How to Enable Multi-Authentication in OnePlan

  • Updated

Direct Answer: How to Enable Multi-Authentication in OnePlan

To enable Multi-Authentication in OnePlan, go to the Resource Center, click the menu, then select Configure > Authentication. In the Authentication Type drop-down, select Multi-Authentication, then choose the allowed sign-in methods — Office365, Forms, or both — in the Allowed Authentications drop-down. Once enabled, users can sign in with either their Office 365 credentials or a native OnePlan (Forms) account.


What This Article Covers: Multi-Authentication

This article explains how to enable Multi-Authentication so you can invite external users — contractors, customers, or other collaborators — to OnePlan without adding them to your company’s Office 365/Microsoft Entra ID tenant. It covers the Authentication Type and Allowed Authentications settings, and what users see when signing in under each authentication mode.

What you will accomplish: By the end of this article, you will be able to enable Multi-Authentication, choose the correct allowed authentication methods for your environment, and understand how the sign-in experience changes for your users.


Before You Begin: Enabling Multi-Authentication

  • Confirm you have Owner or Administrator permissions in OnePlan — this is required to access Configure > Authentication in the Resource Center.
  • Know your current Authentication Type. By default, OnePlan is set to Office365 Strict, meaning only users in your Office 365 tenant can access your OnePlan environment.
  • Check whether you already have external users configured in your Microsoft Entra ID directory. Do not enable Multi-Authentication if you have external Entra ID users set up — enabling it in that scenario will prevent those external users from accessing OnePlan.
  • If you’re not sure whether Multi-Authentication is the right change for your environment, see Authentication in OnePlan - Overview for a comparison of both Authentication Types.

Why This Matters: Multi-Authentication

Collaborate with people outside your tenant

With Multi-Authentication enabled, you can invite users to collaborate in OnePlan without requiring them to be added to your company’s Office 365/Microsoft Entra ID. These users can be contractors, customers, or anyone else outside your organization that you want to work with in OnePlan.

This is one of two Authentication Types

OnePlan ships with Authentication Type set to Office365 Strict, which restricts access to users in your Office 365 tenant. Enabling Multi-Authentication opens up a second sign-in path (a native OnePlan account, or Forms) alongside Office 365, so you can support both internal and external users from the same environment. See Authentication in OnePlan - Overview for a full comparison of both types before deciding to switch.

Avoid conflicts with existing external Entra ID users

If your Microsoft Entra ID directory already contains external user accounts, enabling Multi-Authentication can block those users from accessing OnePlan. Confirm your Microsoft Entra ID setup before making this change.


Step-by-Step: Enabling Multi-Authentication in OnePlan

Task: Enable Multi-Authentication

  1. Go to the Resource Center, click the menu, then select Configure > Authentication. [[administration/users-and-resources/How to Enable Multi-Authentication in OnePlan/attachments/Access Users Settings.png]]

  2. In the Authentication Type drop-down, select Multi-Authentication. OCT_23_Select_Auth_Method.png

  3. In the Allowed Authentications drop-down, select the allowed authentication methods:

    • Office365 — Allows users to sign in by clicking Sign in with Microsoft. Unlike Office365 Strict, this is not limited to accounts in your own Office 365/Microsoft Entra ID tenant — under Multi-Authentication, a user can sign in with any Microsoft account, including one from a different organization’s tenant or a personal Microsoft account.

    • Forms — A native OnePlan account (an Email and Password) that users can create and use to log into OnePlan, independent of Microsoft entirely.

    Both authentication methods are selected by default. Keep both selected if you need some users to sign in with Office 365 while others (such as external collaborators without a Microsoft account) sign in with a Forms account. If your organization does not use Microsoft Entra ID at all, select Forms only — this gives you Forms-only authentication into your OnePlan environment. Microsoft Entra ID is currently OnePlan’s only supported SSO provider, so Forms-only is the path for organizations using a different identity provider or none at all. OCT_23_Select_Allowed_Auth.png

The login screen users see depends on exactly which Allowed Authentications you select — it is not the same for every Multi-Authentication configuration.

Office365 and Forms both allowed: Users land on a OnePlan-branded “Welcome back!” screen with a Continue with Microsoft button and Work email/Password fields, separated by an “OR” divider.

[[administration/users-and-resources/How to Enable Multi-Authentication in OnePlan/attachments/Multi-Authentication - Office365 and Forms Login Screen.png]]

Forms only allowed: Users land on the same OnePlan-branded screen, but with only the Work email/Password fields — there is no Continue with Microsoft button.

