Direct Answer: What Authentication Options Does OnePlan Support?
OnePlan supports two Authentication Types: Office365 Strict, the default, which only allows sign-in from accounts in your own Office 365/Microsoft Entra ID tenant; and Multi-Authentication, which lets you choose which sign-in methods are allowed — Office365, Forms (a native OnePlan account), or both. Allowing Office365 under Multi-Authentication is broader than Office365 Strict: it lets users sign in with any Microsoft account, not just one in your own tenant, which is one way to bring in external collaborators without giving them separate OnePlan credentials. Organizations that do not use Microsoft Entra ID at all can use Multi-Authentication with Forms set as the only allowed method, since Microsoft Entra ID is currently OnePlan’s only supported SSO provider.
What This Article Covers: Authentication
This article explains the two Authentication Types available in OnePlan — Office365 Strict and Multi-Authentication — what each one controls, how the sign-in experience differs between them, and how to decide which one fits your environment.
What you will understand: After reading this article, you will understand the difference between Office365 Strict and Multi-Authentication, what the Allowed Authentications options (Office365 and Forms) do, and when to switch between authentication modes.
Who This Article Is For: Authentication
- OnePlan administrators deciding whether their environment needs to support sign-in from outside their Office 365 tenant.
- Administrators troubleshooting why a user can or cannot sign in to OnePlan.
- Administrators about to enable Multi-Authentication who want to understand what it changes before making the switch.
This article explains the concepts. For the steps to change your Authentication Type, see How to Enable Multi-Authentication in OnePlan.
Why This Matters: Authentication
Authentication controls who can sign in, not what they can do once inside
Authentication Type determines whether a person can reach the OnePlan sign-in screen and log in at all. It is separate from Enterprise Security Groups, which determine what a user can see and do once they’re signed in. See Enterprise Security Groups in OnePlan - Overview for that distinction.
The default is restrictive by design
OnePlan ships with Office365 Strict so that, out of the box, only people already in your organization’s Office 365/Microsoft Entra ID tenant can sign in. Nothing needs to be configured to keep this behavior — it only becomes a limitation once you need to bring in people from outside your tenant.
Understanding Authentication in OnePlan
Context: Office365 Strict
Office365 Strict is the default Authentication Type in OnePlan. Users are routed directly to their organization’s own, tenant-branded Microsoft Entra ID sign-in page and authenticate with their Office 365 credentials. There is no native OnePlan account option: every user must have an account in your Office 365/Microsoft Entra ID tenant.
[[administration/users-and-resources/Authentication in OnePlan - Overview/attachments/Office365 Strict - Organization Login Screen.png]]
Context: Multi-Authentication
Multi-Authentication opens a second sign-in path alongside Office 365, so OnePlan can support both internal and external users in the same environment. Once enabled, you choose which sign-in methods are allowed through the Allowed Authentications setting — Office365, Forms (a native OnePlan account), or both — and the login screen users see changes accordingly:
Office365 and Forms both allowed:
[[administration/users-and-resources/Authentication in OnePlan - Overview/attachments/Multi-Authentication - Office365 and Forms Login Screen.png]]
Forms only allowed (no Continue with Microsoft button):
[[administration/users-and-resources/Authentication in OnePlan - Overview/attachments/Multi-Authentication - Forms Only Login Screen.png]]
Office365 only allowed — users land on a generic Microsoft sign-in page instead of an organization-specific one, since the page has to accept sign-in from any Microsoft account, not just your organization’s tenant:
[[administration/users-and-resources/Authentication in OnePlan - Overview/attachments/Multi-Authentication - Office365 Only Login Screen.png]]
Under Multi-Authentication, Office365 is not limited to accounts in your own tenant the way Office365 Strict is — a user can sign in with any Microsoft account, including one from a different organization’s tenant or a personal Microsoft account. Forms is independent of Microsoft entirely, for users who don’t have (or don’t want to use) a Microsoft account. Setting Allowed Authentications to Forms only is intended for organizations that are not Microsoft Entra ID users, since Microsoft Entra ID is currently OnePlan’s only supported method of single sign-on (SSO).
