You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
# Tutorial: Azure Active Directory integration with Mind Tools Toolkit
22
22
23
-
In this tutorial, you'll learn how to integrate Mind Tools Toolkit with Azure Active Directory (Azure AD).
24
-
When you integrate Mind Tools Toolkit with Azure AD, you can:
23
+
In this tutorial, you learn how to integrate Mind Tools Toolkit with Azure Active Directory (Azure AD).
24
+
25
+
With this integration, you can:
25
26
26
27
* Control in Azure AD who has access to Mind Tools Toolkit.
27
-
* Enable your users to be automatically signed to Mind Tools Toolkit (SSO) with their Azure AD accounts.
28
-
* Manage your accounts in one central location, the Azure portal.
28
+
* Enable your users to be automatically signed in to Mind Tools Toolkit (single sign-on) with their Azure AD accounts.
29
+
* Manage your accounts in one central location: the Azure portal.
29
30
30
-
For details about software as a service (SaaS) app integration with Azure AD, see [What is application access and single sign-on with Azure Active Directory](https://docs.microsoft.com/azure/active-directory/manage-apps/what-is-single-sign-on).
31
+
To learn more about software as a service (SaaS) app integration with Azure AD, see [What is application access and single sign-on with Azure Active Directory](https://docs.microsoft.com/azure/active-directory/manage-apps/what-is-single-sign-on).
31
32
32
33
## Prerequisites
33
34
34
35
To configure Azure AD integration with Mind Tools Toolkit, you need the following items:
35
36
36
37
* An Azure AD subscription. If you don't have a subscription, you can get a [free account](https://azure.microsoft.com/free/).
37
-
* A Mind Tools Toolkit subscription with single sign-on enabled.
38
+
* A Mind Tools Toolkit subscription with single sign-on (SSO) enabled.
38
39
39
40
## Scenario description
40
41
41
42
In this tutorial, you configure and test Azure AD single sign-on in a test environment.
42
43
43
44
* Mind Tools Toolkit supports SP-initiated SSO.
44
45
* Mind Tools Toolkit supports just-in-time user provisioning.
45
-
* After you configure Mind Tools Toolkit, you can enforce session control. This control helps protect exfiltration and infiltration of your organization's sensitive data in real time. Session control extends from conditional access. [Learn how to enforce session control with Microsoft Cloud App Security](https://docs.microsoft.com/cloud-app-security/proxy-deployment-any-app).
46
+
* After you configure Mind Tools Toolkit, you can enforce session control. This control protects exfiltration and infiltration of your organization's sensitive data in real time. Session control extends from conditional access. [Learn how to enforce session control with Microsoft Cloud App Security](https://docs.microsoft.com/cloud-app-security/proxy-deployment-any-app).
46
47
47
48
## Add Mind Tools Toolkit from the gallery
48
49
49
50
To configure the integration of Mind Tools Toolkit into Azure AD, you need to add Mind Tools Toolkit from the gallery to your list of managed SaaS apps.
50
51
51
52
1. Sign in to the [Azure portal](https://portal.azure.com) by using either a work or school account, or a personal Microsoft account.
52
-
1. On the left pane, select **Azure Active Directory**.
53
+
1. On the leftmost navigation pane, select the **Azure Active Directory** service.
53
54
1. Go to **Enterprise Applications**, and then select **All Applications**.
54
55
1. To add a new application, select **New application**.
55
56
1. In the **Add from the gallery** section, enter **Mind Tools Toolkit** in the search box.
56
57
1. Select **Mind Tools Toolkit** from the search results, and then add the app. Wait a few seconds while the app is added to your tenant.
57
58
58
59
## Configure and test Azure AD single sign-on
59
60
60
-
Configure and test Azure AD single sign-on with Mind Tools Toolkit by using a test user called **B.Simon**.
61
-
For single sign-on to work, you must establish a linked relationship between an Azure AD user and the related user in Mind Tools Toolkit.
61
+
In this section, you configure and test Azure AD single sign-on with Mind Tools Toolkit by using a test user called **B.Simon**. For single sign-on to work, you must establish a linked relationship between an Azure AD user and the related user in Mind Tools Toolkit.
62
62
63
63
To configure and test Azure AD single sign-on with Mind Tools Toolkit, complete the following building blocks:
64
64
@@ -71,89 +71,88 @@ To configure and test Azure AD single sign-on with Mind Tools Toolkit, complete
71
71
72
72
### Configure Azure AD SSO
73
73
74
-
Follow these steps to enable and configure Azure AD single sign-on with Mind Tools Toolkit:
74
+
In this section, you configure Azure AD single sign-on with Mind Tools Toolkit by following these steps:
75
75
76
76
1. In the [Azure portal](https://portal.azure.com/), on the **Mind Tools Toolkit** application integration page, select **Single sign-on**.
77
77
78
-

79
-
80
-
1. On the **Select a Single sign-on method** pane, select **SAML/WS-Fed** mode to enable single sign-on.
78
+

81
79
82
-

80
+
1. In the **Select a Single sign-on method** dialog box, select **SAML/WS-Fed** to enable single sign-on.
83
81
84
-
1. On the **Set up Single Sign-On with SAML** pane, select the pencil icon to open **Basic SAML Configuration** pane.
82
+

85
83
86
-

84
+
1. On the **Set up Single Sign-On with SAML** page, select the pencil icon for **Basic SAML Configuration** to edit the settings.
87
85
88
-
1. On the **Basic SAML Configuration** section, perform the following steps:
86
+

