Appearance
Sign in with Microsoft Entra ID
Your users can sign in to the Learning Platform with their Microsoft work account instead of an e-mail address and password. You switch it on yourself in Settings → Account Settings, under Sign-in Methods.
What Entra ID does — and what it does not
Entra ID is used for authentication only. There is no directory synchronization between your Entra ID and your account with us.
| Who can sign in | Decided in your Entra ID. That governs sign-in only: it neither creates nor removes users in your account. |
| Name | Taken over from Entra ID once, only when the user does not exist in your account yet and is created on first sign-in. Existing users keep their name and data. |
| Later changes in Entra ID | Not adopted. A user renamed in Entra ID keeps the name stored in your account. |
| User blocked or deleted in Entra ID | We do not learn about it — the sign-in fails at Microsoft. In your account nothing changes; the user has to be deactivated or deleted separately. |
Requirements
- A Microsoft Entra ID tenant.
- A one-time admin consent for our application, confirmed with an Entra ID administrator account. The Microsoft Entra ID App Registration link under Sign-in Methods takes you there.
If that administrator account is not your own, pass the link on to whoever administers your Entra ID — without those rights the consent cannot be given.
Switching it on
Switch on Sign in with Entra ID under Sign-in Methods. The Entra ID button then appears on your account's start page.
You can keep signing in with an e-mail address and a password switched on alongside it, or switch it off — at least one sign-in method has to stay active.
Existing users
Existing users do not have to be re-created. On the first sign-in with Entra ID, a user is matched to their existing account by e-mail address: the account, its learning history and its certificates are preserved, and name and data stay unchanged.
Users who do not exist in your account yet can only sign in if self sign-up is switched on. Otherwise, create or import them in the user management first. You do not set a password when you do — the account is created with the e-mail address alone, and the first sign-in with Entra ID attaches to it.
That address has to be the same on both sides. If it differs, the sign-in creates a new user instead, who belongs to no account and gets no further. Add that user in the user management under the address they signed in with — they are then attached to your account rather than created a second time.
Self sign-up with Entra ID
Available in the Premium and Enterprise plans.
With Enable MS Entra ID Single Sign-On with Just-in-Time user provisioning, under Self Sign-up, users are created in your account automatically on their first sign-in with Entra ID, so you do not have to create or import them beforehand. They arrive as learners; groups, courses and any further roles are assigned in the user management afterwards, as for any other user.
Restrict who may sign up under Self Sign-Up Restrictions. There are two lists, and either one on its own is enough to limit who can sign up with Entra ID:
- Restrict sign-up to the following email domains — applies to every sign-in method, so it also covers sign-up with an e-mail address and a password.
- Restrict sign-up to the following Entra Tenant IDs — applies to Entra ID only. If you are signed in with Entra ID yourself, Add current Entra Tenant ID fills in your own tenant ID.
WARNING
As long as both lists are empty, anyone who has the link to your start page can sign up.
When someone leaves the company
Blocking or deleting a user in Entra ID stops further sign-ins at Microsoft, but changes nothing in your account: the user stays active, keeps their learning history and course assignments, still appears in the reports and still counts towards your subscription. Deactivate or delete them in the user management as a separate step.
Switching a user back to e-mail and password
Open Learning Management → Users, click the edit symbol next to the user, and use Reset next to the sign-in method. The user then signs in with an e-mail address and a password again.
If signing in does not work
Two things to check first:
- whether the user exists in your account, or self sign-up is switched on — without either, the sign-in cannot create the user,
- whether your application requires assignment — an unassigned user is turned away by Microsoft before the sign-in reaches us.
Otherwise please contact support@e-sec.com and include, if possible:
- the e-mail address that was used,
- a screenshot of the error message,
- the browser console log: press F12 and switch to the "Console" tab before signing in.