Role** dialog, select the appropriate role for the user from the list and then click the **Select** button at the bottom of the screen.
141-
1. In the **Add Assignment** dialog, click the **Assign** button.
133+
1. In the **Users and groups** dialog box, select **B.Simon** from the users list. Then choose the **Select** button at the bottom of the screen.
134+
1. If you expect any role value in the SAML assertion, in the **Select Role** dialog box, select the appropriate role for the user from the list. Then choose the **Select** button at the bottom of the screen.
135+
1. In the **Add Assignment** dialog box, select **Assign**.
142136

143137
## Configure Mind Tools Toolkit SSO
144138

145-
To configure single sign-on on **Mind Tools Toolkit** side, you need to send the downloaded **Federation Metadata XML** and appropriate copied URLs from Azure portal to [Mind Tools Toolkit support team](mailto:[email protected]). They set this setting to have the SAML SSO connection set properly on both sides.
139+
To configure single sign-on on the **Mind Tools Toolkit** side, send the downloaded **Federation Metadata XML** text and the previously copied URLs to the [Mind Tools Toolkit support team](mailto:[email protected]). They configure this setting to have the SAML SSO connection set properly on both sides.
140+
141+
### Create a Mind Tools Toolkit test user
146142

147-
### Create Mind Tools Toolkit test user
143+
In this section, you create a user called B.Simon in Mind Tools Toolkit.
148144

149-
In this section, a user called B.Simon is created in Mind Tools Toolkit. Mind Tools Toolkit supports **just-in-time provisioning**, which is enabled by default. There is no action item for you in this section. If a user doesn't already exist in Mind Tools Toolkit, a new one is created when you attempt to access Mind Tools Toolkit.
145+
Mind Tools Toolkit supports just-in-time provisioning, which is enabled by default. There's no action for you to take in this section. If a user doesn't already exist in Mind Tools Toolkit, a new one is created when you attempt to access Mind Tools Toolkit.
150146

151147
### Test SSO
152148

153-
In this section, you test your Azure AD single sign-on configuration using the Access Panel.
149+
In this section, you test your Azure AD single sign-on configuration by using the My Apps portal.
154150

155-
When you click the Mind Tools Toolkit tile in the Access Panel, you should be automatically signed in to the Mind Tools Toolkit for which you set up SSO. For more information about the Access Panel, see [Introduction to the Access Panel](https://docs.microsoft.com/azure/active-directory/active-directory-saas-access-panel-introduction).
151+
When you select the Mind Tools Toolkit tile in the My Apps portal, you are automatically signed in to the Mind Tools Toolkit for which you set up SSO. For more information about the My Apps portal, see [Introduction to the My Apps portal](https://docs.microsoft.com/azure/active-directory/active-directory-saas-access-panel-introduction).
156152

157-
## Additional Resources
153+
## Additional resources
158154

159-
- [List of Tutorials on How to Integrate SaaS Apps with Azure Active Directory](https://docs.microsoft.com/azure/active-directory/active-directory-saas-tutorial-list)
155+
- [Tutorials for integrating SaaS apps with Azure Active Directory](https://docs.microsoft.com/azure/active-directory/active-directory-saas-tutorial-list)
160156

161157
- [What is application access and single sign-on with Azure Active Directory?](https://docs.microsoft.com/azure/active-directory/manage-apps/what-is-single-sign-on)
162158

@@ -166,4 +162,4 @@ When you click the Mind Tools Toolkit tile in the Access Panel, you should be au
166162

167163
- [What is session control in Microsoft Cloud App Security?](https://docs.microsoft.com/cloud-app-security/proxy-intro-aad)
168164

169-
- [How to protect Mind Tools Toolkit with advanced visibility and controls](https://docs.microsoft.com/cloud-app-security/proxy-intro-aad)
165+
- [How to protect Mind Tools Toolkit with advanced visibility and controls](https://docs.microsoft.com/cloud-app-security/proxy-intro-aad)

0 commit comments

Comments
 (0)