Microsoft 365 single sign-on

Give your team one-click, policy-controlled access to Microsoft 365 through Besecure.

About this integration

Besecure acts as the identity provider for Microsoft 365, so your people reach it from the Besecure launcher without a separate password, and access is granted through the same roles, groups and departments you already use.

What you get

  • One-click access from the employee app launcher
  • Access granted by role, group or department rather than per person
  • Access removed the moment someone leaves, in one place
  • Every sign-in recorded in the Besecure audit log

Setting it up

  1. Register Microsoft 365 as an application in Besecure and choose the protocol it supports.
  2. Exchange metadata: give Microsoft 365 your Besecure sign-in URL and signing certificate, and enter its reply/callback URL in Besecure.
  3. Assign the application to the roles, groups or departments that should have it.
  4. Test with a single account, then roll it out to everyone.

Exact field names differ between vendors and change over time, so follow Microsoft 365's own current SSO documentation for the vendor-side steps. If you get stuck, ask us — we do this daily.

Ready to put Microsoft 365 behind one sign-in?

Tell us about your organisation and we will connect your first applications with you.