[[administration/users-and-resources/How to Enable Multi-Authentication in OnePlan/attachments/Multi-Authentication - Forms Only Login Screen.png]]

Office365 only allowed: Users skip the OnePlan-branded screen entirely. They are routed straight to a generic Microsoft sign-in page — Microsoft’s own branding, an “Email, phone, or Skype” field, and a “No account? Create one!” link — rather than an organization-specific one. This is because the page must accept sign-in from any Microsoft account, not just your organization’s tenant, so it can’t be scoped to your organization’s own branded sign-in experience.

[[administration/users-and-resources/How to Enable Multi-Authentication in OnePlan/attachments/Multi-Authentication - Office365 Only Login Screen.png]]

If your environment uses Office365 Strict instead, users skip the OnePlan-branded screen entirely and are routed directly to their organization’s own, tenant-branded Microsoft Entra ID sign-in page, where they enter their Office 365 credentials. This is different from the generic Microsoft page shown under Multi-Authentication with Office365 only allowed — the Office365 Strict page is specific to your organization’s tenant. You can also send users directly into your OnePlan environment using the Share With link — under Office365 Strict authentication, this link routes users straight to your organization’s login screen.

[[administration/users-and-resources/How to Enable Multi-Authentication in OnePlan/attachments/Office365 Strict - Organization Login Screen.png]]


Frequently Asked Questions: Multi-Authentication

Q: Why would I enable Multi-Authentication instead of leaving Office365 Strict in place?

A: In OnePlan, enable Multi-Authentication when you need to invite people who are not part of your company’s Office 365/Microsoft Entra ID tenant — for example, contractors or customers. Office365 Strict only allows sign-in from accounts inside your own tenant.


Q: How do I switch back to Office365 Strict after enabling Multi-Authentication?

A: In OnePlan, go to Resource Center > … menu > Configure > Authentication and select Office365 Strict in the Authentication Type drop-down. This is the same setting used to enable Multi-Authentication, so switching back requires no separate configuration.


Q: Is it safe to enable Multi-Authentication if I already have external users in Microsoft Entra ID?

A: In OnePlan, no. If you have external users already set up in your Microsoft Entra ID directory, enabling Multi-Authentication will prevent those users from accessing OnePlan. Review your AD configuration before switching authentication modes.


Q: What is the difference between the Office365 and Forms authentication methods?

A: In OnePlan, Office365 lets users sign in by clicking Sign in with Microsoft — under Multi-Authentication, this works with any Microsoft account, not just one in your own Office 365/Microsoft Entra ID tenant. Forms is a native OnePlan account that users create and use to log in independently of Microsoft entirely.


Q: Under Multi-Authentication, can a user sign in with a Microsoft account from outside my organization?

A: In OnePlan, yes. If Office365 is an allowed authentication method under Multi-Authentication, users can sign in with any Microsoft account — including one from a different organization’s tenant or a personal Microsoft account. This is broader than Office365 Strict, which only allows accounts in your own tenant.


Q: Why do users see a generic Microsoft login page instead of the OnePlan-branded screen when I set Allowed Authentications to Office365 only?

A: In OnePlan, this is expected. With Allowed Authentications set to Office365 only, the sign-in page has to accept any Microsoft account rather than just your organization’s tenant, so OnePlan routes users straight to Microsoft’s generic sign-in page instead of showing the OnePlan-branded screen. If you select Forms, or both Office365 and Forms, users see the OnePlan-branded screen instead.


Q: Can I set up Forms-only authentication if my organization doesn’t use Microsoft Entra ID?

A: In OnePlan, yes. Enable Multi-Authentication and set Allowed Authentications to Forms only. This gives you Forms-only authentication into your OnePlan environment, since Microsoft Entra ID is currently OnePlan’s only supported SSO provider.


Q: Will the login screen look different after I enable Multi-Authentication?

A: In OnePlan, yes, and the exact screen depends on which Allowed Authentications you select. With Office365 and Forms both allowed, users see a OnePlan-branded screen with both a Continue with Microsoft button and Work email/Password fields. With Forms only, they see the same OnePlan-branded screen but with just the Work email/Password fields. With Office365 only, users skip the OnePlan-branded screen entirely and are routed to a generic (not organization-branded) Microsoft sign-in page, since it has to accept any Microsoft account rather than just your tenant’s. This is different from Office365 Strict, which always routes users to your organization’s own tenant-branded Microsoft Entra ID sign-in page and never shows a OnePlan-branded screen.


What to Do Next: Multi-Authentication

Understand both Authentication Types before or after making this change:

Manage who can access OnePlan once authentication is configured:

Was this article helpful?

0 out of 0 found this helpful

Comments

0 comments

Article is closed for comments.