Single sign-on lets your team log in to the FormsByAir portal with their Microsoft work account, using the Log in with Microsoft button on the login page. There are no FormsByAir passwords to issue, reset or remove. Who can sign in is managed in Microsoft Entra ID, where you already manage your people.
It’s aimed at accounts with a lot of people in the User role (opening and prefilling forms) or the Workflow role (reviewing and approving submissions), where maintaining a FormsByAir login for each person is a chore. See Roles for what each role can do.
How it works
Single sign-on is switched on per account, with a default role of either User or Workflow.
- The first time someone from your organisation logs in with Microsoft, a FormsByAir user is created for them automatically in the default role, using their name and email address from Microsoft.
- From then on they’re a normal user. Their name appears against the submissions they action in the workflow log, they can be assigned submissions, and form and document access lists apply to them as usual.
- Anyone who already has a FormsByAir login with the same email address is linked instead. They keep their current role, and can continue to log in with their password as well.
Private forms are unaffected. If your account uses Microsoft Entra ID for private form authentication, people who have logged in to the portal with Microsoft can open those forms without being asked to sign in again.
Getting set up
Single sign-on is enabled by our support team, so that we can confirm the Microsoft organisation belongs to you. Email support@formsbyair.com with:
- Your Microsoft Entra Tenant Id
- The default role for new users, User or Workflow
Once it’s on, you’ll see it under Profile > Settings > Security > Portal Single Sign-On. After that, the Tenant Id can only be changed by our support team.
Your existing users and logins continue to work as they do now, so you can move people across at your own pace. To retire someone’s FormsByAir password altogether, delete their user. They’ll be created again as a single sign-on user, in the default role, the next time they log in with Microsoft.
Tip: your IT administrator can add FormsByAir to the Microsoft My Apps page by setting the enterprise application’s homepage URL to https://formsbyair.com/login/microsoft.
Managing single sign-on users
Single sign-on users are left off the Users page by default so they don’t crowd the list. Click Filter to include them, where they’re shown with an SSO badge.
- Edit lets you change their role. For example, to promote one reviewer to Supervisor. Their name and email address come from Microsoft and can’t be changed here.
- Delete removes the user from FormsByAir. It doesn’t block them. If they still have access in Microsoft Entra ID they’ll be created again in the default role the next time they log in.
To remove someone’s access, disable or remove them in Microsoft Entra ID.
Limiting who can log in
By default, anyone in your Microsoft organisation can log in and will be given the default role. To limit this to a group of people, your IT administrator can open the FormsByAir enterprise application in Microsoft Entra ID, set Assignment required to Yes, and assign the users or groups who should have access.
Note that this also applies to private forms if your account uses Microsoft Entra ID for private form authentication.
Security
- Single sign-on users never have a FormsByAir password, and password reset is not available for them.
- Must use Two Factor Authentication applies to people logging in with a FormsByAir password. It doesn’t apply to single sign-on logins, your own Microsoft MFA and conditional access policies apply instead.
- Must log in every session applies to everyone, including single sign-on users: they’re logged out when the browser closes or after 60 minutes of inactivity.
- If your account has a Login IP Address Whitelist, it applies to single sign-on logins too.
- Single sign-on sessions last a maximum of 10 hours, after which the person logs in with Microsoft again (usually one click). This means removing someone in Microsoft Entra ID takes effect within the working day.
Other identity providers
Single sign-on is available for Microsoft Entra ID. If you use a different identity provider, such as Okta or Google Workspace, let us know. We’re planning support for other providers and would like to hear what you need.