Context: Choosing Between the Two
If every person who needs OnePlan access already has an account in your Office 365/Microsoft Entra ID tenant, Office365 Strict is sufficient and requires no configuration. If you need to invite someone outside your tenant, Multi-Authentication gives you two ways to do it, and they aren’t mutually exclusive: allowing Office365 under Multi-Authentication lets external users sign in with any Microsoft account (their own organization’s tenant, or a personal Microsoft account) with no OnePlan-specific credentials to manage, while allowing Forms covers users who don’t have a Microsoft account at all. If your organization does not use Microsoft Entra ID at all, use Multi-Authentication with Forms set as the only Allowed Authentication, since Office365 Strict has no path for accounts outside a Microsoft Entra ID tenant and Microsoft Entra ID is currently the only SSO provider OnePlan supports.
Do not enable Multi-Authentication if you already have external users configured directly in your Microsoft Entra ID directory. Doing so can prevent those specific external Entra ID users from accessing OnePlan. See How to Enable Multi-Authentication in OnePlan for details before making this change.
Common Scenarios: When to Use Each Authentication Type
You might keep Office365 Strict in OnePlan if:
- Every current and future OnePlan user is a member of your Office 365/Microsoft Entra ID tenant.
- Your organization’s security policy requires all application access to route through your tenant’s identity provider.
You might switch to Multi-Authentication with Office365 allowed if:
- You need to invite contractors, customers, or partners who have their own Microsoft account — whether in another organization’s tenant or a personal Microsoft account — and want them to sign in with it rather than creating separate OnePlan credentials.
You might switch to Multi-Authentication with both Office365 and Forms allowed if:
- You need to support external users who have a Microsoft account and users who don’t, in the same environment.
- You want some users to sign in with Office 365 while others use a native OnePlan (Forms) account.
You might switch to Multi-Authentication with Forms as the only allowed method if:
- Your organization does not use Microsoft Entra ID at all, since Microsoft Entra ID is currently the only identity provider OnePlan supports for SSO.
Frequently Asked Questions: Authentication
Q: What is the default Authentication Type in OnePlan? A: In OnePlan, the default Authentication Type is Office365 Strict, which only allows sign-in from accounts in your Office 365/Microsoft Entra ID tenant.
Q: Can external users who aren’t in my Office 365 tenant access OnePlan? A: In OnePlan, only if Multi-Authentication is enabled. External users can sign in either with their own Microsoft account (if Office365 is an allowed method) or with a native OnePlan account (if Forms is an allowed method). Under Office365 Strict, only accounts in your own Office 365/Microsoft Entra ID tenant can sign in.
Q: What’s the difference between Office365 Strict and allowing Office365 under Multi-Authentication? A: In OnePlan, Office365 Strict only allows sign-in from accounts in your own Office 365/Microsoft Entra ID tenant. Allowing Office365 under Multi-Authentication is broader — it lets users sign in with any Microsoft account, including one from a different organization’s tenant or a personal Microsoft account, not just accounts in your tenant.
Q: Does changing the Authentication Type change what a user can see or do in OnePlan? A: In OnePlan, no. Authentication Type only controls whether a user can sign in. What they can see and do once signed in is controlled separately by their Enterprise Security Group. See Enterprise Security Groups in OnePlan - Overview.
Q: Will enabling Multi-Authentication change how the login screen looks? A: In OnePlan, yes — see the screenshots for each Allowed Authentications combination under Context: Multi-Authentication above. Office365 Strict always shows your organization’s own, tenant-branded Microsoft Entra ID sign-in page, never a OnePlan-branded screen.
Q: Can I use Multi-Authentication with Forms only, and no Office365 sign-in option? A: In OnePlan, yes. Set Allowed Authentications to Forms only. This is intended for organizations that are not Microsoft Entra ID users, since every user signs in with a native OnePlan account instead of Office 365 credentials.
Q: Does OnePlan support single sign-on (SSO) with identity providers other than Microsoft Entra ID? A: In OnePlan, no. Microsoft Entra ID is currently the only supported SSO provider. Organizations that use a different identity provider, or none at all, should use Multi-Authentication with Forms as the only allowed method.
What to Do Next: Authentication
Change your Authentication Type: - How to Enable Multi-Authentication in OnePlan
Manage who can access OnePlan once authentication is configured: - How to Grant Users Access to OnePlan via Entra Groups - How to Add Named Resources in OnePlan
Review the full process: - Resource Center Administration in OnePlan - Overview
Comments
0 comments
Please sign in to leave a comment.