Montr can be integrated with your organisation's Microsoft Entra ID (Azure Active Directory), allowing users to sign in using their existing Microsoft work account.
The application never sees passwords and cannot change anything in your Microsoft 365 environment.
How is it set up?
Before you start make sure:
Your organization uses Microsoft Entra ID (Azure AD), e.g. through Microsoft 365.
Staff sign in with accounts that are members of your own organization (guest accounts invited from other organizations are not supported).
Your email domain (e.g. `@yourcompany.com`) is a verified domain in your Microsoft environment - if you use Microsoft 365 with your own domain, this is already the case.
You have access to one of the Cloud App Admin roles for one approval step:
Global Administrator
Privileged Role Administrator
Cloud Application Administrator
Application Administrator
To enable SSO, you will need:
Send Montr your Microsoft Tenant ID
We link your Report X organization to your Microsoft environment using your Tenant ID (also called Directory ID) - a value that looks like
aaaabbbb-1111-2222-3333-ccccddddeeeeGo to entra.microsoft.com (or portal.azure.com → Microsoft Entra ID).
On the Overview page, copy the value shown as Tenant ID.
Send it to Montr, as SSO will not work until we have registered this value for you.
At this point users can access the "Sign in with Microsoft" button and they can sign-in using SSO, but they need to consent for SSO, pending organization-wide permissions.
OPTION A - if as a Cloud App Admin you have access to our Report X CMS administrator panel.
Approve the Montr application and grant permissions on behalf of everyone during first sign-in (recommended).
Open the Report X panel login page and click Sign in with Microsoft.
Microsoft shows a consent screen listing the requested permissions for SSO:
Sign you in and read your basic profile, to identify the user and match them to their Report X account.
Click Accept
At this point users can access the "Sign in with Microsoft" button and they can sign-in using SSO, but they need to consent for SSO - Each user sees the Microsoft consent screen once, on their first sign-in; this works only if your organization allows users to consent to applications (if user consent is disabled in your tenant, or you want to grant global permissions, use Option B)OPTION B - if as a Cloud App Admin you DON'T HAVE access to our Report X CMS administrator panel.
If you want to maintain consent per user:
Do nothing - permission to Single-Sign on will be accepted per user, upon users first log in.
At this point users can access the "Sign in with Microsoft" button and they can sign-in using SSO, but they need to consent for SSO - Each user sees the Microsoft consent screen once, on their first sign-in; this works only if your organization allows users to consent to applications (if user consent is disabled in your tenant, use below instruction)
If you want to grant permission for the whole organization up front:
Optionally you can Approve the Montr application and grant permissions on behalf of everyone on your Cloud App panel.Open this link, replacing {tenant-id} with your Tenant ID: https://login.microsoftonline.com/{tenant-id}/adminconsent?client_id=c718f393-0df7-49df-bf90-af3b13096df5
Microsoft shows a consent screen listing the requested permissions for SSO (Sign you in and read your basic profile). The consent applies to your entire organization.
Click Accept.
After accepting, the browser may land on an unrelated or blank page - the consent has still been registered and the tab can simply be closed.
At this point users can access the "Sign in with Microsoft" button and they can sign-in using SSO, without a need to consent again since you already granted permissions globally.
