Let your staff sign in with their Microsoft work accounts instead of an emailed code. The page is laid out in the order the work has to be done.
Before you start
- You need to be an Org admin.
- Your Microsoft Entra administrator consents once to the Members by 2Labs app in your tenant. Nothing needs to be registered on your side.
- You need your Tenant ID (in the Azure portal: Microsoft Entra ID → Overview → Tenant ID) and access to the DNS for each email domain your staff use.
- If the page says single sign-on is not switched on for this instance of Members yet, you can still prepare the settings. They take effect once 2Labs enables it.
Steps
- Go to Organization Settings → Sign-in & security.
- Under Microsoft Entra tenant (step 1), enter the Tenant ID and optionally a Name (optional). Turn on Enabled and click Save tenant.
- Under Email domains (step 2), type a domain in Add a domain and click Add.
- Copy the Name and Value shown and add them as a TXT record where that domain's DNS is managed. Then click Verify. Once found, the domain shows Verified with a date.
- Under Who gets which role (step 3), the simplest way is in Entra: assign people or groups to the Members app with the role Members.OrgAdmin or Members.OrgEditor. To use your own role names or an existing group instead, choose a Type (Group or App role), enter the Group object ID or App role value, choose the Members role and click Add.
- Under Sign-in policy (step 4), choose:
- Email codes and single sign-on — people at your verified domains sign in with Microsoft and can still ask for an email code.
- Single sign-on only — email codes are switched off for your organization. You are asked to confirm with Require single sign-on.
- Email codes only — to go back.
What happens next
Staff at a verified domain see Continue with Microsoft on the sign-in page. A Microsoft sign-in lasts 8 hours. Your own Conditional Access and multi-factor rules apply.
Before you choose Single sign-on only, check that your own Microsoft account has a Members role. Email codes stop working straight away, including for you, and anyone signed in with a code must sign in again with Microsoft.
Where roles come from Entra, someone with a role is added on their first sign-in, and their role follows Entra at each sign-in. Someone with no matching role is refused, never given a default. Where you use no Entra roles or mappings, only people you have invited can sign in. Deactivating someone in Users & roles always wins.
Keep the DNS record in place. It is re-checked daily, and a domain whose record has gone stops being used for sign-in.
The policies can only be chosen once the tenant is enabled and a domain is verified; until then the page says Not ready yet and what is missing. Every change here is recorded in the audit log.