Assigning Minecraft Licenses

Olger
New Contributor III

 

Wondering if anyone has set up automated Minecraft license assigning? We have our Google Workspace set up as IdP for Microsoft Entra (which works fine) and students (and staff) can login to Microsoft using their Google Accounts. Any student that has a Minecraft license assigned can use that using their Google account.

Within Workspace I have created a dynamic Minecraft group that pulls students from specified OU's (each year is in its own OU, currently only a few years use Minecraft). I supply that group name as an attribute in my SAML set up for Microsoft Entra. In Microsoft Entra I have a similar group called Minecraft that is used to assign a Minecraft license to its members. All that works. But how do I get Microsoft Entra to add (and remove) students that are member of the Workspace Minecraft group to the Entra Minecraft group?

3 REPLIES 3

Bill_Gibson
Contributor III

Off-topic: Can you share any resources that address setting Google as the IdP in Entra?

Olger
New Contributor III

https://learn.microsoft.com/en-us/education/windows/configure-aad-google-trust

The thing that gets me (often) with Microsoft Azure/Entra, is that anything where MS is in control, can be done using the GUI. Like setting Entra as IdP and others as SP. When it comes to using another service as IdP (such as Google Workspace), there always seems to be some Powershell involved... Which creates an extra (unnecessary) hurdle.

Anyway, ChatGPT summarizes the process quite well (when asking for "provide resources to set up google workspace as Idp for Microsoft Entra"):

To set up Google Workspace as an Identity Provider (IdP) for Microsoft Entra ID, follow these steps:


Step 1: Configure Google Workspace as an IdP

  1. Sign in to Google Admin Console:

  2. Add SAML App:

  3. Download IdP Metadata:

  4. Configure Service Provider Details:

  5. Attribute Mapping:


Step 2: Configure SAML SSO in Microsoft Entra ID

  1. Add Google Workspace App:

  2. Set Up SAML SSO:

  3. Assign Users:


Step 3: Test the Federation

  1. Access the Application:

  2. Authenticate:

 

Kim_Nilsson
Admin Moderator

Google's own support article is what I have used.

https://support.google.com/a/answer/6363817

 

--
https://wheretofind.me/@NoSubstitute