FormsByAir logo FormsByAir

Single sign-on lets your team log in to the FormsByAir portal with their Microsoft work account, using the Log in with Microsoft button on the login page. There are no FormsByAir passwords to issue, reset or remove. Who can sign in is managed in Microsoft Entra ID, where you already manage your people.

It’s aimed at accounts with a lot of people in the User role (opening and prefilling forms) or the Workflow role (reviewing and approving submissions), where maintaining a FormsByAir login for each person is a chore. See Roles for what each role can do.

How it works

Single sign-on is switched on per account, with a default role of either User or Workflow.

Private forms are unaffected. If your account uses Microsoft Entra ID for private form authentication, people who have logged in to the portal with Microsoft can open those forms without being asked to sign in again.

Getting set up

Single sign-on is enabled by our support team, so that we can confirm the Microsoft organisation belongs to you. Email support@formsbyair.com with:

  1. Your Microsoft Entra Tenant Id
  2. The default role for new users, User or Workflow

Once it’s on, you’ll see it under Profile > Settings > Security > Portal Single Sign-On. After that, the Tenant Id can only be changed by our support team.

Your existing users and logins continue to work as they do now, so you can move people across at your own pace. To retire someone’s FormsByAir password altogether, delete their user. They’ll be created again as a single sign-on user, in the default role, the next time they log in with Microsoft.

Tip: your IT administrator can add FormsByAir to the Microsoft My Apps page by setting the enterprise application’s homepage URL to https://formsbyair.com/login/microsoft.

Managing single sign-on users

Single sign-on users are left off the Users page by default so they don’t crowd the list. Click Filter to include them, where they’re shown with an SSO badge.

To remove someone’s access, disable or remove them in Microsoft Entra ID.

Limiting who can log in

By default, anyone in your Microsoft organisation can log in and will be given the default role. To limit this to a group of people, your IT administrator can open the FormsByAir enterprise application in Microsoft Entra ID, set Assignment required to Yes, and assign the users or groups who should have access.

Note that this also applies to private forms if your account uses Microsoft Entra ID for private form authentication.

Security

Other identity providers

Single sign-on is available for Microsoft Entra ID. If you use a different identity provider, such as Okta or Google Workspace, let us know. We’re planning support for other providers and would like to hear what you need.