Microsoft Entra ID – SSO Setup Guide

Prev Next

Overview

MetroMap supports Single Sign-On (SSO) using OpenID Connect (OIDC).

This guide explains how an organisation can configure MetroMap SSO using Microsoft Entra ID (formerly Azure Active Directory).

The setup is completed in two stages:

  • A user starts the MetroMap SSO login for the first time.
  • The organisation's IT / ICT administrator configures the MetroMap Enterprise Application in Microsoft Entra.

Once the initial configuration is complete, authorised users can simply select Login with Microsoft Account when accessing MetroMap.

Important: MetroMap uses OIDC for authentication. MetroMap does not natively use SAML for authentication.

Before you start

Your organisation will need:

  • A Microsoft Entra ID tenant.
  • An IT / ICT administrator who can manage Enterprise Applications and application consent.
  • A list of email domains to be provided to the MetroMap team for whitelisting.

The organisation can also use its existing Microsoft Entra policies for:

  • User and group access
  • Application approval
  • Administrator consent
  • User consent
  • Conditional Access

These controls are managed by your organisation in Microsoft Entra.


Start the MetroMap SSO login

The MetroMap Enterprise Application is normally added to your organisation's Microsoft Entra tenant when the MetroMap SSO login is initiated for the first time.

Step 1 – Open MetroMap

Open MetroMap via MetroMap Login.

Step 2 – Login with Microsoft Account

Select Login with Microsoft Account.

Sign in using your organisation's Microsoft account.

Depending on your organisation's Microsoft Entra settings, you may be asked to provide consent or request administrator approval.


Initial ICT configuration

After the first login attempt, your IT / ICT administrator needs to complete the initial Microsoft Entra configuration.

The MetroMap Enterprise Application should be available in your organisation's Microsoft Entra tenant.

Step 3 – Locate the MetroMap Enterprise Application

Your IT / ICT administrator should:

  • Sign in to the Microsoft Entra admin center.
  • Go to Entra ID → Enterprise applications → All applications.
  • Search for MetroMap.
  • Select the MetroMap Enterprise Application.

Microsoft describes an application as being provisioned in the tenant when, for example, a user has consented to the application. Once provisioned, administrators can manage the application from Enterprise applications.

Step 4 – Configure MetroMap access

The IT / ICT administrator can now configure how users in the organisation are permitted to access MetroMap.

Depending on your organisation's requirements, this can include:

  • Assigning specific users
  • Assigning security groups
  • Requiring users to be assigned to the application
  • Reviewing and granting application consent
  • Configuring an administrator approval workflow
  • Applying existing organisational security policies

Important: Microsoft Entra controls authentication and access to the application. MetroMap separately controls the user's MetroMap account, subscription and MetroMap permissions.


Microsoft Entra configuration options

The following Microsoft resources provide guidance for the different configuration options available to your IT / ICT team.

Grant admin consent

  • Review MetroMap permissions.
  • Approve consent for the organisation.
  • Manage application consent.

Microsoft – Grant admin consent

Configure admin consent workflow

  • Allow users to request approval.
  • Set approval reviewers.
  • Configure email notifications.
  • Set request expiry.

Microsoft – Configure admin consent workflow

Configure user and group access

  • Assign users or groups to MetroMap.
  • Require users to be assigned before access.
  • Manage access through Entra groups.

Microsoft – Manage application access and security


Test the configuration

After the Enterprise Application has been configured:

  • Select a test user who has been granted access to MetroMap.
  • Open MetroMap Login.
  • Select Login with Microsoft Account.
  • Sign in using the test user's Microsoft work or school account.
  • Confirm that the user is successfully returned to MetroMap.
  • Confirm that the user has the expected MetroMap access.

If the login is successful but the user does not have the expected MetroMap access, review the user's MetroMap account and permissions.


Subsequent users

Once the initial configuration has been completed, additional authorised users can access MetroMap using the same process:

  • Open MetroMap Login.
  • Select Login with Microsoft Account.
  • Sign in using their organisation's Microsoft account.

The user does not need to configure SSO themselves.

Their access is controlled by the organisation's Microsoft Entra configuration and their MetroMap account permissions.


Troubleshooting

MetroMap does not appear under Enterprise Applications

Ask your IT / ICT administrator to check:

Entra ID → Enterprise applications → All applications

Search for MetroMap.

If the application has not yet been provisioned, initiate the MetroMap login process by selecting Login with Microsoft Account.


The user sees "Approval required"

This generally means the organisation's Microsoft Entra settings require administrator approval for the requested application permissions.

The user can follow the organisation's approval process, if configured.

Alternatively, an appropriately authorised administrator can review and grant consent.

Microsoft – Configure the admin consent workflow