This guide walks your organization's IT administrator through configuring Azure Entra ID (formerly Azure Active Directory) as a single sign-on (SSO) provider for MeetOne.
Prerequisites
- An Azure account with access to Azure Entra ID (Azure Active Directory).
- Administrator permissions to register applications in Azure Entra ID.
- Your MeetOne tenant domain (for example
https://acme.meetone.io).
SSO is for sign-in only, not sign-up. Users must already have an account in MeetOne with the same email address as their Azure Entra ID account.
Step 1: Register an Application in Azure Portal
- Go to the Azure Portal.
- Navigate to Azure Active Directory (or Microsoft Entra ID).
- In the left sidebar, click App registrations.
- Click + New registration.
Fill out the registration form:
- Name: Enter a descriptive name (for example, "MeetOne SSO").
- Supported account types: Choose one of the following, based on your organization's requirements:
- Accounts in this organizational directory only — single tenant (most common)
- Accounts in any organizational directory — multi-tenant
- Redirect URI:
- Select Web from the dropdown.
- Enter
https://acme.meetone.io/auth/entra_id/callback, replacingacme.meetone.iowith your actual MeetOne tenant domain.
Click Register to create the application.
Step 2: Get the Client ID and Tenant ID
After registration, you'll land on the application's Overview page.
- Application (client) ID: A GUID that looks like
12345678-1234-1234-1234-123456789abc. Copy this value. - Directory (tenant) ID: A GUID that looks like
87654321-4321-4321-4321-cba987654321. Copy this value.
You'll send both of these to MeetOne support in Step 5.
Step 3: Create a Client Secret
- In the left sidebar of your application, click Certificates & secrets.
- Click the Client secrets tab.
- Click + New client secret.
- Description: Enter a description (for example, "MeetOne Production Secret").
- Expires: Choose an expiration period (6, 12, or 24 months, or a custom date).
- Click Add.
Copy the secret's Value immediately after creating it — it is only shown once. If you navigate away before copying it, you'll need to create a new secret. Also set a calendar reminder to rotate the secret before it expires; MeetOne cannot do this for you.
Step 4: Configure API Permissions
For basic SSO authentication, the default permissions are usually sufficient.
- In the left sidebar, click API permissions. The default permission User.Read should already be listed.
- If you need additional permissions, click + Add a permission.
Recommended Microsoft Graph → Delegated permissions for SSO:
User.Read— read user profile (default, sufficient for SSO)email— access the user's email addressopenid— sign users inprofile— view the user's basic profile
After adding permissions, you may need to click Grant admin consent for [Your Organization].
Step 5: Send Your Credentials to MeetOne
MeetOne configures SSO centrally for each tenant, so the values from Steps 2 and 3 aren't entered directly by your organization.
- Share the following values securely with MeetOne support (support@meetone.io):
- The Client ID (Application ID)
- The Client Secret value
- The Tenant ID (Directory ID)
- Your MeetOne tenant domain (for example
acme.meetone.io)
- MeetOne will enable and configure SSO for your account and confirm once it's live.
Share these credentials over a secure channel (for example, an encrypted attachment or a password manager sharing link) rather than plain email whenever possible.
Step 6: Test the Login
- Once MeetOne support confirms SSO is enabled for your tenant, navigate to your organization's MeetOne sign-in page.
- You should see a "Sign in with SSO" button.
- Click the button to start SSO authentication.
- You'll be redirected to Microsoft's login page.
- After signing in successfully, you'll be redirected back to MeetOne.
Testing checklist
- [ ] The SSO button appears on the sign-in page.
- [ ] Clicking the button redirects to Microsoft login.
- [ ] A successful login redirects back to MeetOne.
- [ ] The correct account is signed in.
- [ ] Users without a matching MeetOne account see an appropriate error.
- [ ] Deactivated MeetOne accounts cannot sign in via SSO.
Restricting Access to Specific Users (Optional)
By default, all users in your Azure Entra ID directory can authenticate against your application. To restrict access to specific users or groups:
- Go to your app registration, then open Enterprise applications and select your application.
- In the left sidebar, click Properties.
- Set Assignment required? to Yes, then click Save.
- In the left sidebar, click Users and groups.
- Click + Add user/group, select the users to assign, then click Assign.
Only assigned users can now authenticate via SSO.
Troubleshooting
"Redirect URI mismatch" error
Problem: After clicking SSO, you see an error about a redirect URI mismatch.
Solution:
- Verify the redirect URI in Azure matches exactly:
https://acme.meetone.io/auth/entra_id/callback. - Check for trailing slashes or typos.
- Ensure the protocol is
https://.
"User not found" error
Problem: SSO succeeds, but the user sees "No user account found with this email address."
Solution:
- SSO only works for users who already have a MeetOne account.
- Create the user's MeetOne account first (for example, via the MeetOne admin panel), using the same email address as their Azure Entra ID account.
- Verify the email address matches exactly (case-insensitive).
"Authentication failed" error
Problem: A generic authentication failure.
Solution:
- Contact MeetOne support to verify the Client ID, Client Secret, and Tenant ID configured for your tenant are correct.
- Check whether the client secret has expired in Azure Portal.
- Ensure the Azure app registration is not disabled.
- Review the Azure app registration's API permissions.
Client secret expiration
Problem: SSO stops working after several months.
Solution:
- Client secrets expire. Check the expiration date in Azure Portal under Certificates & secrets.
- Create a new client secret before the old one expires, and send the updated value to MeetOne support (support@meetone.io) so we can update your configuration.
Admin consent required
Problem: Users see a "Need admin approval" message.
Solution:
- In Azure Portal, go to API permissions.
- Click Grant admin consent for [Your Organization]. This allows all users to authenticate without individual consent prompts.
Security Best Practices
- Rotate secrets regularly — set calendar reminders to rotate client secrets before they expire.
- Use separate applications — consider separate Azure app registrations for production versus staging or test environments.
- Monitor access — regularly review sign-in logs in Azure Portal.
- Restrict permissions — only request the minimum API permissions needed.
- Secure your secrets — never share client secrets over unencrypted channels or commit them anywhere.
- Review user access — periodically audit which users have SSO access, using the assignment feature described above.
Additional Resources
Questions? Contact us at support@meetone.io.