This article provides instructions for setting up an Azure AD (OIDC) connection and test the full login flow in Traffio.
Have these ready before you start:
Azure/Entra tenant admin access
Azure Tenant (Directory) ID (a GUID)
Find your Tenant ID (Directory ID)
Navigate to Azure Portal
Search and open Microsoft Entra ID
On the Overview page, look for Tenant ID (sometimes shown as Directory ID)
Copy it (it looks like a GUID, e.g. 3f2c1a11-....-....-....-............)
View SSO Settings inside Traffio
Navigate to My Company on the sidebar
Click on SSO Tenants tab
You will see a list of all configured SSO tenants with:
Tenant name
Status (Active/Inactive)
Directory Key (masked for security)
Session Duration ( How long users stay logged in before needing to re-authenticate)
Add a New Tenant inside Traffio
Navigate to My Company on the sidebar
Select the SSO Tenants tab
Click the +Add Tenant button
Fill in the form:
- Tenant Name: A friendly name (e.g., "My Company SSO")
- Directory Key: Your Microsoft Azure AD Tenant ID (UUID format)
- Description (Optional)Click Save
Activate/Deactivate Tenant inside Traffio
Activate a Tenant
Navigate to My Company on the sidebar
Select the SSO Tenants tab
Select the desired Tenant
Toggle the Active switch to ON
Click Save
Deactivate a Tenant
Navigate to My Company on the sidebar
Select the SSO Tenants tab
Select the desired Tenant
Toggle the Active switch to OFF (A confirmation message will appear)
Click Confirm to deactivate
Their SSO connection is kept - if you reactivate the tenant, they can log straight back in without a new invitation
Remove Access without Deactivating
Use this if you need to remove one person's SSO access without affecting anyone else or deactivating the whole tenant.
Navigate to People on the sidebar
Select the desired Person Profile
Click Disconnect SSO
After disconnecting:
Their SSO link is removed immediately
You can send them a new SSO invitation at any time to reconnect
Send SSO Invitation
You can send SSO invitations to users so they can link their Microsoft account.
Send to a Single User
Navigate to People on the sidebar
Select the desired Person
Click Send SSO Invitation button
Click Send
Send to All Users (Bulk)
Navigate to My Company on the sidebar
Select the SSO Tenants tab
Click Send Invitations button
Confirm to send invitations to all active users
What the User Receives
The user will receive an email with:
Their organization name
A button to accept the invitation
Accept SSO Invitation
Open the invitation email
Click the Accept Invitation button (You will be redirected to Microsoft login)
Sign in with your Microsoft work account
Make sure the email matches your Traffio account email
After successful login, you are linked!
If You See an Error
Error | Solution |
"Invitation expired" | Ask your administrator to send a new invitation |
"Session expired" | Try clicking the invitation link again |
Login with SSO
Once your account is linked, you can login using SSO:
Navigate to the Traffio login page
Click Sign in with Microsoft (or SSO button)
Select your Microsoft account
You will be logged in automatically
Admin SSO Data
Only users with Admin access level can:
Configure SSO tenants
Activate/deactivate tenants
View SSO status for all users in the company
Frequently Asked Questions
Q: Can I have multiple SSO tenants?
A: Yes, you can configure multiple Microsoft Azure AD tenants for different organisations.
Q: What happens if I deactivate a tenant?
A: Users linked to that tenant will be notified and will need to use password login until a new invitation is sent.
Q: Can a user be linked to multiple tenants?
A: Yes, if your company has multiple Azure AD tenants, users can be linked to any active tenant.
Q: How long is the invitation valid?
A: Invitations expire after 7 days. If expired, send a new invitation.
Q: Where can I see a user's SSO status?
A: Go to the user's profile in People > person name , then check the Person tab for SSO information.