You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
# Tutorial: Azure Active Directory integration with Mind Tools Toolkit
22
22
23
23
In this tutorial, you learn how to integrate Mind Tools Toolkit with Azure Active Directory (Azure AD).
24
-
Integrating Mind Tools Toolkit with Azure AD provides you with the following benefits:
25
24
26
-
* You can control in Azure AD who has access to Mind Tools Toolkit.
27
-
* You can enable your users to be automatically signed-in to Mind Tools Toolkit (Single Sign-On) with their Azure AD accounts.
28
-
* You can manage your accounts in one central location - the Azure portal.
25
+
With this integration, you can:
29
26
30
-
If you want to know more details about SaaS app integration with Azure AD, see [What is application access and single sign-on with Azure Active Directory](https://docs.microsoft.com/azure/active-directory/manage-apps/what-is-single-sign-on).
31
-
If you don't have an Azure subscription, [create a free account](https://azure.microsoft.com/free/) before you begin.
27
+
* Control in Azure AD who has access to Mind Tools Toolkit.
28
+
* Enable your users to be automatically signed in to Mind Tools Toolkit (single sign-on) with their Azure AD accounts.
29
+
* Manage your accounts in one central location: the Azure portal.
30
+
31
+
To learn more about software as a service (SaaS) app integration with Azure AD, see [What is application access and single sign-on with Azure Active Directory](https://docs.microsoft.com/azure/active-directory/manage-apps/what-is-single-sign-on).
32
32
33
33
## Prerequisites
34
34
35
35
To configure Azure AD integration with Mind Tools Toolkit, you need the following items:
36
36
37
37
* An Azure AD subscription. If you don't have a subscription, you can get a [free account](https://azure.microsoft.com/free/).
38
-
* Mind Tools Toolkit single sign-on enabled subscription
38
+
*A Mind Tools Toolkit subscription with single sign-on (SSO) enabled.
39
39
40
40
## Scenario description
41
41
42
42
In this tutorial, you configure and test Azure AD single sign-on in a test environment.
43
43
44
-
* Mind Tools Toolkit supports **SP**initiated SSO
45
-
* Mind Tools Toolkit supports **Just In Time**user provisioning
46
-
*Once you configure Mind Tools Toolkit you can enforce session control, which protect exfiltration and infiltration of your organization’s sensitive data in real-time. Session control extend from Conditional Access. [Learn how to enforce session control with Microsoft Cloud App Security](https://docs.microsoft.com/cloud-app-security/proxy-deployment-any-app).
44
+
* Mind Tools Toolkit supports SP-initiated SSO.
45
+
* Mind Tools Toolkit supports just-in-time user provisioning.
46
+
*After you configure Mind Tools Toolkit, you can enforce session control. This control protects exfiltration and infiltration of your organization's sensitive data in realtime. Session control extends from conditional access. [Learn how to enforce session control with Microsoft Cloud App Security](https://docs.microsoft.com/cloud-app-security/proxy-deployment-any-app).
47
47
48
-
## Adding Mind Tools Toolkit from the gallery
48
+
## Add Mind Tools Toolkit from the gallery
49
49
50
50
To configure the integration of Mind Tools Toolkit into Azure AD, you need to add Mind Tools Toolkit from the gallery to your list of managed SaaS apps.
51
51
52
-
1. Sign in to the [Azure portal](https://portal.azure.com) using either a work or school account, or a personal Microsoft account.
53
-
1. On the left navigation pane, select the **Azure Active Directory** service.
54
-
1.Navigate to **Enterprise Applications** and then select **All Applications**.
55
-
1. To add new application, select **New application**.
56
-
1. In the **Add from the gallery** section, type**Mind Tools Toolkit** in the search box.
57
-
1. Select **Mind Tools Toolkit** from results panel and then add the app. Wait a few seconds while the app is added to your tenant.
52
+
1. Sign in to the [Azure portal](https://portal.azure.com)by using either a work or school account, or a personal Microsoft account.
53
+
1. On the leftmost navigation pane, select the **Azure Active Directory** service.
54
+
1.Go to **Enterprise Applications**, and then select **All Applications**.
55
+
1. To add a new application, select **New application**.
56
+
1. In the **Add from the gallery** section, enter**Mind Tools Toolkit** in the search box.
57
+
1. Select **Mind Tools Toolkit** from the search results, and then add the app. Wait a few seconds while the app is added to your tenant.
58
58
59
59
## Configure and test Azure AD single sign-on
60
60
61
-
In this section, you configure and test Azure AD single sign-on with Mind Tools Toolkit based on a test user called **B.Simon**.
62
-
For single sign-on to work, a link relationship between an Azure AD user and the related user in Mind Tools Toolkit needs to be established.
61
+
In this section, you configure and test Azure AD single sign-on with Mind Tools Toolkit by using a test user called **B.Simon**. For single sign-on to work, you must establish a linked relationship between an Azure AD user and the related user in Mind Tools Toolkit.
63
62
64
-
To configure and test Azure AD single sign-on with Mind Tools Toolkit, you need to complete the following building blocks:
63
+
To configure and test Azure AD single sign-on with Mind Tools Toolkit, complete the following building blocks:
65
64
66
-
1.**[Configure Azure AD SSO](#configure-azure-ad-sso)**- to enable your users to use this feature.
67
-
***[Create an Azure AD test user](#create-an-azure-ad-test-user)** - to test Azure AD single sign-on with B.Simon.
68
-
***[Assign the Azure AD test user](#assign-the-azure-ad-test-user)** - to enable B.Simon to use Azure AD single sign-on.
69
-
1.**[Configure Mind Tools Toolkit SSO](#configure-mind-tools-toolkit-sso)**- to configure the single sign-on settings on application side.
70
-
***[Create Mind Tools Toolkit test user](#create-mind-tools-toolkit-test-user)**- to have a counterpart of B.Simon in Mind Tools Toolkit that is linked to the Azure AD representation of user.
71
-
1.**[Test SSO](#test-sso)**- to verify whether the configuration works.
65
+
1.**[Configure Azure AD SSO](#configure-azure-ad-sso)** to enable your users to use this feature.
66
+
1.**[Create an Azure AD test user](#create-an-azure-ad-test-user)** to test Azure AD single sign-on with B.Simon.
67
+
1.**[Assign the Azure AD test user](#assign-the-azure-ad-test-user)** to enable B.Simon to use Azure AD single sign-on.
68
+
1.**[Configure Mind Tools Toolkit SSO](#configure-mind-tools-toolkit-sso)** to configure the single sign-on settings on the application side.
69
+
1.**[Create a Mind Tools Toolkit test user](#create-a-mind-tools-toolkit-test-user)** to have a counterpart of B.Simon in Mind Tools Toolkit. This counterpart is linked to the Azure AD representation of the user.
70
+
1.**[Test SSO](#test-sso)** to verify whether the configuration works.
72
71
73
72
### Configure Azure AD SSO
74
73
75
-
In this section, you enable Azure AD single sign-on in the Azure portal.
76
-
77
-
To configure Azure AD single sign-on with Mind Tools Toolkit, perform the following steps:
74
+
In this section, you configure Azure AD single sign-on with Mind Tools Toolkit by following these steps:
78
75
79
76
1. In the [Azure portal](https://portal.azure.com/), on the **Mind Tools Toolkit** application integration page, select **Single sign-on**.
80
77
81
-

