Skip to content

Commit e603c9f

Browse files
author
BobbySchmidt2
committed
edit pass: goodpractice-toolkit-tutorial
1 parent b74a4ea commit e603c9f

File tree

1 file changed

+47
-48
lines changed

1 file changed

+47
-48
lines changed

articles/active-directory/saas-apps/goodpractice-toolkit-tutorial.md

Lines changed: 47 additions & 48 deletions
Original file line numberDiff line numberDiff line change
@@ -20,45 +20,45 @@ ms.collection: M365-identity-device-management
2020
---
2121
# Tutorial: Azure Active Directory integration with Mind Tools Toolkit
2222

23-
In this tutorial, you'll learn how to integrate Mind Tools Toolkit with Azure Active Directory (Azure AD).
24-
When you integrate Mind Tools Toolkit with Azure AD, you can:
23+
In this tutorial, you learn how to integrate Mind Tools Toolkit with Azure Active Directory (Azure AD).
24+
25+
With this integration, you can:
2526

2627
* Control in Azure AD who has access to Mind Tools Toolkit.
27-
* Enable your users to be automatically signed to Mind Tools Toolkit (SSO) with their Azure AD accounts.
28-
* Manage your accounts in one central location, the Azure portal.
28+
* Enable your users to be automatically signed in to Mind Tools Toolkit (single sign-on) with their Azure AD accounts.
29+
* Manage your accounts in one central location: the Azure portal.
2930

30-
For details about software as a service (SaaS) app integration with Azure AD, see [What is application access and single sign-on with Azure Active Directory](https://docs.microsoft.com/azure/active-directory/manage-apps/what-is-single-sign-on).
31+
To learn more about software as a service (SaaS) app integration with Azure AD, see [What is application access and single sign-on with Azure Active Directory](https://docs.microsoft.com/azure/active-directory/manage-apps/what-is-single-sign-on).
3132

3233
## Prerequisites
3334

3435
To configure Azure AD integration with Mind Tools Toolkit, you need the following items:
3536

3637
* An Azure AD subscription. If you don't have a subscription, you can get a [free account](https://azure.microsoft.com/free/).
37-
* A Mind Tools Toolkit subscription with single sign-on enabled.
38+
* A Mind Tools Toolkit subscription with single sign-on (SSO) enabled.
3839

3940
## Scenario description
4041

4142
In this tutorial, you configure and test Azure AD single sign-on in a test environment.
4243

4344
* Mind Tools Toolkit supports SP-initiated SSO.
4445
* Mind Tools Toolkit supports just-in-time user provisioning.
45-
* After you configure Mind Tools Toolkit, you can enforce session control. This control helps protect exfiltration and infiltration of your organization's sensitive data in real time. Session control extends from conditional access. [Learn how to enforce session control with Microsoft Cloud App Security](https://docs.microsoft.com/cloud-app-security/proxy-deployment-any-app).
46+
* After you configure Mind Tools Toolkit, you can enforce session control. This control protects exfiltration and infiltration of your organization's sensitive data in real time. Session control extends from conditional access. [Learn how to enforce session control with Microsoft Cloud App Security](https://docs.microsoft.com/cloud-app-security/proxy-deployment-any-app).
4647

4748
## Add Mind Tools Toolkit from the gallery
4849

4950
To configure the integration of Mind Tools Toolkit into Azure AD, you need to add Mind Tools Toolkit from the gallery to your list of managed SaaS apps.
5051

5152
1. Sign in to the [Azure portal](https://portal.azure.com) by using either a work or school account, or a personal Microsoft account.
52-
1. On the left pane, select **Azure Active Directory**.
53+
1. On the leftmost navigation pane, select the **Azure Active Directory** service.
5354
1. Go to **Enterprise Applications**, and then select **All Applications**.
5455
1. To add a new application, select **New application**.
5556
1. In the **Add from the gallery** section, enter **Mind Tools Toolkit** in the search box.
5657
1. Select **Mind Tools Toolkit** from the search results, and then add the app. Wait a few seconds while the app is added to your tenant.
5758

5859
## Configure and test Azure AD single sign-on
5960

60-
Configure and test Azure AD single sign-on with Mind Tools Toolkit by using a test user called **B.Simon**.
61-
For single sign-on to work, you must establish a linked relationship between an Azure AD user and the related user in Mind Tools Toolkit.
61+
In this section, you configure and test Azure AD single sign-on with Mind Tools Toolkit by using a test user called **B.Simon**. For single sign-on to work, you must establish a linked relationship between an Azure AD user and the related user in Mind Tools Toolkit.
6262

6363
To configure and test Azure AD single sign-on with Mind Tools Toolkit, complete the following building blocks:
6464

@@ -71,89 +71,88 @@ To configure and test Azure AD single sign-on with Mind Tools Toolkit, complete
7171

