Your team can sign in with their Microsoft work accounts. You register an app in your own Microsoft tenant, so you decide who is assigned to it and you hold its secret. Only the workspace owner can set this up.
Before you start
Microsoft sign-in comes with the Practice and Firm plans.
You need to be able to create app registrations in Microsoft Entra.
Your own Debut address must be on your firm’s own domain.
Register the app in Microsoft Entra
In Debut, open Settings and choose the Sign-in tab. Find the Sign in with Microsoft card.
In Microsoft Entra, open App registrations and create a single-tenant app.
Under Authentication, add a Web platform. Use the Redirect URI shown on the card. It is https://login.baselinezero.io/sign-in/entra/callback.
Under Certificates & secrets, create a client secret. Note the expiry date Entra shows beside it.
Under API permissions, choose Add a permission, then Microsoft Graph, then Delegated permissions. Add openid, profile and email. Then choose Grant admin consent for your tenant.
Using the Teams integration? Add two more delegated permissions in the same place: Calendars.ReadWrite and offline_access. Then choose Grant admin consent again. Debut uses them to see when you are busy and to put each booking on your calendar.
This is the only redirect URI the app needs. Calendar connections use it too.
Enter the app in Debut
Paste the Directory (tenant) ID and the Application (client) ID.
Paste the Client secret.
Enter the date in Secret expires on.
Choose Save.
The secret is kept in a vault. It is never kept in Debut’s database, and it is never shown again.
Verify the app
After you save, the card says Saved, not yet verified.
Choose Sign in with Microsoft to verify.
Sign in with your own Microsoft account. Use a member account of your tenant on your firm’s own domain. A guest or personal account is refused.
This proves the app is set up. It also claims your email domain for this workspace. A public mailbox domain, or a domain another workspace already holds, is refused.
Once verified, the card says Connected. Everyone on your Team list with an address on your domain can now sign in with Microsoft. Signing in never adds anyone to the team on its own.
Require Microsoft for everyone
Turn on Require Microsoft for everyone to turn passwords off for your domain. Anyone with an address on your domain is sent to Microsoft at sign-in. Debut refuses the switch if it would lock you out. The owner can still sign in with a password, from a link under the Microsoft button.
Accounts on first sign-in
This decides what happens when someone on your domain signs in with Microsoft but is not on the Team list.
Off · only people already on the team turns them away.
On · create their account as read only creates their account as read only, with no clients. It takes no seat.
Choose Save. To give a new account a role and clients, open their page under Team.
Replace the secret before it expires
Every owner and admin is emailed 30 and 15 days before the secret expires. From 7 days out the email comes daily, until a new secret is saved.
Create a new client secret in Entra.
In Debut, open The app’s ids, secret and redirect URI on the card.
Paste the new Client secret and update Secret expires on.
Choose Save changes.
If your plan changes
On a plan without Microsoft sign-in, members are moved to passwords. At their next Microsoft sign-in, each member sets a password and adds an authenticator. Microsoft sign-in turns off once everyone has. Your app and its settings are kept. On a plan that includes it again, an owner or admin chooses Turn Microsoft sign-in back on.
Disconnect Microsoft
Choose Disconnect Microsoft on the card. Everyone signs in with a password again.
Members who sign in with Microsoft for the first time are always read only with no clients. Give them a role on their page under Team.
Related guides
Integrations in Debut
Connect your Microsoft calendar and Teams



