Authentication
Portal Connect supports three methods for users to sign in to the A4D portal. The method is chosen during the setup wizard and applies to the entire tenant, though individual logins can deviate when Mixed mode is active.
The three methods
Microsoft Login
Users sign in using their existing Microsoft 365 account (Azure Active Directory). No separate portal password is needed.
- Login name must be an email address (the user's Microsoft 365 UPN)
- Single sign-on: the user's existing Microsoft session is used where possible
- Password resets and account security are managed in Azure AD, not in Portal Connect
- Recommended for organisations where all employees have Microsoft 365 accounts
Username / Password
Users sign in with a username and password created in Portal Connect.
- Login name can be any unique identifier (does not need to be an email address)
- Password is set on the login card and stored encrypted; the field appears blank after saving
- Administrators are responsible for communicating initial passwords and handling resets
- Suitable when employees do not have Microsoft 365 accounts
Mixed mode
Both Microsoft Login and Username/Password are accepted. Each login record specifies which method applies to that individual user.
- Users with Microsoft accounts use Microsoft Login; others use username/password
- Adds some administrative overhead - two authentication paths to manage
- Useful during a migration from username/password to Microsoft Login
Changing the method after setup
The authentication method can be changed at any time from the AppsForDynamics365 Portal Configuration page using the Change Portal Authentication action. The change takes effect immediately for new sign-ins.
Changing from Mixed mode or Username/Password to Microsoft Login exclusively will prevent users with username/password logins from signing in. Ensure all login records have been updated to Microsoft Login format before making this switch.
Per-login authentication method
The Authentication method field on each login card controls that individual user's sign-in method. In a Microsoft Login or Username/Password tenant, all logins should match the tenant setting. In Mixed mode, you set this per user.