7272
### Configure Azure AD SSO
7373

74-
Follow these steps to enable and configure Azure AD single sign-on with Mind Tools Toolkit:
74+
In this section, you configure Azure AD single sign-on with Mind Tools Toolkit by following these steps:
7575

7676
1. In the [Azure portal](https://portal.azure.com/), on the **Mind Tools Toolkit** application integration page, select **Single sign-on**.
7777

78-
![The Manage section with Single sign-on highlighted](common/select-sso.png)
79-
80-
1. On the **Select a Single sign-on method** pane, select **SAML/WS-Fed** mode to enable single sign-on.
78+
![The Manage section, with Single sign-on highlighted](common/select-sso.png)
8179

82-
![The Select a single sign-on method section with SAML highlighted](common/select-saml-option.png)
80+
1. In the **Select a Single sign-on method** dialog box, select **SAML/WS-Fed** to enable single sign-on.
8381

84-
1. On the **Set up Single Sign-On with SAML** pane, select the pencil icon to open **Basic SAML Configuration** pane.
82+
![The Select a single sign-on method dialog box, with SAML highlighted](common/select-saml-option.png)
8583

86-
![The Set up a Single Sign-On with SAML pane with the pencil icon highlighted](common/edit-urls.png)
84+
1. On the **Set up Single Sign-On with SAML** page, select the pencil icon for **Basic SAML Configuration** to edit the settings.
8785

88-
1. On the **Basic SAML Configuration** section, perform the following steps:
86+
![The Set up Single Sign-On with SAML page, with the pencil icon for Basic SAML Configuration highlighted](common/edit-urls.png)
8987

90-
In the **Sign-on URL** text box, type a URL using the following pattern:
91-
`https://app.goodpractice.net/#/<subscriptionUrl>/s/<locationId>`.
88+
1. In the **Basic SAML Configuration** section, in the **Sign-on URL** box, enter a URL having the pattern `https://app.goodpractice.net/#/<subscriptionUrl>/s/<locationId>`.
9289

9390
> [!NOTE]
94-
> The Sign-on URL value is not real. Update the value with the actual Sign-On URL. Contact [Mind Tools Toolkit Client support team](mailto:[email protected]) to get the value.
91+
> The **Sign-on URL** value isn't real. Update the value with the actual sign-on URL. Contact the [Mind Tools Toolkit Client support team](mailto:[email protected]) to get the value.
9592
96-
1. On the **Set up Single Sign-On with SAML** page, in the **SAML Signing Certificate** section, click **Download** to download the **Federation Metadata XML** from the given options as per your requirement and save it on your computer.
93+
1. On the **Set-up Single Sign-On with SAML** page, go to the **SAML Signing Certificate** section. To the right of **Federation Metadata XML**, select **Download** to download the XML text and save it on your computer. The XML contents depend on the options you select.
9794

98-
![The Certificate download link](common/metadataxml.png)
95+
![The SAML Signing Certificate section, with Download highlighted next to Federation Metadata XML](common/metadataxml.png)
9996

100-
1. On the **Set up Mind Tools Toolkit** section, copy the appropriate URL(s) as per your requirement.
97+
1. In the **Set up Mind Tools Toolkit** section, copy whichever of the following URLs you need.
10198

102-
![Copy configuration URLs](common/copy-configuration-urls.png)
99+
* **Login URL**
103100

104-
1. Login URL
101+
* **Azure AD Identifier**
105102

106-
1. Azure AD Identifier
103+
* **Logout URL**
107104

108-
1. Logout URL
105+
![The Set up Mind Tools Toolkit section, with the configuration URLs highlighted](common/copy-configuration-urls.png)
109106

110107
### Create an Azure AD test user
111108

112-
In this section, you'll create a test user in the Azure portal called B.Simon.
109+
In this section, you create a test user called B.Simon in the Azure portal:
113110

114-
1. From the left pane in the Azure portal, select **Azure Active Directory**, select **Users**, and then select **All users**.
115-
1. Select **New user** at the top of the screen.
111+
1. On the leftmost side of the Azure portal, select **Azure Active Directory** > **Users** > **All users**.
112+
1. At the top of the screen, select **New user**.
116113
1. In the **User** properties, follow these steps:
117-
1. In the **Name** field, enter `B.Simon`.
118-
1. In the **User name** field, enter the [email protected]. For example, `[email protected]`.
119-
1. Select the **Show password** check box, and then write down the value that's displayed in the **Password** box.
120-
1. Click **Create**.
114+
1. In the **Name** field, enter **B.Simon**.
115+
1. In the **User name** field, enter **B.Simon@**_companydomain_**.**_extension_. For example, **[email protected]**.
116+
1. Select the **Show password** check box, and then write down the value that's shown in the **Password** box.
117+
1. Select **Create**.
121118

