Skip to main content

Set up Microsoft sign-in

Let your team sign in with Microsoft through an app in your own tenant.

Your team can sign in with their Microsoft work accounts. You register an app in your own Microsoft tenant, so you decide who is assigned to it and you hold its secret. Only the workspace owner can set this up.

Before you start

  • Microsoft sign-in comes with the Practice and Firm plans.

  • You need to be able to create app registrations in Microsoft Entra.

  • Your own Debut address must be on your firm’s own domain.

Register the app in Microsoft Entra

  1. In Debut, open Settings and choose the Sign-in tab. Find the Sign in with Microsoft card.

  2. In Microsoft Entra, open App registrations and create a single-tenant app.

  3. Under Authentication, add a Web platform. Use the Redirect URI shown on the card. It is https://login.baselinezero.io/sign-in/entra/callback.

  4. Under Certificates & secrets, create a client secret. Note the expiry date Entra shows beside it.

  5. Under API permissions, choose Add a permission, then Microsoft Graph, then Delegated permissions. Add openid, profile and email. Then choose Grant admin consent for your tenant.

Using the Teams integration? Add two more delegated permissions in the same place: Calendars.ReadWrite and offline_access. Then choose Grant admin consent again. Debut uses them to see when you are busy and to put each booking on your calendar.

This is the only redirect URI the app needs. Calendar connections use it too.

The Sign in with Microsoft card with the redirect URI and the app fields

Enter the app in Debut

  1. Paste the Directory (tenant) ID and the Application (client) ID.

  2. Paste the Client secret.

  3. Enter the date in Secret expires on.

  4. Choose Save.

The secret is kept in a vault. It is never kept in Debut’s database, and it is never shown again.

Verify the app

After you save, the card says Saved, not yet verified.

  1. Choose Sign in with Microsoft to verify.

  2. Sign in with your own Microsoft account. Use a member account of your tenant on your firm’s own domain. A guest or personal account is refused.

This proves the app is set up. It also claims your email domain for this workspace. A public mailbox domain, or a domain another workspace already holds, is refused.

The card after saving, with the Sign in with Microsoft to verify button

Once verified, the card says Connected. Everyone on your Team list with an address on your domain can now sign in with Microsoft. Signing in never adds anyone to the team on its own.

Require Microsoft for everyone

Turn on Require Microsoft for everyone to turn passwords off for your domain. Anyone with an address on your domain is sent to Microsoft at sign-in. Debut refuses the switch if it would lock you out. The owner can still sign in with a password, from a link under the Microsoft button.

Accounts on first sign-in

This decides what happens when someone on your domain signs in with Microsoft but is not on the Team list.

  • Off · only people already on the team turns them away.

  • On · create their account as read only creates their account as read only, with no clients. It takes no seat.

Choose Save. To give a new account a role and clients, open their page under Team.

The connected card with the Require Microsoft switch and Accounts on first sign-in

Replace the secret before it expires

Every owner and admin is emailed 30 and 15 days before the secret expires. From 7 days out the email comes daily, until a new secret is saved.

  1. Create a new client secret in Entra.

  2. In Debut, open The app’s ids, secret and redirect URI on the card.

  3. Paste the new Client secret and update Secret expires on.

  4. Choose Save changes.

If your plan changes

On a plan without Microsoft sign-in, members are moved to passwords. At their next Microsoft sign-in, each member sets a password and adds an authenticator. Microsoft sign-in turns off once everyone has. Your app and its settings are kept. On a plan that includes it again, an owner or admin chooses Turn Microsoft sign-in back on.

Disconnect Microsoft

Choose Disconnect Microsoft on the card. Everyone signs in with a password again.

Members who sign in with Microsoft for the first time are always read only with no clients. Give them a role on their page under Team.

Related guides

  • Integrations in Debut

  • Connect your Microsoft calendar and Teams

Did this answer your question?