> ## Documentation Index
> Fetch the complete documentation index at: https://docs.getthread.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Set Up Single Sign-On (SSO) with Microsoft 365

> Enable Microsoft 365 Single Sign-On for Thread Inbox and Admin so your team can log in securely with M365 credentials instead of one-time passcodes.

<Frame>
  <img src="https://mintcdn.com/thread/ysyi1-ysJ96KyxOf/images/a3d2977b-gtm-sso.gif?s=8586dfccd363fb037be075ad03558653" alt="Animation showing Microsoft 365 Single Sign-On login for Thread" width="838" height="527" data-path="images/a3d2977b-gtm-sso.gif" />
</Frame>

Thread Single Sign-On (SSO) lets your team log in to Thread Inbox and Thread Admin using your Microsoft 365 account, powered by Auth0. This doc walks you through setting it up.

<Note>
  See **Security** updates in the [changelog](/changelog/q3-2026).
</Note>

Thread workspace Admins can enable Service Team members to log into Thread Inbox using one of two authentication methods:

* One-time password
* Single Sign-On powered by Microsoft 365

Many MSPs opt into the security and reliability benefits of Microsoft 365 authentication. Here's how to get started:

## How to Configure

<Steps>
  <Step title="Open the Microsoft 365 and Teams App integration">
    Navigate to the Thread Admin Panel and select [Integrations -> Microsoft 365 and Teams App](https://admin.getthread.com/dashboard/integrations/chat/msteams/integrations)
  </Step>

  <Step title="Connect Microsoft 365">
    Below the option titled Microsoft 365, click **Connect** if it isn’t set up and follow on-screen instructions (described in the first section of [this page](/companion-apps/choose-which-ticket-updates-post-to-channel) for additional support)
  </Step>

  <Step title="Enable the SSO toggle">
    Once Microsoft 365 is listed as “Connected”, set the Enable SSO toggle to **ON**

    <Frame>
      <img src="https://mintcdn.com/thread/MmA6qEMELRi-vXeU/images/d4e64526-image.png?fit=max&auto=format&n=MmA6qEMELRi-vXeU&q=85&s=dbbcbdb44ef5a1aaff20b779df4c1c8c" alt="Enable SSO toggle set to ON below the connected Microsoft 365 integration" width="992" height="597" data-path="images/d4e64526-image.png" />
    </Frame>
  </Step>

  <Step title="Finish setup">
    Your workspace is now set up
  </Step>
</Steps>

## Once SSO is setup

Once SSO is setup and configured, point your service team to log into [Inbox](http://inbox.getthread.com/login) which will let your teammates take advantage of M365’s authentication.

<Frame>
  <img src="https://mintcdn.com/thread/ysyi1-ysJ96KyxOf/images/66d1a0bd-image.png?fit=max&auto=format&n=ysyi1-ysJ96KyxOf&q=85&s=16e6009c007514022344ec1dfe94e205" alt="Thread Inbox login screen with the Microsoft 365 Single Sign-On option" width="732" height="699" data-path="images/66d1a0bd-image.png" />
</Frame>

Logins will be restricted to only M365 SSO for users with ‘**Member**’ role Thread users; users with the ‘**Admin**’ role can also login through the one-time password as a backup alternative

## FAQ Section

<AccordionGroup>
  <Accordion title="Does SSO replace logging in with the One Time Passcode?">
    It does not! Users who have the "admin" role can choose to still login with the one time passcode sent to their email address, and users logging in without a Microsoft account will still have to use the one time passcode to login.
  </Accordion>
</AccordionGroup>


## Related topics

- [Microsoft Teams App Permissions Reference](/security-billing/microsoft-teams-app-permissions.md)
- [How to Deploy Desktop Messenger with SSO](/messenger/how-to-deploy-desktop-messenger-with-sso.md)
- [Microsoft 365 Administration](/skill-library/m365-administration/overview.md)
