Single Sign-On with Microsoft Entra ID
Your team can sign in to mtdt.io with their Microsoft work accounts. You register mtdt.io as an application in your own Microsoft Entra ID tenant, send us a few values from it, and we connect your tenant on our side. After that, anyone you assign to the application signs in with their Microsoft account.
Before you start
- Your redirect URI. Contact support@mtdt.io and we'll send you a redirect URI made for your company.
- An Entra admin account that can register applications and grant admin consent, for example Global Administrator or Cloud Application Administrator.
1. Register the application
- In the Microsoft Entra admin center, go to App registrations and choose New registration.
- Fill in the form:
- Name:
MTDT SSO - Supported account types: Accounts in this organizational directory only (Single tenant)
- Redirect URI: platform Web, value — the redirect URI we sent you. Paste it exactly as is.
- Name:
- Choose Register.
- On the application's Overview page, copy these two values:
- Application (client) ID
- Directory (tenant) ID
2. Create a client secret
- In the registered application, open Certificates & secrets and choose New client secret.
- Pick an expiry period and choose Add.
- Copy the value in the Value column right away. Entra shows it only once. The Secret ID column is a different value and isn't needed.
- Note the expiry date.
3. Add the email claim
- Open Token configuration and choose Add optional claim.
- Token type: ID. Select email and choose Add.
- If Entra offers a checkbox to turn on the Microsoft Graph email permission, select it.
mtdt.io identifies each person by email address, so every user who signs in needs an email in their Entra profile (Contact information → Email). Users with an Exchange mailbox already have one.
4. Set API permissions
- Open API permissions. The application needs these Microsoft Graph delegated permissions:
emailopenidprofileUser.Read
- To add missing ones, choose Add a permission → Microsoft Graph → Delegated permissions, then select them in the OpenId permissions group.
- Choose Grant admin consent for <your directory>. Every permission should now show a green check in the Status column, and your users won't see a consent prompt on their first sign-in.
5. Choose who can sign in
- Go to Enterprise applications and open MTDT SSO.
- Open Properties, set Assignment required? to Yes, and save.
- Open Users and groups and assign the people who should have access to mtdt.io.
With assignment required, only assigned users can sign in through this application. Everyone else in your tenant is refused by Microsoft before reaching mtdt.io.
Once SSO is on, everyone with an email on your domains signs in to mtdt.io through Microsoft, including people who used a password before. Make sure all of them are assigned.
6. Send us the details
Send these to your mtdt.io contact over a secure channel:
- Application (client) ID
- Directory (tenant) ID
- Client secret value and its expiry date
- The email domains your team uses (for example,
acme.com)
We'll confirm once your tenant is connected.
Signing in
On the mtdt.io sign-in page, a user enters their work email. mtdt.io recognises your domain and shows the option to continue with your SSO.
Signing in with Microsoft doesn't add anyone to your workspace. Invite teammates from Team settings as usual. They'll sign in with their Microsoft accounts.
Renewing the client secret
The connection stops working when the client secret expires. Before that date, create a new secret (step 2) and send us its value and expiry date. Delete the old secret in Entra after we confirm the switch.