Sign in to FBTM with Microsoft Entra ID
A setup guide for your IT administrator. Once it is done, your people sign in to FBTM with their work account and your organization's own password, MFA and Conditional Access policies.
This is a test environment of FBTM. Use it only when FBTM asks you to test single sign-on; its values are different from production.
How it works
Your users type their work email on the FBTM sign-in page and are sent to Microsoft to sign in. FBTM never sees their password. You decide who can use FBTM and with which FBTM role by assigning users to the FBTM application in your Entra tenant.
Your organization
- Approves the FBTM application once (admin consent).
- Assigns users or groups to an FBTM role.
- Owns passwords, MFA and access policies.
FBTM
- Registers your tenant and email domains.
- Creates each user's FBTM account on first sign-in.
- Keeps what each role can see and do inside FBTM.
Before you start
- A Microsoft Entra ID tenant with the email domain your users sign in with verified (for example
yourcompany.com). - An administrator who can grant tenant-wide consent: Global Administrator, Privileged Role Administrator or Cloud Application Administrator.
- Entra ID Free is enough to assign individual users. Assigning groups requires Entra ID P1 or P2.
Setup
-
Send FBTM your tenant details
Your administrator → your FBTM contact
Send your Tenant ID (Entra admin center → Overview), the email domains your users sign in with, and a technical contact. FBTM registers your tenant against your FBTM account; sign-in is refused for tenants FBTM has not registered.
-
Approve the FBTM application
Your administrator
Enter your Tenant ID to build your consent link, open it signed in as an administrator of your tenant, and approve.
FBTM asks only to sign users in and read their basic profile: name, email and username. It gets no access to mail, files or other data. After you approve, you land on an FBTM page that confirms the consent.
-
Allow only assigned users
Your administrator
In the Entra admin center go to Enterprise applications and find the FBTM application by its Application ID:
46cfba41-80fe-427b-9c33-9bddb27ec977Open Properties, set Assignment required? to Yes and save. From then on only the users and groups you assign can sign in to FBTM.
-
Assign users to an FBTM role
Your administrator
In the same application open Users and groups → Add user/group, select the users or groups and pick one role. The role decides what the user can do in FBTM.
Role in Entra Role in FBTM Client Manager Client Manager. The highest access level for your organization in FBTM. Client Analyst Client Analyst. Day-to-day access for your team. Guest Guest. Limited access. A user with several roles gets the highest one. A user assigned with Default Access or no FBTM role cannot sign in. Your FBTM contact can walk you through what each role can do.
-
Sign in
Each user
On the FBTM sign-in page, type your work email (for example
name@yourcompany.com) and continue. You are sent to Microsoft and back to FBTM.- The first time, FBTM creates your account with the role you were assigned. If you already had an FBTM account with the same email in your organization, that account is used instead.
- If you have access to more than one FBTM account, FBTM asks which one to open.
- FBTM does not ask for its own password or code: your organization's MFA and Conditional Access apply.
Managing access
| You want to | Do this in Entra | Takes effect |
|---|---|---|
| Give someone access | Assign the user or their group with a role | Their next sign-in |
| Change someone's role | Edit the assignment and pick another role | Their next sign-in |
| Remove access | Remove the assignment, or disable the user | New sign-ins are blocked at once; an open FBTM session ends when it expires |
Leavers: for an immediate cut-off of an open session, also tell your FBTM contact.
What FBTM receives from Microsoft
At each sign-in: the user's immutable object ID and tenant ID, name, email and username, and the FBTM role you assigned. FBTM keeps the object ID to recognize the user even if their email changes later. No passwords, tokens for other services or directory data are shared.
Troubleshooting
| Message | Meaning | Fix |
|---|---|---|
| AADSTS50105 | The user is not assigned to the FBTM application. | Assign the user or their group (step 4). |
| AADSTS65001 or "Need admin approval" | Consent was not granted in your tenant. | Repeat step 2 with an administrator account. |
| AADSTS700016 | The FBTM application does not exist in your tenant yet. | Complete step 2 with the link from this page. |
| Access Not Assigned | The user is assigned without an FBTM role. | Edit the assignment and choose Client Manager, Client Analyst or Guest. |
| Sign-in with your organization account was not completed | The sign-in was cancelled, or your tenant is not registered with FBTM yet. | Try again; if it persists, confirm step 1 with your FBTM contact. |
| Account Needs Attention | An FBTM account with the same username already exists elsewhere. | Contact FBTM support. |
Support
FB Tax Management support · contact@fbtm.com · 312-777-6060