Metro Retro Help
  • ๐Ÿ‘‹Welcome
  • Getting Started
    • ๐Ÿ˜Migrating from V2?
    • ๐ŸฅณLearn The Basics
    • ๐ŸคฉRunning Your First Session
  • Boards
    • ๐ŸŽฏBoards Overview
    • ๐Ÿ—๏ธCreate a board
    • ๐Ÿ•น๏ธDesign & Meeting Mode
    • ๐ŸงฐThe Toolbar
    • ๐ŸŽจCustomizing Your Board
    • ๐ŸคShare your board
    • โœ…Actions
    • ๐Ÿ’ฌMentions
    • ๐Ÿ””Notifications
    • โฐHow to set the timer
    • ๐Ÿ˜ŽHide & Show Sticky Notes
    • ๐Ÿ‘Voting
    • ๐Ÿ•น๏ธHost controls
    • ๐ŸŽซJira Integration
    • ๐Ÿ“ฅImport data to your boards
    • ๐Ÿ”’Locking the layout
    • ๐Ÿท๏ธTags
    • ๐Ÿ“คExport your board
    • ๐ŸงชBeta Features
  • Dashboard
    • ๐ŸŽฏDashboard Overview
    • ๐Ÿ—‚๏ธBoards
    • โœ…Action Items
    • โญTeams and Members
  • ๐ŸคฉTemplates
    • ๐ŸŽฏTemplates Overview
    • ๐Ÿ—ƒ๏ธTemplate Library
    • ๐Ÿ–Œ๏ธCustom Templates
  • Management
    • ๐Ÿค“Admins
    • ๐Ÿง‘โ€๐Ÿคโ€๐Ÿง‘Manage People
    • ๐ŸคผManage Teams
    • Manage Boards
    • ๐Ÿ”Security & Access Control
    • ๐Ÿ”‘Single Sign-On
      • ๐Ÿ“˜Azure Integration
      • ๐Ÿ“•Google Integration
      • ๐Ÿ““Okta Integration
    • ๐Ÿ’ŒInvite and Access Approvals
    • ๐Ÿ“”Billing & Subscription
  • Plans
    • ๐ŸŽฏPlans Overview
    • โŒ›Legacy Plans
      • Pro Plan
      • Business Plan
      • Enterprise Plan
  • Product
    • ๐Ÿš€Release Notes
  • Technical
    • ๐Ÿค–Technical Overview
  • Help
    • ๐Ÿค”FAQs
      • General FAQS
      • "How-To" FAQs
      • Using Metro Retro FAQs
      • Pricing FAQs
    • ๐ŸŽนKeyboard Shortcuts
Powered by GitBook
On this page
  • Prerequisites
  • How to find your Metro Retro Account ID
  • Integration Setup

Was this helpful?

Export as PDF
  1. Management
  2. ๐Ÿ”‘Single Sign-On

๐Ÿ“˜Azure Integration

PreviousSingle Sign-OnNextGoogle Integration

Last updated 7 months ago

Was this helpful?

Prerequisites

In order to configure Azure SSO integration with Metro Retro you will need:

  • Admin access to your Metro Retro account.

  • Admin access to your Azure portal (with permission to add Enterprise Applications).

  • One or more authorized domains adding to your Metro Retro account (see end of article).

  • A note of your organizations Metro Retro Account ID.

How to find your Metro Retro Account ID

Before you begin, you will need your organization's 12 character Metro Retro Account ID. You can find this in the under the management menu within Metro Retro: https://metroretro.io/manage

Integration Setup

From within the Azure portal, search for and select Enterprise Applications from the resources palette, click New Application and then Create your own application. Set the name as Metro Retro and select Integrate any other application you don't find in the gallery if not already selected.

Click Create.

Select Single sign-on from the left menu (or getting started quick link) and select SAML as the sign-in method.

Under Basic SAML configuration, enter your Metro Retro Account ID number as the Identifier (Entity ID) and set the Reply URL to https://metroretro.io/login/saml. Leave all other fields in this section blank.

Leave the default User Attributes & Claims settings, as per the screenshot above. If the defaults are different or you have changed them, please set them as above.

Next, download the Base64 encoded Certificate file from Section 3. Make a note of the Login URL and Azure AD Identifier from Section 4. We will need all these values to configure the Metro Retro side of the integration.

Go to your Metro Retro account administration screen and navigate to Single Sign-On. Map the values from Azure to Metro Retro like so:

  • Entry Point = Login URL

  • Issuer = Azure AD Identifier

  • Certificate = Text content of the Base64 certificate file

Once added, click Save Configuration. We recommend leaving the "Restrict login" setting off until you are sure all your team members are able to login via SSO otherwise it may block their access.

If you have not already had your authorized domains configured by a Metro Retro team member, please contact us on Intercom or at [email protected] to set these up. The domains should include all domains that your team will login from.

Authorized domains allow us to redirect users from Metro Retro to your SSO Identity Provider if they login directly via our login interface rather than going via your service portal. They are not required, but recommended.

Metro Retro Account ID
SAML Settings
The data we need from Azure
Example configuration within Metro Retro