Microsoft 365 OAuth SSO with Flexopus
Enable your employees to register easily and securely with Flexopus – without needing separate login details. With Microsoft 365 OAuth SSO integration, your users can simply use their existing Microsoft accounts to log in to Flexopus.
What is Microsoft 365 OAuth SSO integration?
The Microsoft 365 OAuth SSO integration connects Flexopus to the Microsoft identity system via the OAuth 2.0 protocol. Users authenticate via their existing Microsoft 365 account – Flexopus does not gain access to passwords, but only to a secure access token.
Upon first login, Flexopus automatically creates a new user profile that uses the name and email address from the Microsoft account. For all subsequent logins, authentication will be verified directly via Microsoft.
Administrators can use a whitelist to precisely define which email domains are granted access – thus keeping access limited to their own organization.
What is the purpose of integration?
With Microsoft 365 OAuth SSO integration, your employees don't need to remember any additional login details for Flexopus. Simply log in with your usual Microsoft account – quickly, securely and effortlessly.
Typical use cases for integration:
- Employees can log in to Flexopus with one click using their Microsoft 365 account.
- New user profiles are automatically created upon first login – no manual creation is necessary.
- Administrators control access via domain whitelists, thereby restricting access in a targeted manner.
- Optional: Disable password login and force SSO as the only login option.
How easy is the integration?
The setup is straightforward and requires no technical expertise. In the Flexopus dashboard, navigate to the authentication settings, select Microsoft O365 SSO as the provider, and define the allowed email domains. You can then test the configuration directly in your browser.
Ready to start? For complete step-by-step setup instructions, please visit our Help Center.
What are the advantages of integration?
- Easy sign-up: Users sign in with their existing Microsoft 365 account – no additional password is required.
- Increased security: OAuth 2.0 does not transmit passwords, but uses secure token-based authentication.
- Access control: Administrators use a whitelist to determine which domains are granted access.
- Automatic user setup: The user profile is created automatically upon first login – no manual effort required from IT.
- 2FA support: Two-factor authentication from Microsoft is automatically implemented.
- Included free of charge: Integration is included in Flexopus at no extra cost.
Further integrations
questions and answers
What data is transferred during registration?
When logging in via Microsoft OAuth SSO, Microsoft only transmits the user's name and email address to Flexopus. Passwords or other personal data will not be shared. Flexopus only stores the information necessary for user management.
What happens when an employee leaves the company?
If a Microsoft account is deactivated or deleted, the corresponding user can no longer log in to Flexopus via SSO. However, the Flexopus user profile remains and must be deactivated or deleted separately in Flexopus. For automatic synchronization of user management, we recommend combining it with SCIM integration.
Can I disable password login after setup?
Yes. Once Microsoft OAuth SSO is successfully set up, administrators can disable password login in the Flexopus settings and set SSO as the only login option. Additionally, the login form can be hidden – a backup access via a separate URL remains available for administrators.
Why is SAML2 recommended instead of OAuth SSO?
Microsoft OAuth SSO offers a quick and easy way to set up single sign-on. For companies that require even tighter access control – e.g. To allow only specific users from Active Directory – Flexopus recommends using SAML2 SSO. Both options are available and can be chosen depending on the requirements.
Does two-factor authentication (2FA) also work with SSO?
Yes. The 2FA settings from the Microsoft account will be applied automatically. If 2FA is set as mandatory in your Microsoft Admin Center, users will be automatically prompted for 2FA verification upon login – without any additional configuration in Flexopus.