89
87
90
-
In the **Sign-on URL** text box, type a URL using the following pattern:
1. In the **Basic SAML Configuration** section, in the **Sign-on URL** box, enter a URL having the pattern `https://app.goodpractice.net/#/<subscriptionUrl>/s/<locationId>`.
92
89
93
90
> [!NOTE]
94
-
> The Sign-on URL value is not real. Update the value with the actual Sign-On URL. Contact [Mind Tools Toolkit Client support team](mailto:[email protected]) to get the value.
91
+
> The **Sign-on URL** value isn't real. Update the value with the actual sign-on URL. Contact the[Mind Tools Toolkit Client support team](mailto:[email protected]) to get the value.
95
92
96
-
1. On the **Setup Single Sign-On with SAML** page, in the **SAML Signing Certificate** section, click **Download** to download the **Federation Metadata XML** from the given options as per your requirement and save it on your computer.
93
+
1. On the **Set-up Single Sign-On with SAML** page, go to the **SAML Signing Certificate** section. To the right of **Federation Metadata XML**, select **Download** to download the XML text and save it on your computer. The XML contents depend on the options you select.
1. Select the **Show password** check box, and then write down the value that's displayed in the **Password** box.
120
-
1.Click**Create**.
114
+
1. In the **Name** field, enter **B.Simon**.
115
+
1. In the **User name** field, enter **B.Simon@**_companydomain_**.**_extension_. For example, **[email protected]**.
116
+
1. Select the **Show password** check box, and then write down the value that's shown in the **Password** box.
117
+
1.Select**Create**.
121
118
122
119
### Assign the Azure AD test user
123
120
124
121
In this section, you enable B.Simon to use Azure single sign-on by granting access to Mind Tools Toolkit.
125
122
126
-
1. In the Azure portal, select **Enterprise Applications**, and then select**All applications**.
123
+
1. In the Azure portal, select **Enterprise Applications** >**All applications**.
127
124
1. In the applications list, select **Mind Tools Toolkit**.
128
-
1. In the app's overview page, find the **Manage** section and select **Users and groups**.
125
+
1. In the app's overview page, go to the **Manage** section, and select **Users and groups**.
129
126
130
-

127
+

131
128
132
-
1. Select **Add user**, then select**Users and groups**in the **Add Assignment** dialog.
129
+
1. Select **Add user**. In the**Add Assignment**dialog box, select **Users and groups**.
133
130
134
-

131
+

135
132
136
-
1. In the **Users and groups** dialog, select **B.Simon** from the Users list, then click the **Select** button at the bottom of the screen.
137
-
1. If you're expecting any role value in the SAML assertion, in the **Select Role** dialog, select the appropriate role for the user from the list and then click the **Select** button at the bottom of the screen.
138
-
1. In the **Add Assignment** dialog, click the **Assign** button.
133
+
1. In the **Users and groups** dialog box, select **B.Simon** from the users list. Then choose the **Select** button at the bottom of the screen.
134
+
1. If you expect any role value in the SAML assertion, in the **Select Role** dialog box, select the appropriate role for the user from the list. Then choose the **Select** button at the bottom of the screen.
135
+
1. In the **Add Assignment** dialog box, select **Assign**.
139
136
140
137
## Configure Mind Tools Toolkit SSO
141
138
142
-
To configure single sign-on on **Mind Tools Toolkit** side, you need to send the downloaded **Federation Metadata XML** and appropriate copied URLs from Azure portal to [Mind Tools Toolkit support team](mailto:[email protected]). They set this setting to have the SAML SSO connection set properly on both sides.
139
+
To configure single sign-on on the **Mind Tools Toolkit** side, send the downloaded **Federation Metadata XML**text and the previously copied URLs to the [Mind Tools Toolkit support team](mailto:[email protected]). They configure this setting to have the SAML SSO connection set properly on both sides.
143
140
144
141
### Create a Mind Tools Toolkit test user
145
142
146
-
In this section, a user called B.Simon is created in Mind Tools Toolkit. Mind Tools Toolkit supports **just-in-time provisioning**, which is enabled by default. There is no action item for you in this section. If a user doesn't already exist in Mind Tools Toolkit, a new one is created when you attempt to access Mind Tools Toolkit.
143
+
In this section, you create a user called B.Simon in Mind Tools Toolkit.
144
+
145
+
Mind Tools Toolkit supports just-in-time provisioning, which is enabled by default. There's no action for you to take in this section. If a user doesn't already exist in Mind Tools Toolkit, a new one is created when you attempt to access Mind Tools Toolkit.
147
146
148
147
### Test SSO
149
148
150
-
In this section, you test your Azure AD single sign-on configuration using the Access Panel.
149
+
In this section, you test your Azure AD single sign-on configuration by using the My Apps portal.
151
150
152
-
When you click the Mind Tools Toolkit tile in the Access Panel, you should be automatically signed in to the Mind Tools Toolkit for which you set up SSO. For more information about the Access Panel, see [Introduction to the Access Panel](https://docs.microsoft.com/azure/active-directory/active-directory-saas-access-panel-introduction).
151
+
When you select the Mind Tools Toolkit tile in the My Apps portal, you are automatically signed in to the Mind Tools Toolkit for which you set up SSO. For more information about the My Apps portal, see [Introduction to the My Apps portal](https://docs.microsoft.com/azure/active-directory/active-directory-saas-access-panel-introduction).
153
152
154
153
## Additional Resources
155
154
156
-
-[List of Tutorials on How to Integrate SaaS Apps with Azure Active Directory](https://docs.microsoft.com/azure/active-directory/active-directory-saas-tutorial-list)
155
+
-[Tutorials for integrating SaaS apps with Azure Active Directory](https://docs.microsoft.com/azure/active-directory/active-directory-saas-tutorial-list)
157
156
158
157
-[What is application access and single sign-on with Azure Active Directory?](https://docs.microsoft.com/azure/active-directory/manage-apps/what-is-single-sign-on)
0 commit comments