Signing in with Microsoft SSO

Help Center Hub/Integrations/

Signing in with Microsoft SSO

THE BASICS
INTEGRATIONS
Integrations OverviewWorkday Adaptive PlanningWebhooksQuickBooksOktaMicrosoftSigning in with Microsoft SSOLano APIJiraGoogle DriveDocuSignDATEVCANDISAuth0Adobe Sign

Signing in with SSO (Microsoft Entra ID)

If your organisation uses Microsoft Entra ID, your team can sign in to Lano with their existing Microsoft work accounts instead of a separate Lano password. This article explains how to add users when SSO is enabled, how to log in, and what to do if someone can't sign in.

Before You Start

Single Sign-On handles authentication only - it confirms who a user is. It does not create Lano accounts and does not assign roles or permissions. This means every user still has to be invited to Lano first. SSO only changes how they log in.

Adding a User

An Admin on your Lano account can invite new users:

  1. Go to Settings → Users

  2. Click Invite User

  3. Fill in the required fields:

    • Name & email

    • Role (Admin, Manager, Finance, or Expense Approver)

    • Entities the user should have access to

    • If assigning the Expense Approver role: select the employees whose expenses this user should be able to review

  4. Click Send Invite

    Important: the email address must exactly match the one that the person uses in your Microsoft Entra ID directory. If the addresses don't match, their sign-in will be rejected.

How Signing In Works

Lano uses email-first login. The user enters their email address, and Lano recognises that their organisation uses SSO.

  1. The user opens the Lano login page and enters their email address

  2. They are redirected straight to Microsoft - no password field appears on Lano's side

  3. They sign in with Microsoft, following whatever your organisation requires (password, MFA, conditional access)

  4. Microsoft returns them to Lano and they are signed in

    Users who belong to an organisation without SSO see the normal password field instead.

First Sign - In: Administrator Consent

The very first time anyone from your organisation signs in, Microsoft will ask one of your IT administrators to approve access on behalf of the whole organisation.

Once that approval is given:

  • Every other user in your organisation can sign in without any further prompts

  • No certificates or keys need to be exchanged with Lano

Lano only requests the openid, profile and email scopes - enough to confirm identity. Lano does not request access to your directory, groups, mailboxes or files.

User Roles and Permissions

Roles are managed entirely in Lano. Group membership in Microsoft Entra ID does not map to Lano roles.

Role

Permissions


Admin
Full access to all settings and actions across the platform. Can manage users, roles, services, team members, and receive all notifications.
Manager
Can initiate hires, manage team members, and view non-financial information. Receives updates related to team activity and onboarding.
Finance
Access to invoices, payroll data, and payment execution. Can view team member profiles and receive finance-related notifications.
Expense Approver
Limited to reviewing and managing expenses only for specific employees. No access to other platform areas.

To change a role or entity access:

  1. Go to Settings → Users

  2. Select the user

  3. Click Edit

Removing a User

To revoke someone's access:

  • Click Delete next to their name in Settings → Users

  • Their access is revoked immediately

  • You can re-invite them later if needed

Note: Removing a person from your Microsoft Entra ID directory does not remove them from your Lano user list. Both steps are needed when someone leaves.

Troubleshooting

If a user can't sign in, they'll see a generic error message. For security reasons, the message doesn't say why. The most common causes are:


What happened

How to fix it


The user hasn't been invited in Lano yet
Invite them in Settings → Users
Their Lano email doesn't match their Microsoft account email
Delete the invite and re-send it with the correct address
Administrator consent was never granted
Ask an IT administrator to sign in first and approve the consent prompt
Their account was deleted in Lano
Re-invite them


If none of these apply, contact your Lano representative.

Enabling SSO for Your Organisation

SSO is enabled per organisation and set up by Lano during onboarding. To turn it on, contact your Lano representative - they'll need your Microsoft Entra Tenant ID, which your IT team can provide.

Learn More

  • Managing Users in Lano

  • Joining an Existing Company Account in Lano

  • User Roles Explained

Was this answer helpful to you?

Pourquoi Lano?

Tarifs

Demander une démo

Pourquoi Lano?

Tarifs


Demander une démoEOR & PayrollContractor Management

© Lano Software GmbH 2026