Skip to content
Teammate Help Centre

Approving Teammate for Microsoft 365 sign-in

System AdministrationFor adminsVerified 23 Sep 20264 min

Before anyone on your team can sign in to Teammate with their Microsoft 365 account, someone with Microsoft administrator rights has to approve Teammate for your organisation. It only has to be done once — after that, every Microsoft sign-in for your company works, and you can create Single Sign-On users.

Before you start

Single Sign-On has to be switched on for your company first. If you don’t see a Single Sign-On connections section under System Administration → General, email support@teammateapp.com and we’ll turn it on.

Who can approve Teammate

You need to be a Microsoft 365 Global Administrator, or hold a role your organisation has given the right to grant admin consent for apps. If that isn’t you, you don’t need to track one down yourself — Teammate can send them a link (see below).

Open the Connect box

  1. Go to System Administration → General.
  2. Find the Single Sign-On connections section. The Microsoft 365 card shows Not activated yet until someone approves Teammate.
  3. Click Connect Microsoft. The Activate Microsoft sign-in box opens.

Two ways to approve

If you…Choose
are a Microsoft 365 administrator yourselfI’m our Microsoft administrator — approve now. Teammate takes you straight to Microsoft’s approval screen.
are not an administratorI’m not — get a link for our IT administrator. Teammate shows a copyable link (valid 7 days) with Copy link and Email this link buttons — no Teammate login needed on their end.

What Microsoft will ask for

Whichever route is used, the Microsoft screen that opens asks for exactly one thing: permission to sign your people in and read their basic profile — name and work email. Nothing else. Teammate never asks for access to files, mail, calendars or any other Microsoft 365 data.

The verification sign-in

Straight after the administrator approves, Teammate asks them to sign in once more with their Microsoft account. This confirms the approval actually belongs to your organisation before Teammate turns the connection on — it’s automatic and takes a few seconds.

Once it’s connected

The Microsoft 365 card now shows Connected, your organisation, and a line such as “Approved by ••••@yourcompany.com on 23 Sep 2026”. From here your team can sign in with Microsoft, and you can create Single Sign-On users in Human Resources. A Remove button is there if you ever need to disconnect — Teammate asks you to confirm first, and warns that no new Single Sign-On users can be created until your organisation approves Teammate again.

Already approved? Test sign-in

If your organisation already approved Teammate some other way — or you’re not sure — open the Connect box and choose Already approved? Test sign-in. Teammate tries a Microsoft sign-in there and then; if it succeeds, the connection is recorded immediately with no separate approval step. If Microsoft still shows a consent screen, your organisation genuinely hasn’t approved Teammate yet — use one of the two routes above instead.

Where else you’ll see this

Until your organisation is connected, anywhere a Login Type is chosen — the Add Employee wizard, an employee’s Credentials, or HR Admin → User Access Setting — shows an amber Not activated yet badge with an Activate it in System Administration link. Selecting Microsoft sign-in there is still possible, but saving is refused until the connection above is made.

The SSO only switch

Below the two cards is an SSO only switch. Turning it on removes the Username option when adding or editing users, so every new login must be Microsoft or Google. It shows how many people currently sign in with a username, and existing username users keep signing in exactly as before — the switch only changes what’s offered when adding or editing someone.

Troubleshooting

Was this helpful?

Keep going

Related articles