You will need to have a MetroMap Enterprise plan to access the Single Sign-On (SSO) service. This is currently available using Microsoft Entra ID.
Azure Active Directory Single Sign-On (Azure AD SSO)
MetroMap supports Single Sign-On (SSO) using Microsoft Entra ID (formerly Azure Active Directory).
Using Microsoft Entra ID SSO allows users to sign in to MetroMap using their organisation's Microsoft account without needing a separate MetroMap username and password.
The authentication process is managed by Microsoft Entra ID, allowing organisations to apply their existing identity and security policies to MetroMap access.
Benefits of using this service
Better User Experience
- Same passwords to sign into on-premises and cloud-based applications.
- Less time is taken to resolve password-related issues.
Simplified Administration
- No need for complex deployments, IP filtering or other types of network configuration.
- No need to change settings frequently.
More Secure
- Microsoft Entra ID manages authentication and security controls.
- Organisations can apply Microsoft Entra Conditional Access policies, including Multi-Factor Authentication (MFA), where configured.
- MetroMap does not manage or store the user's Microsoft account password.
On-boarding Process and Account Management
To enable MetroMap SSO, your organisation's Account Admin will need to contact your MetroMap Account Manager or write to support@metromap.com.au.
We will add your entity’s email domain to allow our authentication system to recognise users within your organisation. We will then create an Enterprise Subscription for your organisation, and the users within your organisation who use MetroMap services will stay under this subscription. The administrator(s) of your account will have the ability to manage the users within the subscription through our MetroMap User Management Portal.
To provide the best user experience and services, we will request a user’s email address, first name, last name, and phone number (if applicable) during the user’s login process. We use the user’s email as a unique identifier to allow that user to store uploaded geometry files on our MetroMap MapViewer. If necessary, our support team can provide one-to-one support services via phone or email.
Once MetroMap SSO has been enabled, your organisation's IT / ICT administrator will need to configure the MetroMap Enterprise Application within the Microsoft Entra admin center.
See the Microsoft documentation for more details:
Configure admin consent workflow
Once the enrolment process is finished, users will be able to use our seamless login process for MetroMap MapViewer.
User Sign-in Flow with MetroMap
-
The user tries to access the MetroMap MapViewer.
-
If the user is not signed in, they will be redirected to the Microsoft sign-in page.
-
The user enters their email and password into the Microsoft sign-in page and selects the Sign-in button.
-
For a first-time user, the Azure AD sign-in page will then redirect the user to the Microsoft Permissions acknowledgement page.
The permissions include:
- Sign you in and read your profile – email, first name, last name, and phone number (if applicable) to provide our basic services.
- Maintain access to data you have given it access to – allows MetroMap MapViewer to keep the user signed in for an extended time.
-
Microsoft Entra ID authenticates the user and returns the authentication response to MetroMap.
-
If the user sign-in is successful, they can access the MetroMap MapViewer and use the web application.
.png)