Sign in to FBTM with Microsoft Entra ID

A setup guide for your IT administrator. Once it is done, your people sign in to FBTM with their work account and your organization's own password, MFA and Conditional Access policies.

Dev environment Identity provider: Microsoft Entra ID About 15 minutes

This is a test environment of FBTM. Use it only when FBTM asks you to test single sign-on; its values are different from production.

How it works

Your users type their work email on the FBTM sign-in page and are sent to Microsoft to sign in. FBTM never sees their password. You decide who can use FBTM and with which FBTM role by assigning users to the FBTM application in your Entra tenant.

Your organization

  • Approves the FBTM application once (admin consent).
  • Assigns users or groups to an FBTM role.
  • Owns passwords, MFA and access policies.

FBTM

  • Registers your tenant and email domains.
  • Creates each user's FBTM account on first sign-in.
  • Keeps what each role can see and do inside FBTM.

Before you start

  • A Microsoft Entra ID tenant with the email domain your users sign in with verified (for example yourcompany.com).
  • An administrator who can grant tenant-wide consent: Global Administrator, Privileged Role Administrator or Cloud Application Administrator.
  • Entra ID Free is enough to assign individual users. Assigning groups requires Entra ID P1 or P2.

Setup

  1. Send FBTM your tenant details

    Your administrator → your FBTM contact

    Send your Tenant ID (Entra admin center → Overview), the email domains your users sign in with, and a technical contact. FBTM registers your tenant against your FBTM account; sign-in is refused for tenants FBTM has not registered.

  2. Approve the FBTM application

    Your administrator

    Enter your Tenant ID to build your consent link, open it signed in as an administrator of your tenant, and approve.

    FBTM asks only to sign users in and read their basic profile: name, email and username. It gets no access to mail, files or other data. After you approve, you land on an FBTM page that confirms the consent.

  3. Allow only assigned users

    Your administrator

    In the Entra admin center go to Enterprise applications and find the FBTM application by its Application ID:

    46cfba41-80fe-427b-9c33-9bddb27ec977

    Open Properties, set Assignment required? to Yes and save. From then on only the users and groups you assign can sign in to FBTM.

  4. Assign users to an FBTM role

    Your administrator

    In the same application open Users and groups → Add user/group, select the users or groups and pick one role. The role decides what the user can do in FBTM.

    Role in EntraRole in FBTM
    Client ManagerClient Manager. The highest access level for your organization in FBTM.
    Client AnalystClient Analyst. Day-to-day access for your team.
    GuestGuest. Limited access.

    A user with several roles gets the highest one. A user assigned with Default Access or no FBTM role cannot sign in. Your FBTM contact can walk you through what each role can do.

  5. Sign in

    Each user

    On the FBTM sign-in page, type your work email (for example name@yourcompany.com) and continue. You are sent to Microsoft and back to FBTM.

    • The first time, FBTM creates your account with the role you were assigned. If you already had an FBTM account with the same email in your organization, that account is used instead.
    • If you have access to more than one FBTM account, FBTM asks which one to open.
    • FBTM does not ask for its own password or code: your organization's MFA and Conditional Access apply.

Managing access

You want toDo this in EntraTakes effect
Give someone accessAssign the user or their group with a roleTheir next sign-in
Change someone's roleEdit the assignment and pick another roleTheir next sign-in
Remove accessRemove the assignment, or disable the userNew sign-ins are blocked at once; an open FBTM session ends when it expires

Leavers: for an immediate cut-off of an open session, also tell your FBTM contact.

What FBTM receives from Microsoft

At each sign-in: the user's immutable object ID and tenant ID, name, email and username, and the FBTM role you assigned. FBTM keeps the object ID to recognize the user even if their email changes later. No passwords, tokens for other services or directory data are shared.

Troubleshooting

MessageMeaningFix
AADSTS50105The user is not assigned to the FBTM application.Assign the user or their group (step 4).
AADSTS65001 or "Need admin approval"Consent was not granted in your tenant.Repeat step 2 with an administrator account.
AADSTS700016The FBTM application does not exist in your tenant yet.Complete step 2 with the link from this page.
Access Not AssignedThe user is assigned without an FBTM role.Edit the assignment and choose Client Manager, Client Analyst or Guest.
Sign-in with your organization account was not completedThe sign-in was cancelled, or your tenant is not registered with FBTM yet.Try again; if it persists, confirm step 1 with your FBTM contact.
Account Needs AttentionAn FBTM account with the same username already exists elsewhere.Contact FBTM support.

Support

FB Tax Management support · contact@fbtm.com · 312-777-6060