Signing in with the company's Microsoft account

MetronHR signs people in through Microsoft Entra ID, using OpenID Connect. Management stores the Azure tenant once, and after that everyone comes in with their work account. Whether new accounts may be created in the process is a separate decision. Included in every plan.

As of:15. September 2026

What is checked when somebody signs in

The order is the security. Every step can end the sign-in, and every rejection states its reason in plain words instead of just saying "failed".

  • 1. Profile

    What is checked
    Does the token contain an email address?
    If it does not fit
    Stop. Without an address there is no way to match a person.
  • 2. Tenant

    What is checked
    Is this Azure tenant stored with a business?
    If it does not fit
    Stop, with a note that this sign-in is not set up.
  • 3. Known account

    What is checked
    Does the person already exist and are they still active?
    If it does not fit
    A deleted account, or one inactive everywhere, does not get in.
  • 4. Known address

    What is checked
    Does an account with this address exist?
    If it does not fit
    It is linked. Membership of the business comes about only with creation released.
  • 5. New person

    What is checked
    Creation released, subscription active, licence free?
    If it does not fit
    If one of those is missing there is no access and a message with the reason.

As of 15. September 2026. The licence limit is checked twice: in advance, and bindingly under a lock inside the transaction, so that two simultaneous sign-ins do not both get the last licence.

Setting it up

Management sets it up, once per business. After that the only change for the staff is a second button on the sign-in page.

  1. 1. Store the Azure tenant

    Enter the Microsoft tenant id in the company settings. An Azure tenant belongs to exactly one business; if it is already stored elsewhere, the entry is rejected.

  2. 2. Decide whether accounts may be created

    With this enabled, an account comes into being at the first sign-in; without it, only those who have already been invited can get in. For businesses that want to keep access tight, "off" is the right setting.

  3. 3. Check a sign-in

    Somebody from the directory signs in. The settings then show how many accounts are linked to the directory.

The other ways in

Not every business has Microsoft 365, and not everybody in a business sits at a computer. That is why there are four routes side by side, and the business decides which of them apply.

  • Microsoft Entra ID

    For whom
    Businesses on Microsoft 365.
    What comes with it
    No second password, the directory's rules apply along with it.
  • Email and password

    For whom
    Everyone else.
    What comes with it
    Optionally with a second factor through an authenticator app.
  • Passkey

    For whom
    Anyone who wants to work without a password.
    What comes with it
    Signing in through the device, its fingerprint or its face recognition; the biometric data stays on the device.
  • Terminal and QR code

    For whom
    Employees without a work phone and without a computer.
    What comes with it
    A card or a chip at the terminal, a QR code for the app. No biometrics.

As of 15. September 2026. For time tracking itself MetronHR processes no biometric data, see the article on time tracking without a fingerprint.

Why a fingerprint at the terminal is not a good idea is set out in the article Time tracking without a fingerprint. Where the data sits and who processes it is set out in the Trust Center.

Questions about signing in

What we are asked most often about it.

Microsoft Entra ID, formerly Azure Active Directory, through OpenID Connect. Other providers such as Google Workspace or Okta are not connected. Anyone without an Entra tenant signs in with an email address and a password, optionally with a passkey and a second factor.

Nothing extra: signing in through Entra ID is included in every plan. It is not a paid-for feature, because secure sign-in is not an optional extra.

Only if the business expressly switches it on. With creation off, only people who already exist in MetronHR get in; everyone else gets a message and no access. With it on, the account comes into being at the first sign-in, but only while the subscription is running and only while a licence is free.

The sign-in fails, because Entra ID no longer issues a token. The account in MetronHR stays and has to be deactivated there. Automatic provisioning in both directions, through SCIM for example, does not exist.

No. An Azure tenant belongs to exactly one MetronHR business, and that link is unique. An attempt to store the same Azure tenant a second time is rejected.

The employee app signs in with the account credentials, and alongside that there is signing in at the terminal by card or chip and signing in by QR code. Which route applies in the business is decided by management.

Question not answered here? Every step is explained in the help centre.

Sign in with the account you already have

Store Entra ID once, and after that signing in is one button.

See the Trust Center

No credit card, cancel any time