Azure AD

Azure AD is an identity and access-management service that integrates with a variety of applications and services. It offers multi-factor authentication and conditional access policies, which can be used to secure access to Mindful via SSO.

This section covers the Azure AD SSO integration. Topics covered:

  • Adding users
  • Setting up Application Roles
  • Assigning users to groups
  • Assigning users to your application

For instructions on configuring Azure AD, see this getting started guide from Azure.

Add Users

  1. Navigate to Azure Active Directory > Users, then click New User.
  2. Fill in the required fields to create a new user. If Groups or Roles are already configured, you can link those here as well.

(Optional) Set up Application Roles

There are two group concepts in Azure AD: Groups and Application Roles. Either one can be sent as a custom claim to Mindful, but each has its own configuration requirements. Regardless of the method you choose, you will still need to assign users to your application.

Note: If you do not plan to use Application Roles, skip this section.
  1. From your Azure active directory select App registrations.
  2. Navigate to your application.
  3. Click App roles, then click Create app role. Make sure Allowed member types is set to Users/Groups or Both.
image of the active directory sidebar menuexample of editing an app role

Assign Users to Groups

  1. Navigate to Users.
  2. Click the user you wish to update.
  3. Click the Groups side navigation link.
  4. Click add memberships.
  5. Select the user(s) you wish to add to the group.

Assign Users to Your Application

  1. Navigate to Enterprise Applications > Your application.
  2. Click Assign users and groups, then click Add user/group.
  3. Select the user(s) you wish to assign the role.
  4. Select the application role you wish to assign to the user(s). This can be the default user role if you're not using groups.
  5. Click Assign.
  6. This will add another row to the Users and groups list. You should see the new row with your assigned role.

image of the application role selector