RMM Labs
Integrations 4 min read 28 September 2026 By Fred

How to set up Microsoft (Entra ID) single sign-on in Xcellerate OPS

Add a Microsoft sign-in button to your OPS login page. Use the one-click Entra setup or register the app yourself.

How to set up Microsoft (Entra ID) single sign-on in Xcellerate OPS

Connect Microsoft Entra ID to Xcellerate OPS and your team signs in with the Microsoft 365 work account they already use. Your login page gets a Microsoft sign-in button, for staff and for portal users who have an account. OPS can create the app registration in your Entra tenant with one click, or you can register the app yourself.

TL;DR

  • Admins add the Microsoft SSO card under Settings → Data and security → Integrations → Authentication.
  • One-click: an Entra Global Administrator signs in and OPS creates and enables the app registration. Manual: paste your own client ID and secret.
  • OPS matches the Microsoft email address to an existing user. No accounts are created automatically.

Before you start

  • You are an admin of your OPS workspace. Only admins can change these settings.
  • For the one-click setup: someone who can sign in as a Global Administrator of your Entra tenant. Microsoft asks that person to consent to Application.ReadWrite.All and DelegatedPermissionGrant.ReadWrite.All (delegated permissions).
  • For the manual setup: access to Entra ID → App registrations in the Azure portal.
  • The people who will sign in already exist as users in OPS, with the same email address as their Microsoft account.

Step 1: add the Microsoft SSO card

  1. Go to Settings → Data and security → Integrations.
  2. Drag Microsoft SSO from the catalog on the right into the Authentication category, or click it.
  3. The card Allow sign-in with Microsoft appears.

The Integrations page in OPS settings The Integrations page with empty categories (Mailbox, Authentication, Payments, Billing) and the catalog of available integrations on the right.

  1. On the card, click Set up automatically.
  2. Read the dialog. OPS will create an app registration named after your workspace URL, with a client secret valid for 24 months and the correct redirect URI, and then switch SSO on.
  3. Click Continue to Microsoft sign-in, sign in as a Global Administrator and accept the consent.
  4. You return to Integrations with the message "Microsoft 365 SSO was provisioned in your Entra tenant and enabled". Microsoft sign-in works straight away.

Step 2, option B: manual app registration

  1. In Entra ID, register a new application with a Web redirect URI. Use the URI shown below the cards next to Register this redirect URI with each provider. It follows the pattern https://auth.<platform-domain>/sso/microsoft/callback. One URI serves all workspaces.
  2. Create a client secret. Sign-in requests the scopes openid email profile.
  3. On the card, paste the Application (client) ID and the Client secret.
  4. Switch on Enable on the login page and click Save. You see "Sign-in options saved."

Step 3 (optional): profile pictures

Once a provider is enabled, you can switch on Profile pictures from the sign-in account. It saves instantly. For Microsoft, also switch on Include Microsoft 365 pictures and click Save. Sign-in then also requests the Microsoft Graph permission User.Read. If your tenant requires admin consent, grant it on the app registration first.

What happens after you connect

  • The login page shows a Microsoft button. OPS matches the Microsoft email address to an existing user in your workspace. Staff land in the app, portal users in the client portal.
  • SSO counts as a strong sign-in factor, so a workspace that requires passkeys still accepts it. Read more about security and access control.
  • With pictures on, OPS fetches the directory photo in the background after sign-in. It only fills a gap: an uploaded picture comes first, then Gravatar, then the Microsoft 365 photo. It never replaces a picture someone uploaded or removed, and it checks again at most every 30 days.

Good to know

  • Create users in OPS first. Disabled (offboarded) users are refused.
  • The one-click client secret expires after 24 months. Running Set up automatically again creates a new app registration.
  • The one-click app only has consent for openid, profile and email. Microsoft 365 pictures add User.Read, which can trigger a consent prompt or be blocked until an admin grants it.
  • The Microsoft picture setting is only saved when Microsoft SSO and profile pictures are both on.
  • The client secret field is write-only. Leave it blank to keep the saved secret.
  • You can only remove a card after you Disable it. Removing it also clears the stored client ID and secret.

Troubleshooting

  • "No account exists in this workspace for that identity." There is no active OPS user with that email address. Invite the person or check the address.
  • "Your identity provider did not return an email address." The Microsoft account has no email address or UPN.
  • "Sign-in could not be completed. Please try again." The sign-in took longer than 10 minutes or the code exchange failed. Start again.
  • "Automatic SSO setup failed: …" Microsoft's own reason follows, for example "The sign-in was cancelled."

Get started

Want your team to sign in with the account they already use? Get started for free and set up Microsoft sign-in from Settings. See all EU integrations too.

Frequently asked questions

Does OPS create an account at the first Microsoft sign-in?
No. OPS matches the Microsoft email address to an existing, active user in your workspace, so invite users first.
Who can run the one-click setup?
A workspace admin starts it. The Microsoft sign-in during setup must be done by a Global Administrator of your Entra tenant.
Does Microsoft sign-in work when passkeys are required?
Yes. SSO counts as a strong sign-in factor, so workspaces that require passkeys accept it.
Sources: Verified against the Xcellerate OPS source code by the product team on 2026-09-28. Feature pages: https://rmmlabs.io/en/products/ops/features/integrations-eu; https://rmmlabs.io/en/products/ops/features/security-access. Screenshots: real captures of the Xcellerate OPS demo workspace, Sep 2026.

Ready to solve time registration compliance?

Xcellerate OPS covers Belgian 2027 time registration requirements out of the box — no extra module needed.

Related articles