This guide explains how to configure your Microsoft Entra ID tenant to enable single sign-on (SSO) for My Pro Metrics using SAML 2.0. This allows your team members to access My Pro Metrics with their enterprise credentials.
For more information, see also Microsoft Entra ID’s guidance on enabling single sign-on for enterprise applications.
Before you begin #
Before you can configure your Microsoft Entra ID tenant for logging in to My Pro Metrics, you need the following:
- A Microsoft Entra ID tenant.
- An account that is at least a Cloud Application Administrator.
- My Pro Metrics SAML configuration details:
- Assertion Consumer Service URL (ACS URL): The URL where Microsoft Entra ID will send the SAML assertion.
- Entity ID: Unique identifier for My Pro Metrics as a service provider.
Contact My Pro Metrics support for the SAML configuration details. In your message, include which email domain and identity provider will be used for authentication.
Instructions
Step 1: Register an enterprise application in Microsoft Entra ID
Log in to the Microsoft Entra admin center as one of the following: Cloud Application Administrator, Application Administrator, or Global Administrator.
In the Entra admin center, navigate to Microsoft Entra ID → Enterprise applications → New application → Create your own application.
Select Integrate any other application you don’t find in the gallery (Non-gallery), give it a name such as “My Pro Metrics”, and continue.
In the new app, navigate to Manage → Single sign-on.
Select SAML as the single sign-on method.
On the SAML setup screen, make the following adjustments:
Basic SAML Configuration:
- Identifier (Entity ID): Enter the Entity ID provided to you.
- Reply URL (ACS URL): This URL will be used by My Pro Metrics to receive the SAML response from Microsoft Entra ID.
- Sign-on URL: This URL will be provided by Microsoft Entra ID. You will use it later for testing. Leave it empty if you want to use the IdP-initiated flow with myapps.microsoft.com.
- Relay State: Specify the Start URL provided to you.
User Attributes & Claims:
- Name ID: Map the user.mail attribute to the Name ID in the Email Address format. This is important if you have external users in your directory to ensure proper emails are used instead of EXT surrogates.
Download the Federation Metadata XML file. You will need to provide it to My Pro Metrics to complete the domain registration.
Step 2: Assign users and groups to the application
In the Users and Groups section, assign the users and groups who should have access to My Pro Metrics.
If you want users to log in without extra steps, you can configure self-serve login or require admin approval for access.
Step 3: Share SAML metadata with My Pro Metrics
Download the Federation Metadata XML file and share it with My Pro Metrics to finish registering your domain.
Step 4: Test the integration
After My Pro Metrics confirms receipt and processing of your metadata file, test the integration:
- Log in to the My Pro Metrics Hub as a user assigned to the application in Microsoft Entra ID.
- Verify that the user in the top-right corner of the Hub matches their Microsoft Entra identity.
- Review the audit logs in Microsoft Entra ID to ensure authentication is successful or to identify any issues.