Microsoft 365 single sign-on
Give your team one-click, policy-controlled access to Microsoft 365 through Besecure.
About this integration
Besecure acts as the identity provider for Microsoft 365, so your people reach it from the Besecure launcher without a separate password, and access is granted through the same roles, groups and departments you already use.
What you get
- One-click access from the employee app launcher
- Access granted by role, group or department rather than per person
- Access removed the moment someone leaves, in one place
- Every sign-in recorded in the Besecure audit log
Setting it up
- Register Microsoft 365 as an application in Besecure and choose the protocol it supports.
- Exchange metadata: give Microsoft 365 your Besecure sign-in URL and signing certificate, and enter its reply/callback URL in Besecure.
- Assign the application to the roles, groups or departments that should have it.
- Test with a single account, then roll it out to everyone.
Exact field names differ between vendors and change over time, so follow Microsoft 365's own current SSO documentation for the vendor-side steps. If you get stuck, ask us — we do this daily.