78
+

82
79
83
-
2. On the **Select a Single sign-on method** dialog, select **SAML/WS-Fed** mode to enable single sign-on.
80
+
1. In the **Select a Single sign-on method** dialog box, select **SAML/WS-Fed** to enable single sign-on.

90
87
91
-
4. On the **Basic SAML Configuration** section, perform the following steps:
88
+
1. In the **Basic SAML Configuration** section, in the **Sign-on URL** box, enter a URL having the pattern `https://app.goodpractice.net/#/<subscriptionUrl>/s/<locationId>`.
92
89
93
-
In the **Sign-on URL** text box, type a URL using the following pattern:
> The **Sign-on URL** value isn't real. Update the value with the actual sign-on URL. Contact the [Mind Tools Toolkit Client support team](mailto:support@goodpractice.com) to get the value.
95
92
96
-
> [!Note]
97
-
> The Sign-on URL value is not real. Update the value with the actual Sign-On URL. Contact [Mind Tools Toolkit Client support team](mailto:[email protected]) to get the value.
93
+
1. On the **Set-up Single Sign-On with SAML** page, go to the **SAML Signing Certificate** section. To the right of **Federation Metadata XML**, select **Download** to download the XML text and save it on your computer. The XML contents depend on the options you select.
98
94
99
-
5. On the **Set up Single Sign-On with SAML** page, in the **SAML Signing Certificate** section, click **Download** to download the **Federation Metadata XML** from the given options as per your requirement and save it on your computer.
95
+

1. Select the **Show password** check box, and then write down the value that's displayed in the **Password** box.
123
-
1.Click**Create**.
114
+
1. In the **Name** field, enter **B.Simon**.
115
+
1. In the **User name** field, enter **B.Simon@**_companydomain_**.**_extension_. For example, [email protected].
116
+
1. Select the **Show password** check box, and then write down the value that's shown in the **Password** box.
117
+
1.Select**Create**.
124
118
125
119
### Assign the Azure AD test user
126
120
127
-
In this section, you'll enable B.Simon to use Azure single sign-on by granting access to Mind Tools Toolkit.
121
+
In this section, you enable B.Simon to use Azure single sign-on by granting access to Mind Tools Toolkit.
128
122
129
-
1. In the Azure portal, select **Enterprise Applications**, and then select**All applications**.
123
+
1. In the Azure portal, select **Enterprise Applications** >**All applications**.
130
124
1. In the applications list, select **Mind Tools Toolkit**.
131
-
1. In the app's overview page, find the **Manage** section and select **Users and groups**.
125
+
1. In the app's overview page, go to the **Manage** section, and select **Users and groups**.
132
126
133
-

