How do I set up Microsoft sign-in (SSO) for Passbeam?
There are two ways to do it, and you can use both. Option 1 links your own Microsoft account to your own Passbeam sign-in, so you can sign in with Microsoft. It only affects you. Option 2 connects your organisation's Microsoft Entra ID, so your whole team signs in with Microsoft, and who gets in (and as what) is set in Entra. Both are free. At Passbeam we are against SSO tax.
Option 1 - link your own Microsoft account. Go to My account → Passkeys & sign-in and press Link a Microsoft account.
Enter your Passbeam password, press Sign in with Microsoft and sign in with your work account. You'll come straight back to Passbeam. From then on you can use Sign in with Microsoft on the sign-in page. Your password, passkeys and authenticator app all keep working too.
Option 2 - connect your organisation, with roles from Entra. Go to Organisation → Single sign-on and press Connect your organisation. You need to be an Owner or Admin in Passbeam. There are three steps and they need doing in order.
Step 1 - approve Passbeam. Press Approve in Microsoft. This needs a Global Administrator in your Microsoft 365, and it's once per organisation.
Step 2 - give people a role in Entra. In the Microsoft Entra admin centre, go to Enterprise applications → Passbeam → Users and groups → Add user/group. Pick the person, then pick Owner, Admin or Helpdesk as the role, and press Assign. Give yourself Owner or Admin first, as step 3 needs it.
Enterprise applicationsPassbeam
Passbeam | Users and groups
| Display Name | Object Type | Role assigned |
|---|---|---|
| Alex Morgan | User | Owner |
| Sam Patel | User | Admin |
| Chris Lee | User | Helpdesk |
Enterprise applicationsPassbeamUsers and groups
Add Assignment
Users
1 user selected (Sam Patel)
Select a role
Admin
Only people with a role can sign in, and the role they get in Passbeam is the one assigned directly within Entra. You can assign a group rather than people one at a time, but Entra only allows that with Entra ID P1.
Step 3 - connect. Back in Passbeam, enter your Passbeam password and press Sign in with Microsoft. Your organisation then shows on the Single sign-on page.
Your team don't need inviting. Anyone with a role just presses Sign in with Microsoft on the sign-in page, and they're added the first time they do. Their name, email and role come from Entra and are updated every time they sign in, so change someone's role in Entra and it changes in Passbeam at their next sign-in. Take the role away and they can't sign in.
Only allowing Microsoft - Require Microsoft sign-in. If you want everyone to sign in with Microsoft and nothing else, turn on Require Microsoft sign-in on the same page. Passwords and passkeys then stop working for everyone except Owners. Owners keep theirs on purpose, so you can still get in if Microsoft is having a bad day.
You have to be signed in with Microsoft to turn it on. If you signed in with a password or passkey the button is greyed out, so sign out, sign back in with Sign in with Microsoft, and it'll be there.
Before it turns on, it shows you anyone who'll lose access. That's anyone who still signs in with a Passbeam password and hasn't linked a Microsoft account. Either get them to link one first (Option 1), or remove them and give them a role in Entra instead. Tick the box and press Require Microsoft sign-in.
Anyone signed in with a password or passkey at that point is signed out. While it's on you can't invite people by email, apart from Owners - you add them in Entra instead. To turn it off, press Stop requiring Microsoft sign-in. Any Owner or Admin can do that, however they signed in.
If someone tries their password while it's on, they'll see "Your organisation requires you to sign in to Passbeam with Microsoft. Use Sign in with Microsoft instead." Disconnecting your last organisation turns it off as well.
Related questions
- What happens when somebody leaves?
- Can I stop one device getting on without revoking its certificate?
- Can I restrict a network to one group?
- Can I refuse devices that Intune says are not compliant?
- Does this cover wired as well as wireless?
- Which switches do 802.1X properly, and which ignore re-authentication?
- How do personal or BYOD devices get on the network?
- How can I see which devices are connected right now?
- Sessions are empty. What do I need to turn on?
- Why does a wired session show no IP address or data usage?
Still stuck? Ask us, or read the rest of the knowledge base.