Microsoft 365 identity and access

Control Evidize access with your Microsoft 365 identity.

Let your team enter Evidize with the Microsoft work account your organization already governs. Align sign-in with Microsoft Entra ID, reduce separate application credentials, and keep access to interview operations scoped to approved people and roles.

  • Use existing Microsoft work accounts
  • Require Microsoft SSO or preserve hybrid access
  • Keep identity and product activity accountable

Microsoft governs the work-account sign-in. Evidize governs product access and product activity.

Security settings showing Microsoft SSO linked while the compact product navigation remains visible

Outcome 1 of 2

Confirm the Microsoft sign-in path at a glance.

See Microsoft SSO shown as linked beside the account’s current sign-in and security settings.

Outcome 1 of 2: Confirm the Microsoft sign-in path at a glance.. See Microsoft SSO shown as linked beside the account’s current sign-in and security settings.

Full product view

Confirm the Microsoft sign-in path at a glance.

See Microsoft SSO shown as linked beside the account’s current sign-in and security settings.

Identity provider
Microsoft Entra ID
Sign-in experience
Microsoft 365 SSO
Team access
Assigned roles and active status
Oversight
SSO access and roles visible

One work identity, fewer access gaps

Bring product sign-in under the Microsoft identity controls your team already knows.

Evidize supports Microsoft SSO-required, local-only, and hybrid sign-in postures. When Microsoft SSO is used, Microsoft authenticates the work account and Evidize admits only an active, provisioned user from the configured Microsoft Entra tenant with an allowed product role. In an SSO-required organization, a separate Evidize password does not remain as a hidden fallback.

That keeps the identity responsibility clear. Your Microsoft team controls Entra authentication policies and Microsoft sign-in visibility; Evidize controls product eligibility, product sessions, and in-product audit activity. The Outlook organizer workflow is a separate Microsoft 365 integration, and candidate check-in remains a disclosed experience outside the employee SSO path.

  1. Reduce separate credential overhead

    Let employees use the familiar Microsoft work account they already use, reducing another password path and the support burden that comes with separate credentials.

  2. Apply the organization’s Microsoft sign-in posture

    Use Microsoft Entra MFA, passwordless authentication, and Conditional Access during Microsoft sign-in wherever the customer’s licensing, assignments, and policies support them.

  3. Keep product access accountable

    Combine Microsoft’s identity-level sign-in records with a separate Evidize activity trail so security and hiring stakeholders can investigate the right layer without blurring responsibilities.

The Microsoft identity journey

Move from sign-in policy to an authorized hiring workspace.

Keep Microsoft authentication, Evidize product access, and candidate-facing interview protection connected—but clearly separated—throughout rollout and daily use.

  1. 01 · Confirm the SSO connection Security administrator Make the linked Microsoft sign-in path visible.

    Administrators can confirm the linked Microsoft SSO status while Microsoft Entra continues to apply the authentication policies assigned in the customer tenant.

    Microsoft SSO shown as linked
  2. 02 · Review team access Organization administrator See who can use the product and which role they hold.

    Keep active status, assigned product role, and sign-in method visible while Microsoft authentication records remain available in Microsoft Entra.

    SSO method, role, and active status

See it in action

See the linked Microsoft sign-in path and the people authorized to use it.

Security settings showing Microsoft SSO linked while the compact product navigation remains visible

Outcome 1 of 2

Confirm the Microsoft sign-in path at a glance.

See Microsoft SSO shown as linked beside the account’s current sign-in and security settings.

Outcome 1 of 2: Confirm the Microsoft sign-in path at a glance.. See Microsoft SSO shown as linked beside the account’s current sign-in and security settings.

Full product view

Confirm the Microsoft sign-in path at a glance.

See Microsoft SSO shown as linked beside the account’s current sign-in and security settings.

Microsoft Entra authentication policies and sign-in records remain administered in your Microsoft tenant.

A clear control boundary

Microsoft controls authentication. Evidize controls product access.

Microsoft Entra ID is the customer’s identity provider. Evidize supports that sign-in path and applies its own organization, user, role, session, and audit controls after Microsoft authentication succeeds.
  • Microsoft MFA and Conditional Access depend on the customer’s Microsoft licensing, assignments, and policy configuration; Evidize does not configure those policies automatically.
  • SSO does not imply SCIM provisioning, Entra group-to-role synchronization, just-in-time user creation, or instant termination of every already-issued application session.
  • Employee SSO is separate from disclosed candidate check-in, and authorized people remain responsible for candidate communication and every employment decision.
Review Microsoft’s Entra SSO guidance

Plan the identity fit

Answer the security and rollout questions before enabling Microsoft SSO.

Clear buyer answers on sign-in policy, MFA and Conditional Access, user provisioning, Outlook access, audit evidence, and candidate privacy.
Is Microsoft Entra ID the same as Azure Active Directory?

Yes. Microsoft Entra ID (formerly Azure Active Directory) is the Microsoft identity service Evidize uses for the employee single sign-on capability described on this page.

Can an organization require Microsoft SSO?

Yes. Evidize supports an SSO-required posture as well as local-only and hybrid access. When SSO is required, local password sign-in fails closed. The organization’s intended posture is mapped with Evidize during rollout rather than changed through a customer self-service policy switch today.

Does Evidize receive or store the employee’s Microsoft password?

No. Microsoft handles the work-account authentication. Evidize verifies the authorized identity Microsoft returns and then creates its own product session for the approved user.

Can Microsoft MFA and Conditional Access govern the sign-in?

Yes, when those controls are licensed, configured, and assigned in the customer’s Microsoft tenant. Microsoft Entra applies them during Microsoft authentication; Evidize does not sell, configure, or independently enforce the customer’s Microsoft policies.

Does SSO automatically provision and remove Evidize users?

No. SSO authenticates identity; it is not the same as user lifecycle provisioning. Evidize users and product roles must be provisioned and managed in the application. The current product does not claim general SCIM provisioning or automatic Microsoft group-to-role synchronization.

Does Microsoft SSO give Evidize mailbox access?

No. Employee portal sign-in uses identity information, not Microsoft Graph mailbox permissions. The Outlook organizer workflow is a separate integration that works from the appointment open in Outlook. There is no separate Teams add-in today.

What happens when someone leaves the organization?

The organization can block future Microsoft authentication in Entra, and an authorized Evidize administrator can deactivate the product user and revoke product access. SSO alone should not be described as instant universal logout because already-issued application sessions have their own lifecycle.

How does employee SSO affect candidate privacy?

Employee SSO governs recruiter and administrator access to Evidize. Candidate check-in remains a separate disclosed path. The hiring organization should provide its own privacy information and an accommodation or alternative route, and authorized people remain responsible for every hiring decision.

Bring your Microsoft 365 administrator

Map the sign-in and access model before rollout.

Bring identity, security, recruiting, and privacy stakeholders. We will map SSO-required versus hybrid access, eligible Microsoft policies, user provisioning, product roles, Outlook operations, audit responsibilities, and the candidate privacy boundary.