127
+

134
128
135
-
1. Select **Add user**, then select**Users and groups**in the **Add Assignment** dialog.
129
+
1. Select **Add user**. In the**Add Assignment**dialog box, select **Users and groups**.
136
130
137
-

131
+

138
132
139
-
1. In the **Users and groups** dialog, select **B.Simon** from the Users list, then click the **Select** button at the bottom of the screen.
140
-
1. If you're expecting any role value in the SAML assertion, in the **Select Role** dialog, select the appropriate role for the user from the list and then click the **Select** button at the bottom of the screen.
141
-
1. In the **Add Assignment** dialog, click the **Assign** button.
133
+
1. In the **Users and groups** dialog box, select **B.Simon** from the users list. Then choose the **Select** button at the bottom of the screen.
134
+
1. If you expect any role value in the SAML assertion, in the **Select Role** dialog box, select the appropriate role for the user from the list. Then choose the **Select** button at the bottom of the screen.
135
+
1. In the **Add Assignment** dialog box, select **Assign**.
142
136
143
137
## Configure Mind Tools Toolkit SSO
144
138
145
-
To configure single sign-on on **Mind Tools Toolkit** side, you need to send the downloaded **Federation Metadata XML** and appropriate copied URLs from Azure portal to [Mind Tools Toolkit support team](mailto:[email protected]). They set this setting to have the SAML SSO connection set properly on both sides.
139
+
To configure single sign-on on the **Mind Tools Toolkit** side, send the downloaded **Federation Metadata XML** text and the previously copied URLs to the [Mind Tools Toolkit support team](mailto:[email protected]). They configure this setting to have the SAML SSO connection set properly on both sides.
140
+
141
+
### Create a Mind Tools Toolkit test user
146
142
147
-
### Create Mind Tools Toolkit test user
143
+
In this section, you create a user called B.Simon in Mind Tools Toolkit.
148
144
149
-
In this section, a user called B.Simon is created in Mind Tools Toolkit. Mind Tools Toolkit supports **just-in-time provisioning**, which is enabled by default. There is no action item for you in this section. If a user doesn't already exist in Mind Tools Toolkit, a new one is created when you attempt to access Mind Tools Toolkit.
145
+
Mind Tools Toolkitsupports just-in-time provisioning, which is enabled by default. There's no action for you to take in this section. If a user doesn't already exist in Mind Tools Toolkit, a new one is created when you attempt to access Mind Tools Toolkit.
150
146
151
147
### Test SSO
152
148
153
-
In this section, you test your Azure AD single sign-on configuration using the Access Panel.
149
+
In this section, you test your Azure AD single sign-on configuration by using the My Apps portal.
154
150
155
-
When you click the Mind Tools Toolkit tile in the Access Panel, you should be automatically signed in to the Mind Tools Toolkit for which you set up SSO. For more information about the Access Panel, see [Introduction to the Access Panel](https://docs.microsoft.com/azure/active-directory/active-directory-saas-access-panel-introduction).
151
+
When you select the Mind Tools Toolkit tile in the My Apps portal, you are automatically signed in to the Mind Tools Toolkit for which you set up SSO. For more information about the My Apps portal, see [Introduction to the My Apps portal](https://docs.microsoft.com/azure/active-directory/active-directory-saas-access-panel-introduction).
156
152
157
-
## Additional Resources
153
+
## Additional resources
158
154
159
-
-[List of Tutorials on How to Integrate SaaS Apps with Azure Active Directory](https://docs.microsoft.com/azure/active-directory/active-directory-saas-tutorial-list)
155
+
-[Tutorials for integrating SaaS apps with Azure Active Directory](https://docs.microsoft.com/azure/active-directory/active-directory-saas-tutorial-list)
160
156
161
157
-[What is application access and single sign-on with Azure Active Directory?](https://docs.microsoft.com/azure/active-directory/manage-apps/what-is-single-sign-on)
162
158
@@ -166,4 +162,4 @@ When you click the Mind Tools Toolkit tile in the Access Panel, you should be au
166
162
167
163
-[What is session control in Microsoft Cloud App Security?](https://docs.microsoft.com/cloud-app-security/proxy-intro-aad)
168
164
169
-
-[How to protect Mind Tools Toolkit with advanced visibility and controls](https://docs.microsoft.com/cloud-app-security/proxy-intro-aad)
165
+
-[How to protect Mind Tools Toolkit with advanced visibility and controls](https://docs.microsoft.com/cloud-app-security/proxy-intro-aad)
0 commit comments