Skip to main content

Single Sign On (SSO) - SAML 2.0 - Microsoft Entra ID

SSO, or Single Sign-On, is an authentication method that allows users to log in once and gain access to multiple applications or services without needing to authenticate again for each one. It simplifies the login process, improves security, and enhances the user experience.

Mapon offers Single Sign-On (SSO) functionality, enabling seamless and secure access for your users through their existing identity provider.

We support the SAML 2.0 protocol, ensuring compatibility with a wide range of identity provider platforms, such as Microsoft Entra ID.

📘 SAML SSO is available for Web platform and Driver mobile application (iOS, Android).


Full process flow chart


Set up steps


1. Create "Microsoft Entra ID" account

Go to the link below, select a plan according to your needs and create an account:


2. Create an Application

  1. On your account, go to Microsoft Entra ID section.
    ​

  2. Select "Enterprise Applications" section, click on + Add button, select Enterprise application option.
    ​

  3. In the Microsoft Entra App Gallery, click + Create your own application and fill in your Application's name.
    ​

  4. Select the option "Integrate any other application you don't find in the gallery (Non-gallery)" and click the Create button.
    ​


3. SAML configuration

  1. Contact your client project manager, with reference to this section of these instructions.

    🔔Your client project manager will initiate a request to our development team and will provide you with Entity ID and Reply URL shortly.

  2. After that, in your newly created application, select the "Single sign-on" section from the menu on the left, and select SAML.
    ​

  3. Click Edit (in the Basic SAML Configuration section).
    ​

  4. Fill out the Entity ID and Reply URL with the URL we provided to you.
    ​

  5. Click the Save button.



4. Attributes & Claims + Properties

During sign-in, claims send user information to the application.
​Claim values come from the user's properties in Microsoft Entra ID.

You may choose any property from the user profile as a claim's value source, but ensure that the claim names match.

Attributes & Claims

Claims can be edited in the "Attributes & Claims" section:

Claim

Possible values, description

email

used as the unique identifier for users in our system.

required

firstname

used when creating a new user/driver account.

required

lastname

used when creating a new user/driver account.

required

create_user


​

Web platform user creation.

  • 1 - will trigger the creation of a new user account on our platform when an unregistered user attempts to log in.
    ​
    The new user account will be of type 'user,' and initially, it will not have access to any section in the platform. Your company's administrator must configure user permissions in the platform's User settings.
    ​

  • 0 - when an unregistered user attempts to log in, the system will not trigger the creation of a new user account.

optional

create_driver

Triggers Driver app driver creation.

  • 1 - will trigger the creation of a new Driver account on our platform when an unregistered driver attempts to log in the Driver mobile application. The new user account will be of type 'driver'.

  • 0 - when an unregistered driver attempts to log in, the system will not trigger the creation of a new driver account.

optional

vehicle_group

Value should correspond to some vehicle group ID in our system and after driver creation this driver will have access to the vehicles that are in this group. Example: 68889

Find vehicle group IDs in:
​Settings -> Vehicle groups, in the ID column.
​

optional

driver_id

This is driver's identifier, which will be saved in IButton ID field in Driver's profile.
​

optional

User Properties

User properties are visible in the "Users and groups" section.

When adding users in Microsoft Azure, you need to choose and fill in the relevant properties.


5. Download and send "Metadata XML"

After completing all configuration steps above, download the Federation Metadata XML file and send it to us.

✅ We will then set up the application's SSO for your company on our side and notify you.


Additional Information

About driver creation (Driver App)

If you want to create drivers automatically (claim: create_driver = 1), it is mandatory to specify also vehicle_group. If vehicle_group is not specified for a new driver, driver account will not be created.

If you want to create an empty driver account (account that does not have access to any vehicles), use vehicle_group = 0.

SSO Login Flow Example (Driver App)

  1. The driver logs in using SSO, passing the following claims:

    • firstname

    • lastname

    • create_driver = 1

    • vehicle_group = 11890

    • driver_id = 12345678

  2. If the user does not already exist in our system, a new driver account is created.
    ​

  3. In the Driver app, the system automatically allows the user to access vehicles in the group specified by the vehicle_group claim.
    ​

  4. The driver_id claim is used as a driver identifier and is saved in the IButton ID field in our system.
    ​

  5. The driver is created and has access to the Driver mobile application.

If driver has no access to web

If a driver does not have access to our web platform and it is necessary, it can be enabled in Driver profile manually by company's manager.


​

Did this answer your question?