Skip to main content

Setting up single sign-on (SSO) with Microsoft Entra ID

Set up the SSO add-on with Microsoft Entra ID, check access settings, invite a pilot group, and test sign-in before rolling it out.

Written by Logan Bowlby

Overview

Single sign-on (SSO) lets your team use their Microsoft work accounts to sign in to Mobaro.

SSO is an add-on that Mobaro enables and connects for your organization. Your IT team manages Microsoft Entra access; you manage Users and their permissions in Mobaro.

At a glance

Who can do this

Mobaro Super User, your Microsoft Entra administrator, and Mobaro Support.

Where

Microsoft Entra admin center; Administrate › Users and Administrate › User Groups in Mobaro.

Works on

Backend (web) and Mobile app sign-in.

Availability

Add-on — ask your CSM to enable Single Sign-On (SSO).


Before you begin

This guide covers the Entra invitation-based setup. Mobaro creates a guest identity in its Entra environment and connects it to the existing Mobaro User. The person authenticates with their own organization’s Microsoft account.

⚠️ Heads-up: If you already use the older app-registration setup, ask Mobaro to confirm your migration plan. Do not delete an existing registration, redirect URI or client secret while it is still in use. The invitation-based setup below does not ask you to create or email a client secret.


Connect your organization

1. Arrange SSO with Mobaro

Contact your CSM to arrange the SSO add-on. Give Mobaro Support your organization name, Entra tenant ID, work-email domains and a pilot User’s email. Ask Mobaro to confirm the connection is ready before inviting Users.

Find your tenant ID under Entra ID › Overview › Properties in the Microsoft Entra admin center. See Microsoft’s tenant ID instructions.

If your IT team restricts access to external organizations, obtain Mobaro’s resource-tenant ID and required application IDs from Support; do not guess these values.

2. Check your Entra access settings

Your Entra Security Administrator should review Entra ID › External Identities › Cross-tenant access settings.

If you need a Mobaro-specific exception, use Organizational settings › Add organization with the tenant ID supplied by Mobaro.

Open the organization’s Outbound access settings, then B2B collaboration › Users and groups. Check that the intended Users are allowed by the effective policy.

Use the scope your IT team approves; do not broaden tenant-wide defaults just to complete setup.

3. Check external application access

Select External applications. Check that the effective policy allows the required applications supplied by Mobaro Support.

4. Save the approved access settings

Save any approved changes.

Some granular scoping options require Microsoft Entra ID P1 or P2. Follow Microsoft’s cross-tenant access instructions for the available options.

Mobaro handles access on its resource-tenant side. Agree MFA and Conditional Access requirements with Mobaro before the pilot; the prompts depend on both organizations’ policies.


Prepare and invite your Users

5. Check the pilot Users

In Administrate › Users, check that each pilot User already exists and has the work email they will use for Microsoft sign-in.

Resolve aliases or different sign-in addresses with your IT team and Mobaro before sending invitations. Do not create duplicate Users to work around a mismatch.

Put the pilot Users in a small User Group. Keep their required Roles and Location memberships in Mobaro: Entra authentication does not assign these. See Create new users in your organization and Create and manage User Groups.

6. Open the SSO invitation dialog

As a Super User, open Administrate › Users and select the toolbar control with the tooltip Invite to sign in with SSO.

7. Send the pilot invitations

In Invite users to sign in with SSO, select the pilot group.

Review Members (uncheck to exclude), clear anyone who should not join the pilot, and select Send invitations.

Mobaro queues the invitations and sends each person an email.

🛑 Critical: After an existing User completes the SSO switch, their previous Mobaro password no longer works. Test with a small pilot and agree a recovery route with Mobaro before moving a wider team. Removing someone from an SSO-required group does not restore password sign-in.


Test the connection

8. Complete the pilot sign-in

Ask each pilot User to open the Mobaro invitation and sign in with the invited work email.

The Mobaro sign-in form routes eligible invited Users to their Microsoft identity provider. If Microsoft offers both a personal and a work account, use the intended work account.

9. Check Backend and Mobile app access

Complete any Microsoft consent or MFA prompts required by your organization.

Test a fresh sign-in to both the Backend and the Mobile app, and check that the expected Locations and work are available. Microsoft explains the first-time invitation and consent experience.

10. Check SSO Status

In Administrate › Users, use the SSO Status column and filter to follow the pilot.

Status

Meaning

Queued

Waiting for invitation processing.

Pending

Invitation processing succeeded; the SSO switch has not been completed.

Accepted

The User has completed the SSO switch.

If an invitation needs resending, a Super User can select that User’s Pending status.

If a User stays queued, has no expected status, or cannot finish signing in, contact Mobaro Support with their email, the time of the attempt and the exact error. Include Microsoft’s request or correlation ID when one is shown.


Roll out to more teams

11. Require SSO for selected groups

After the pilot succeeds, open the relevant User Group. In Single Sign-On (SSO), tick Require single sign-on and save.

A Super User, the group’s creator or Administrators, or a Role with User Groups › Modify can change this setting.

Members who do not already have an SSO status are queued automatically. This does not import Entra groups or create Mobaro Users. Follow Controlling SSO access with user groups for ongoing membership and invitation management.


Manage access after setup

SSO controls authentication. Continue managing Roles, Location access and offboarding in Mobaro.

Blocking an Entra account does not guarantee that an existing application session ends immediately. Coordinate Entra revocation and Mobaro access removal with your administrators; see Microsoft’s access-revocation guidance.


Best practices

  • Tell the pilot team when invitations will arrive and which work account to use.

  • Test your actual tablet, phone and browser policies before a wider rollout.

  • Keep an agreed recovery contact and avoid changing an active legacy SSO connection without a migration plan.


Frequently asked questions

Why can’t I see the SSO options in Mobaro?

SSO is an add-on. Ask your CSM to check that Single Sign-On (SSO) is enabled and the connection is ready. A Super User should handle the invitation pilot; access to group settings also depends on permissions.

Do we still need an app registration and client secret?

Not for the invitation-based setup described here. Existing legacy connections can still depend on them. Ask Mobaro to confirm your connection type before changing or removing any existing credentials.

Does SSO create our Users or copy Entra groups?

No. Create Users and maintain their memberships in Mobaro. Require single sign-on queues eligible existing members for SSO; it is not directory synchronization.

Why does Microsoft say access is blocked?

Ask your IT team to review the sign-in error and relevant outbound B2B collaboration or Conditional Access policies. Mobaro must also check its resource-tenant configuration. Share the error and correlation ID with Support rather than changing unrelated security settings.

Does removing a User from the group restore their password?

No. Removing the SSO requirement does not reverse a completed switch. Contact Mobaro Support if a User needs a different sign-in method.

Did this answer your question?