Overview
Single sign-on (SSO) lets your team use their Microsoft work accounts to sign in to Mobaro.
SSO is an add-on that Mobaro enables and connects for your organization. Your IT team manages Microsoft Entra access; you manage Users and their permissions in Mobaro.
At a glance |
|
Who can do this | Mobaro Super User, your Microsoft Entra administrator, and Mobaro Support. |
Where | Microsoft Entra admin center; Administrate › Users and Administrate › User Groups in Mobaro. |
Works on | Backend (web) and Mobile app sign-in. |
Availability | Add-on — ask your CSM to enable Single Sign-On (SSO). |
Before you begin
This guide covers the Entra invitation-based setup. Mobaro creates a guest identity in its Entra environment and connects it to the existing Mobaro User. The person authenticates with their own organization’s Microsoft account.
⚠️ Heads-up: If you already use the older app-registration setup, ask Mobaro to confirm your migration plan. Do not delete an existing registration, redirect URI or client secret while it is still in use. The invitation-based setup below does not ask you to create or email a client secret.
Connect your organization
1. Arrange SSO with Mobaro
Contact your CSM to arrange the SSO add-on. Give Mobaro Support your organization name, Entra tenant ID, work-email domains and a pilot User’s email. Ask Mobaro to confirm the connection is ready before inviting Users.
Find your tenant ID under Entra ID › Overview › Properties in the Microsoft Entra admin center. See Microsoft’s tenant ID instructions.
If your IT team restricts access to external organizations, obtain Mobaro’s resource-tenant ID and required application IDs from Support; do not guess these values.
2. Check your Entra access settings
Your Entra Security Administrator should review Entra ID › External Identities › Cross-tenant access settings.
If you need a Mobaro-specific exception, use Organizational settings › Add organization with the tenant ID supplied by Mobaro.
Open the organization’s Outbound access settings, then B2B collaboration › Users and groups. Check that the intended Users are allowed by the effective policy.
Use the scope your IT team approves; do not broaden tenant-wide defaults just to complete setup.
3. Check external application access
Select External applications. Check that the effective policy allows the required applications supplied by Mobaro Support.
4. Save the approved access settings
Save any approved changes.
Some granular scoping options require Microsoft Entra ID P1 or P2. Follow Microsoft’s cross-tenant access instructions for the available options.
Mobaro handles access on its resource-tenant side. Agree MFA and Conditional Access requirements with Mobaro before the pilot; the prompts depend on both organizations’ policies.
Prepare and invite your Users
5. Check the pilot Users
In Administrate › Users, check that each pilot User already exists and has the work email they will use for Microsoft sign-in.
Resolve aliases or different sign-in addresses with your IT team and Mobaro before sending invitations. Do not create duplicate Users to work around a mismatch.
Put the pilot Users in a small User Group. Keep their required Roles and Location memberships in Mobaro: Entra authentication does not assign these. See Create new users in your organization and Create and manage User Groups.
6. Open the SSO invitation dialog
As a Super User, open Administrate › Users and select the toolbar control with the tooltip Invite to sign in with SSO.
7. Send the pilot invitations
In Invite users to sign in with SSO, select the pilot group.
Review Members (uncheck to exclude), clear anyone who should not join the pilot, and select Send invitations.
Mobaro queues the invitations and sends each person an email.
🛑 Critical: After an existing User completes the SSO switch, their previous Mobaro password no longer works. Test with a small pilot and agree a recovery route with Mobaro before moving a wider team. Removing someone from an SSO-required group does not restore password sign-in.
Test the connection
8. Complete the pilot sign-in
Ask each pilot User to open the Mobaro invitation and sign in with the invited work email.
The Mobaro sign-in form routes eligible invited Users to their Microsoft identity provider. If Microsoft offers both a personal and a work account, use the intended work account.
9. Check Backend and Mobile app access
Complete any Microsoft consent or MFA prompts required by your organization.
Test a fresh sign-in to both the Backend and the Mobile app, and check that the expected Locations and work are available. Microsoft explains the first-time invitation and consent experience.
10. Check SSO Status
In Administrate › Users, use the SSO Status column and filter to follow the pilot.
Status | Meaning |
Queued | Waiting for invitation processing. |
Pending | Invitation processing succeeded; the SSO switch has not been completed. |
Accepted | The User has completed the SSO switch. |
If an invitation needs resending, a Super User can select that User’s Pending status.
If a User stays queued, has no expected status, or cannot finish signing in, contact Mobaro Support with their email, the time of the attempt and the exact error. Include Microsoft’s request or correlation ID when one is shown.
Roll out to more teams
11. Require SSO for selected groups
After the pilot succeeds, open the relevant User Group. In Single Sign-On (SSO), tick Require single sign-on and save.
A Super User, the group’s creator or Administrators, or a Role with User Groups › Modify can change this setting.
Members who do not already have an SSO status are queued automatically. This does not import Entra groups or create Mobaro Users. Follow Controlling SSO access with user groups for ongoing membership and invitation management.
Manage access after setup
SSO controls authentication. Continue managing Roles, Location access and offboarding in Mobaro.
Blocking an Entra account does not guarantee that an existing application session ends immediately. Coordinate Entra revocation and Mobaro access removal with your administrators; see Microsoft’s access-revocation guidance.
Best practices
Tell the pilot team when invitations will arrive and which work account to use.
Test your actual tablet, phone and browser policies before a wider rollout.
Keep an agreed recovery contact and avoid changing an active legacy SSO connection without a migration plan.
Frequently asked questions
Why can’t I see the SSO options in Mobaro?
SSO is an add-on. Ask your CSM to check that Single Sign-On (SSO) is enabled and the connection is ready. A Super User should handle the invitation pilot; access to group settings also depends on permissions.
Do we still need an app registration and client secret?
Not for the invitation-based setup described here. Existing legacy connections can still depend on them. Ask Mobaro to confirm your connection type before changing or removing any existing credentials.
Does SSO create our Users or copy Entra groups?
No. Create Users and maintain their memberships in Mobaro. Require single sign-on queues eligible existing members for SSO; it is not directory synchronization.
Why does Microsoft say access is blocked?
Ask your IT team to review the sign-in error and relevant outbound B2B collaboration or Conditional Access policies. Mobaro must also check its resource-tenant configuration. Share the error and correlation ID with Support rather than changing unrelated security settings.
Does removing a User from the group restore their password?
No. Removing the SSO requirement does not reverse a completed switch. Contact Mobaro Support if a User needs a different sign-in method.








