Before you start

You'll need:

  • The Microsoft Entra ID add-on switched on in DuoApp. A DuoApp company admin switches it on in Admin → DuoApp Features, in the People section. It's £250 per month + VAT and we're rolling it out gradually - if you can't see it, contact us to have it enabled.
  • A DuoApp admin to enter your tenant ID, create provisioning tokens and choose who must sign in with Microsoft.
  • A Microsoft Entra Global Administrator or Application Administrator to grant consent and set up the enterprise applications.

Sign-in and provisioning are set up separately. You can use Microsoft sign-in on its own and keep adding people in DuoApp, or add provisioning so Entra creates and switches off DuoApp users for you.

// Who manages what

Entra decides who someone is. DuoApp decides what they do.

  • Microsoft Entra ID: the person's identity (name and email), whether they can access DuoApp, and their password, MFA and Conditional Access.
  • DuoApp: roles, permissions, projects, sites, supervisors, and timesheet and payroll settings.

Your Microsoft organisation is only ever connected to your DuoApp company explicitly, by tenant ID - DuoApp never matches organisations by email domain.

Part 1: Microsoft sign-in

Connect your organisation

  1. In DuoApp, go to Admin → Entra ID and open the consent link shown there.
  2. Sign in as a Global Administrator or Application Administrator and grant consent to the DuoApp application for your organisation. DuoApp then appears under Enterprise applications in the Microsoft Entra admin centre.
  3. In the Microsoft Entra admin centre, open Overview and copy your Tenant ID.
  4. Back in DuoApp Admin → Entra ID, paste the tenant ID and save.
  5. Click Connect / test my Microsoft account and sign in with your own work account. This checks the connection end to end and links your Microsoft account to your DuoApp user.

Control who can use DuoApp (recommended)

  1. In Enterprise applications, open DuoApp and go to Properties. Set Assignment required? to Yes and save. Only people you assign can then sign in to DuoApp with Microsoft.
  2. Go to Users and groups and assign the users or groups who should use DuoApp. (Assigning groups rather than individual users needs a Microsoft Entra ID P1 or P2 licence - that's a Microsoft requirement.)

Choose who must sign in with Microsoft

In DuoApp, go to Admin → Users and choose which users must sign in with Microsoft - any selection, or everyone. For those users, DuoApp password sign-in is turned off. Everyone else can carry on with their DuoApp password, which is useful for subcontractors who aren't in your organisation.

Users then choose Sign in with Microsoft on the DuoApp sign-in page, on the web or in the DuoApp mobile app. Microsoft handles the sign-in, so your MFA, Conditional Access and password policies apply.

Part 2: Automatic provisioning (SCIM)

With provisioning, Entra creates a DuoApp user when you assign someone, keeps their name and email up to date, and switches off their access when you remove them. Until DuoApp is listed in the Microsoft Entra app gallery, provisioning is set up as a separate non-gallery application.

In DuoApp

  1. Go to Admin → Entra ID and set user management to Managed by Entra ID (SCIM).
  2. Create a provisioning token. Copy the Tenant URL and the token - the token is shown only once. If you lose it, revoke it and create a new one.

In the Microsoft Entra admin centre

  1. Go to Enterprise applications → New application → Create your own application.
  2. Name it DuoApp provisioning, choose Integrate any other application you don't find in the gallery (Non-gallery), and create it.
  3. Open Provisioning and set Provisioning Mode to Automatic.
  4. Under Admin Credentials, paste the Tenant URL and the provisioning token as the Secret Token. Click Test Connection, then save.
  5. Open Attribute mapping in the left-hand menu (called Mappings on older screens), open Provision Microsoft Entra ID Groups and set Enabled to No. DuoApp provisions users only.
  6. Open Provision Microsoft Entra ID Users and check the attribute mappings against the table below. The one change you need to make is externalId: set its source attribute to objectId.
  7. Go to Users and groups and assign the same users and groups you assigned to the DuoApp sign-in app.
  8. Back in Provisioning, click Start provisioning.

User attribute mappings

DuoApp (SCIM) attributeEntra source attribute 
userNameuserPrincipalNameKeep the default
activeSwitch([IsSoftDeleted], , "False", "True", "True", "False")Keep the default
emails[type eq "work"].valuemailKeep the default
name.givenNamegivenNameKeep the default
name.familyNamesurnameKeep the default
externalIdobjectIdChange from the default (mailNickname)

What happens next

  • Timing. Entra syncs roughly every 40 minutes. To push one person straight away, use Provision on demand on the provisioning app.
  • New users appear in DuoApp marked Needs configuration. They can't sign in until a DuoApp admin sets their role, projects and site access.
  • Name and email changes made in Entra are synced to DuoApp.
  • Everything is audited. Each user created, updated or switched off is recorded in DuoApp's audit log, showing whether the change came from Entra (SCIM) or from someone in DuoApp.

When people leave

Disabling, unassigning or deleting a user in Microsoft Entra ID switches off their DuoApp access automatically at the next sync (or straight away with Provision on demand).

// Deactivated, never deleted

Their history stays in DuoApp

DuoApp deactivates the user - it never deletes them. Their timesheets, site attendance, approvals, documents and audit history are all kept, so your records stay complete.

Troubleshooting

Sign-in messages

If Microsoft sign-in doesn't work, DuoApp shows a message explaining why. The code underneath each one is what our support team will ask for.

MessageWhat it means and what to do
Your organisation isn't connected to DuoApp
untrusted_tenant
The Microsoft account belongs to an organisation that isn't connected to any DuoApp company. Check the tenant ID entered in DuoApp Admin → Entra ID matches Overview → Tenant ID in the Entra admin centre, and that the person is signing in with their work account - not a personal or guest Microsoft account.
Your Microsoft account isn't linked to a DuoApp user
not_linked
The organisation is connected, but this Microsoft account isn't linked to anyone in your DuoApp company. If you use provisioning, check the person is assigned to the provisioning app and has been provisioned - Provision on demand will push them straight away. Otherwise, ask a DuoApp admin to check they've been added to DuoApp.
Your account isn't available
account_unavailable
The DuoApp user exists but can't sign in right now: they've been blocked or removed in DuoApp, they're still marked Needs configuration waiting for an admin to set up their role and access, or they've been switched off from Entra ID.
Your sign-in expired
expired
The sign-in took too long, or its link was used twice (for example, after pressing Back). Start again from the DuoApp sign-in page.
Sign-in was cancelled or failed
failed
The person cancelled at Microsoft, or Microsoft reported an error - for example a Conditional Access policy blocked the sign-in. Check the user's sign-in logs in the Entra admin centre.
This Microsoft account is already linked to someone else
already_linked
Shown when connecting a Microsoft account from DuoApp. Each Microsoft account can be linked to only one DuoApp user in a company.

Provisioning

  • Test Connection fails: check the Tenant URL was copied exactly, and that the token hasn't been revoked in DuoApp. If in doubt, create a new token.
  • Someone hasn't appeared in DuoApp: check they're assigned to the DuoApp provisioning app, then use Provision on demand or check the provisioning logs in Entra.
  • They've appeared but can't sign in: a DuoApp admin still needs to set their role, projects and site access - look for Needs configuration in Admin → Users. Also check they're assigned to the DuoApp sign-in app.
// Need a hand?

We're happy to help

Email contactus@duoapp.co.uk or call +44 1303 201346, and include any message code you've seen. For an overview of the add-on, see Microsoft Entra ID for DuoApp.