Entra (Azure) Single Sign-On

Entra (Azure) Single Sign-On

Streamline Access with Entra Single Sign-On for Vibe.fyi. Scale effortlessly as your organisation grows and simplify user management through centralised control in Azure AD.


InfoExclusive to Enterprise users. On the Pro plan? Consider upgrading to unlock this feature.

Read First

Vibe SSO App Permissions

When you first log in using SSO, our app will request the following permissions:
  1. User.Read
  2. offline_access
  3. Group.Read.All
For all subsequent SSO logins, the app will only request:
  1. User.Read
  2. offline_access
Here’s what each permission is used for:
  1. User.Read: This allows us to retrieve the user's First Name, Last Name, Unique ID, and Email Address for authentication and user management purposes.
  2. offline_access: This enables us to periodically re-check the groups the validated users belong to. This ensures that any updates to user accounts in Entra (e.g., changes in group memberships) are reflected in the Vibe admin page automatically.
  3. Group.Read.All: This permission is only required during the first login. It allows us to fetch a list of groups to set up mappings between the user groups in our system and the corresponding Entra groups.
Notes
Importantly, we only retrieve groups that contain the word "vibe" to keep the scope of this request focused and relevant. By requesting these permissions, Vibe ensures secure and seamless SSO functionality while respecting the principle of minimal access.

Integration Guide

Step 1: Azure User Groups

Read First

Vibe is organised into two distinct areas:
  1. System Settings: Manage technical tasks such as setting up new locations, users and groups.
  2. Vibe Portal: Workspace for creating and managing content across all Vibe channels.
To establish a basic permission structure, start by adding two Azure groups: ‘Vibe-Admin’ and ‘Vibe-Publishers’. 
  1. Members of the ‘Vibe-Admin’ group have full access to the admin console and portal, with full publishing permissions in the Vibe Portal. 
  2. Members of the ‘Vibe-Publishers’ group will only have full publishing permissions in the Vibe Portal
Within the Vibe Portal, you can use groups to control publisher-level access to Slides, Playlists, and Locations. This can be structured in various ways:
  1. By Roles (e.g., HR, H&S, L&D), where specific teams manage content relevant to their function.
  2. By Locations, aligned with segmentation by country or site, which enables local publishing permissions. This way, onsite users can manage content relevant to their location, ensuring localised messaging across their channels. 
This structure offers flexibility, allowing tailored access control so local teams can manage and publish content specific to their roles or locations.

Add Groups

  1. Go to portal.azure.com and open the Groups section.

  2. Add the required user groups and assign users to each group.
    Alert
    You must include Vibe or Vibe.fyi in the group name.

Step 2: Enable SSO Login

Next, log into your vibe portal using an admin-level Vibe user account, then follow these steps to activate Azure AD SSO login for your Vibe.fyi application.
  1. Open System Settings and navigate to Site Settings> Account Security
  2. Toggle the Enable Azure AD SSO login
  3. In the Email Domain(s) field, enter the valid email domain linked to each users work email (e.g.: @myonlinebusiness.com) 
  4. Optional - Update the Login Button Text as needed

  5. Click [Enable SSO login and set up group mapping]. 

Step 3: Map Azure & Vibe.fyi user groups 

  1. In the Azure AD Group Mapping window, review the Action Required notice and ensure your Azure App Registration includes the updated Vibe redirect URL.

  2. Click Fetch a list of Azure groups to connect Vibe to Microsoft Graph and retrieve the available Azure AD groups from your tenant.
  3. In the Azure AD Group Mapping window, select the appropriate Azure AD group from the Select Azure group dropdown.

  4. Click Save Mapping to save the configuration.

Step 4: Log in with your Microsoft account

Notes
Permissions are needed to grant admin content for the Vibe.fyi SSO app. Learn more on the Microsoft Learn website where it is stated that in order to grant tenant-wide admin consent, you need a Microsoft Entra user account with one of the following roles:
  1. Privileged Role Administrator, for granting consent for apps requesting any permission, for any API.
  2. Cloud Application Administrator or Application Administrator, for granting consent for apps requesting any permission for any API, except Microsoft Graph app roles (application permissions).
  3. A custom directory role that includes the permission to grant permissions to applications, for the permissions required by the application.
When step 1 and 2 (above) are complete, your Vibe portal and admin console login forms will be replaced with an option to log in with a Microsoft account.
  1. Open your Vibe.fyi portal or admin console
  2. Click [Log in with your Microsoft account] and login with a Microsoft account that has permission to access all Azure groups.
     
  3. You may get a “Need admin approval” message at this point, if you see this message…
    1. Ask an Azure administrator to log into portal.azure.com, go to Enterprise applications and find Vibe site’s customer SSO login
    2. Open the Permissions pane, and click the Grant admin content for (your organisation name) button
    3. Read the list of requested permissions and click the Accept button
    4. Once this this admin consent has been granted, open your Vibe.fyi portal or admin console and click the [Log in with your Microsoft account] button again
  4. When you see the "You do not belong to the required Azure groups to be able to log in" message, send the name of your primary Azure 'administrator' group to your Vibe.fyi support contact (or email support@vibe.fyi) and they will perform the initial Azure / Vibe.fyi group mapping.
Info
When your Vibe.fyi support contact confirms that the initial grouping is complete, any user in the primary admin group can then login using their Microsoft account and proceed to step 4 below.
Why are users showing as inactive in vibe portal?
If a user has not logged into Vibe for some time they will be marked as inactive, However, they should still be able to log in without any issue.

Managing SSO Users

Add Users

To add a new Vibe portal user, create a new Microsoft account (or choose an existing one) and add the user to the relevant group in portal.azure.com.

Remove Users

To remove a users access to the Vibe.fyi portal, deactivate/delete their Microsoft account OR remove them from the Azure user group that is mapped to a Vibe.fyi user group.
This update will take effect within 30 minutes after which the user will not be able to log in to Vibe.

Mapping Vibe Groups to Azure AD Groups

After SSO has been set up, administrators can create additional Vibe groups and map them to Azure AD groups without needing to reconfigure the SSO integration. This makes it easy to manage permissions and automatically assign users to the appropriate Vibe group based on their Azure AD membership.

To map a Vibe group to an Azure AD group:
  1. Go to Accounts & Access > Groups.
  2. Select an existing Vibe group or click Create Group to create a new one.
  3. Configure the group's permissions as required.
  4. In the Azure Group Mapping field, select the Azure AD group that should be linked to the Vibe group.
  5. Click Save.