122119
### Assign the Azure AD test user
123120

124121
In this section, you enable B.Simon to use Azure single sign-on by granting access to Mind Tools Toolkit.
125122

126-
1. In the Azure portal, select **Enterprise Applications**, and then select **All applications**.
123+
1. In the Azure portal, select **Enterprise Applications** > **All applications**.
127124
1. In the applications list, select **Mind Tools Toolkit**.
128-
1. In the app's overview page, find the **Manage** section and select **Users and groups**.
125+
1. In the app's overview page, go to the **Manage** section, and select **Users and groups**.
129126

130-
![The "Users and groups" link](common/users-groups-blade.png)
127+
![The Manage section, with Users and groups highlighted](common/users-groups-blade.png)
131128

132-
1. Select **Add user**, then select **Users and groups** in the **Add Assignment** dialog.
129+
1. Select **Add user**. In the **Add Assignment** dialog box, select **Users and groups**.
133130

134-
![The Add User link](common/add-assign-user.png)
131+
![The Users and groups window, with Add user highlighted](common/add-assign-user.png)
135132

136-
1. In the **Users and groups** dialog, select **B.Simon** from the Users list, then click the **Select** button at the bottom of the screen.
137-
1. If you're expecting any role value in the SAML assertion, in the **Select Role** dialog, select the appropriate role for the user from the list and then click the **Select** button at the bottom of the screen.
138-
1. In the **Add Assignment** dialog, click the **Assign** button.
133+
1. In the **Users and groups** dialog box, select **B.Simon** from the users list. Then choose the **Select** button at the bottom of the screen.
134+
1. If you expect any role value in the SAML assertion, in the **Select Role** dialog box, select the appropriate role for the user from the list. Then choose the **Select** button at the bottom of the screen.
135+
1. In the **Add Assignment** dialog box, select **Assign**.
139136

140137
## Configure Mind Tools Toolkit SSO
141138

142-
To configure single sign-on on **Mind Tools Toolkit** side, you need to send the downloaded **Federation Metadata XML** and appropriate copied URLs from Azure portal to [Mind Tools Toolkit support team](mailto:[email protected]). They set this setting to have the SAML SSO connection set properly on both sides.
139+
To configure single sign-on on the **Mind Tools Toolkit** side, send the downloaded **Federation Metadata XML** text and the previously copied URLs to the [Mind Tools Toolkit support team](mailto:[email protected]). They configure this setting to have the SAML SSO connection set properly on both sides.
143140

144141
### Create a Mind Tools Toolkit test user
145142

146-
In this section, a user called B.Simon is created in Mind Tools Toolkit. Mind Tools Toolkit supports **just-in-time provisioning**, which is enabled by default. There is no action item for you in this section. If a user doesn't already exist in Mind Tools Toolkit, a new one is created when you attempt to access Mind Tools Toolkit.
143+
In this section, you create a user called B.Simon in Mind Tools Toolkit.
144+
145+
Mind Tools Toolkit supports just-in-time provisioning, which is enabled by default. There's no action for you to take in this section. If a user doesn't already exist in Mind Tools Toolkit, a new one is created when you attempt to access Mind Tools Toolkit.
147146

148147
### Test SSO
149148

150-
In this section, you test your Azure AD single sign-on configuration using the Access Panel.
149+
In this section, you test your Azure AD single sign-on configuration by using the My Apps portal.
151150

152-
When you click the Mind Tools Toolkit tile in the Access Panel, you should be automatically signed in to the Mind Tools Toolkit for which you set up SSO. For more information about the Access Panel, see [Introduction to the Access Panel](https://docs.microsoft.com/azure/active-directory/active-directory-saas-access-panel-introduction).
151+
When you select the Mind Tools Toolkit tile in the My Apps portal, you are automatically signed in to the Mind Tools Toolkit for which you set up SSO. For more information about the My Apps portal, see [Introduction to the My Apps portal](https://docs.microsoft.com/azure/active-directory/active-directory-saas-access-panel-introduction).
153152

154153
## Additional Resources
155154

156-
- [List of Tutorials on How to Integrate SaaS Apps with Azure Active Directory](https://docs.microsoft.com/azure/active-directory/active-directory-saas-tutorial-list)
155+
- [Tutorials for integrating SaaS apps with Azure Active Directory](https://docs.microsoft.com/azure/active-directory/active-directory-saas-tutorial-list)
157156

158157
- [What is application access and single sign-on with Azure Active Directory?](https://docs.microsoft.com/azure/active-directory/manage-apps/what-is-single-sign-on)
159158

0 commit comments

Comments
 (0)