The portal has two ways to sign in. Which one a person uses depends on how their account was set up, and each person has exactly one.
| Sign in with Microsoft | Email account | |
|---|---|---|
| Who it's for | Organizations on Microsoft 365 | People without Microsoft 365 |
| How the account is created | An administrator invites the person's email | intSignal creates it on request |
| Password | Your Microsoft password — the portal never sees it | Set by you, at least 12 characters |
| Second factor | Whatever your organization's Microsoft sign-in rules require | A 6-digit authenticator code, every sign-in |
| Forgotten password | Reset it the usual way with Microsoft | Contact intSignal |
Use the right button
If your organization uses Microsoft 365, always choose Sign in with Microsoft. The email form below it only works for email accounts. Typing a Microsoft 365 address there returns "No account was found for that email", and repeated failed attempts can temporarily block your whole office network from signing in.
Sign in with Microsoft
Single sign-on uses your organization's Microsoft 365 (Microsoft Entra ID) accounts, so your team signs in with the same account they use for email and Teams. There's no separate portal password, and when someone leaves and you disable them in Microsoft 365, they can no longer sign in with Microsoft.
Linking your Microsoft 365 tenant
Before anyone can use Microsoft sign-in, your organization has to be linked to your Microsoft tenant. This happens once.
Ask intSignal for a consent link
intSignal generates an administrator consent link specific to your organization.
Have your Microsoft administrator approve it
Someone who can grant consent for your whole Microsoft tenant, such as a Global Administrator, opens the link, signs in, and accepts. This allows the intSignal portal to sign in your users.
intSignal confirms the link
Your organization is now tied to that Microsoft tenant, and invited users can sign in.
What the portal receives from Microsoft
When someone signs in, Microsoft sends the portal only their name, email address (or Microsoft username), and identifiers for their account and your organization's tenant. The portal does not receive their password or their Microsoft group memberships, so portal roles are always managed in the portal, never in Microsoft 365.
Signing in
Get invited
An administrator in your organization invites your email address. The invitation must use the same address you sign in to Microsoft 365 with. You may receive an invitation email.
Open the portal
Go to portal.intsignal.com. You'll see "Sign in to your organization's portal."
Choose Sign in with Microsoft
Sign in with your Microsoft 365 account as usual, including any multi-factor step your organization requires.
You're in
The first time you sign in, your account is activated with the roles your administrator chose, and you land on the Dashboard. After that, you just sign in.
Multi-factor authentication for Microsoft accounts is controlled by your organization's Microsoft sign-in policies. The portal doesn't add a second code of its own, so if you want MFA for portal access, require it in Microsoft 365.
Email accounts
Email accounts are for people who don't have a Microsoft 365 account. They're protected by a password and an authenticator app, and both are required every time. Administrators in your organization can't create email accounts. Ask intSignal, and they'll set one up.
First sign-in
Find your temporary password
When intSignal creates your account, you receive an email containing a temporary password.
Sign in with it
At portal.intsignal.com, under Or sign in with email, enter your email address and the
temporary password, then select Sign in. You'll see "Finish setting up your account." Both
of the next steps are on that one screen.
Choose your own password
Under Choose a new password (min 12 chars), enter it in New password and again in Confirm password. It must be at least 12 characters, and both entries must match. A longer passphrase is easier to remember and harder to guess than a short complex password.
Add the account to your authenticator app
Open an authenticator app such as Microsoft Authenticator or Google Authenticator, and add the account in one of three ways:
- Scan the QR code shown on screen.
- Under Can't scan? Enter this key manually, type the key shown. It's split into groups of four characters to make it easier to read.
- On a phone, tap Open in authenticator app (mobile).
Confirm and finish
Under Then enter the 6-digit code it shows, type the code your app now displays, and select Finish & sign in. The code changes every 30 seconds; if it's about to change, wait for the next one.
Signing in after that
- Under Or sign in with email, enter your email and password, then select Sign in.
- When asked to "Enter the 6-digit code from your authenticator app," type the current code and select Verify.
The code is accepted for a short window either side of the current 30 seconds, so a code that changes as you type it will normally still work.
Lost your password or your phone?
There is no self-service reset for email accounts. Contact intSignal:
- Forgot your password: intSignal emails you a new temporary password. Sign in with it, and on the next screen choose a new password. Because your authenticator is still set up, you'll also enter your current 6-digit code to confirm the change before selecting Finish & sign in.
- Lost or replaced your phone: intSignal resets your authenticator, and you set it up again the next time you sign in, exactly as on your first sign-in.
Tip
There are no backup codes, so losing your authenticator means waiting for a reset. Use an authenticator app you can restore onto a new phone, and add the account to it straight away when you replace your device.
Sessions and signing out
- Staying signed in: your session stays active while you use the portal and ends after a period of inactivity.
- Changes apply immediately: if an administrator disables your account or changes your roles, it takes effect on your next action, without waiting for you to sign out.
- Signing out: select Sign out at the bottom of the sidebar, under your name.
Signing out of the portal doesn't sign you out of Microsoft. On a shared computer, also sign out of your Microsoft account, or the next person can select Sign in with Microsoft and get straight in as you.
Troubleshooting
| What you see | What it means | What to do |
|---|---|---|
| Sign-in failed or your account is not provisioned. Contact your administrator. | After Sign in with Microsoft: you haven't been invited, the invitation went to a different email address, your organization isn't linked to your Microsoft tenant, or your account is disabled or locked. | Ask your administrator to check the invitation and your status on the Users page. If nobody at your organization can sign in, contact intSignal. |
| No account was found for that email — please check for a typo. | There's no email account with that address. | Check for typos. If you use Microsoft 365, use Sign in with Microsoft instead. |
| Invalid email or password | The password is wrong. | Try again carefully, or contact intSignal for a new temporary password. |
| Password must be at least 12 characters. or Passwords do not match. | While choosing a new password, it's too short or the two entries differ. | Enter a password of 12 or more characters, identically in both fields. |
| Too many attempts — try again later. | Your account is temporarily locked after repeated wrong passwords. | Wait about 15 minutes, then try again. |
| Too many failed attempts. Please wait a few minutes and try again. | Too many wrong authenticator codes. | Wait a few minutes. Check that your phone's clock is set automatically; a wrong clock produces wrong codes. |
| This account is locked. Contact your administrator. | intSignal has locked the account. | Contact intSignal. |
| Access from your network has been blocked. Contact support to be unblocked. | Too many failed sign-ins came from your network, possibly from several people. | Contact intSignal support to unblock it. Make sure Microsoft 365 users are using Sign in with Microsoft. |
