Documentation

Platform · Getting Started

Signing in & single sign-on

How to sign in to the intSignal portal with Microsoft 365 or with an email account and authenticator app — first-time setup, linking your Microsoft tenant, sessions, and fixing every sign-in error.

The portal has two ways to sign in. Which one a person uses depends on how their account was set up, and each person has exactly one.

Sign in with MicrosoftEmail account
Who it's forOrganizations on Microsoft 365People without Microsoft 365
How the account is createdAn administrator invites the person's emailintSignal creates it on request
PasswordYour Microsoft password — the portal never sees itSet by you, at least 12 characters
Second factorWhatever your organization's Microsoft sign-in rules requireA 6-digit authenticator code, every sign-in
Forgotten passwordReset it the usual way with MicrosoftContact intSignal

Use the right button

If your organization uses Microsoft 365, always choose Sign in with Microsoft. The email form below it only works for email accounts. Typing a Microsoft 365 address there returns "No account was found for that email", and repeated failed attempts can temporarily block your whole office network from signing in.

Sign in with Microsoft

Single sign-on uses your organization's Microsoft 365 (Microsoft Entra ID) accounts, so your team signs in with the same account they use for email and Teams. There's no separate portal password, and when someone leaves and you disable them in Microsoft 365, they can no longer sign in with Microsoft.

Linking your Microsoft 365 tenant

Before anyone can use Microsoft sign-in, your organization has to be linked to your Microsoft tenant. This happens once.

Ask intSignal for a consent link

intSignal generates an administrator consent link specific to your organization.

Have your Microsoft administrator approve it

Someone who can grant consent for your whole Microsoft tenant, such as a Global Administrator, opens the link, signs in, and accepts. This allows the intSignal portal to sign in your users.

intSignal confirms the link

Your organization is now tied to that Microsoft tenant, and invited users can sign in.

What the portal receives from Microsoft

When someone signs in, Microsoft sends the portal only their name, email address (or Microsoft username), and identifiers for their account and your organization's tenant. The portal does not receive their password or their Microsoft group memberships, so portal roles are always managed in the portal, never in Microsoft 365.

Signing in

Get invited

An administrator in your organization invites your email address. The invitation must use the same address you sign in to Microsoft 365 with. You may receive an invitation email.

Open the portal

Go to portal.intsignal.com. You'll see "Sign in to your organization's portal."

Choose Sign in with Microsoft

Sign in with your Microsoft 365 account as usual, including any multi-factor step your organization requires.

You're in

The first time you sign in, your account is activated with the roles your administrator chose, and you land on the Dashboard. After that, you just sign in.

Multi-factor authentication for Microsoft accounts is controlled by your organization's Microsoft sign-in policies. The portal doesn't add a second code of its own, so if you want MFA for portal access, require it in Microsoft 365.

Email accounts

Email accounts are for people who don't have a Microsoft 365 account. They're protected by a password and an authenticator app, and both are required every time. Administrators in your organization can't create email accounts. Ask intSignal, and they'll set one up.

First sign-in

Find your temporary password

When intSignal creates your account, you receive an email containing a temporary password.

Sign in with it

At portal.intsignal.com, under Or sign in with email, enter your email address and the temporary password, then select Sign in. You'll see "Finish setting up your account." Both of the next steps are on that one screen.

Choose your own password

Under Choose a new password (min 12 chars), enter it in New password and again in Confirm password. It must be at least 12 characters, and both entries must match. A longer passphrase is easier to remember and harder to guess than a short complex password.

Add the account to your authenticator app

Open an authenticator app such as Microsoft Authenticator or Google Authenticator, and add the account in one of three ways:

  • Scan the QR code shown on screen.
  • Under Can't scan? Enter this key manually, type the key shown. It's split into groups of four characters to make it easier to read.
  • On a phone, tap Open in authenticator app (mobile).

Confirm and finish

Under Then enter the 6-digit code it shows, type the code your app now displays, and select Finish & sign in. The code changes every 30 seconds; if it's about to change, wait for the next one.

Signing in after that

  1. Under Or sign in with email, enter your email and password, then select Sign in.
  2. When asked to "Enter the 6-digit code from your authenticator app," type the current code and select Verify.

The code is accepted for a short window either side of the current 30 seconds, so a code that changes as you type it will normally still work.

Lost your password or your phone?

There is no self-service reset for email accounts. Contact intSignal:

  • Forgot your password: intSignal emails you a new temporary password. Sign in with it, and on the next screen choose a new password. Because your authenticator is still set up, you'll also enter your current 6-digit code to confirm the change before selecting Finish & sign in.
  • Lost or replaced your phone: intSignal resets your authenticator, and you set it up again the next time you sign in, exactly as on your first sign-in.

Tip

There are no backup codes, so losing your authenticator means waiting for a reset. Use an authenticator app you can restore onto a new phone, and add the account to it straight away when you replace your device.

Sessions and signing out

  • Staying signed in: your session stays active while you use the portal and ends after a period of inactivity.
  • Changes apply immediately: if an administrator disables your account or changes your roles, it takes effect on your next action, without waiting for you to sign out.
  • Signing out: select Sign out at the bottom of the sidebar, under your name.

Signing out of the portal doesn't sign you out of Microsoft. On a shared computer, also sign out of your Microsoft account, or the next person can select Sign in with Microsoft and get straight in as you.

Troubleshooting

What you seeWhat it meansWhat to do
Sign-in failed or your account is not provisioned. Contact your administrator.After Sign in with Microsoft: you haven't been invited, the invitation went to a different email address, your organization isn't linked to your Microsoft tenant, or your account is disabled or locked.Ask your administrator to check the invitation and your status on the Users page. If nobody at your organization can sign in, contact intSignal.
No account was found for that email — please check for a typo.There's no email account with that address.Check for typos. If you use Microsoft 365, use Sign in with Microsoft instead.
Invalid email or passwordThe password is wrong.Try again carefully, or contact intSignal for a new temporary password.
Password must be at least 12 characters. or Passwords do not match.While choosing a new password, it's too short or the two entries differ.Enter a password of 12 or more characters, identically in both fields.
Too many attempts — try again later.Your account is temporarily locked after repeated wrong passwords.Wait about 15 minutes, then try again.
Too many failed attempts. Please wait a few minutes and try again.Too many wrong authenticator codes.Wait a few minutes. Check that your phone's clock is set automatically; a wrong clock produces wrong codes.
This account is locked. Contact your administrator.intSignal has locked the account.Contact intSignal.
Access from your network has been blocked. Contact support to be unblocked.Too many failed sign-ins came from your network, possibly from several people.Contact intSignal support to unblock it. Make sure Microsoft 365 users are using Sign in with Microsoft.
Need a hand with Platform?Talk to our team →