Microsoft / Azure AD auto-join
Set your organisation's email domain once and every staff member who signs in to Reach with their Microsoft 365 account is added to your organisation automatically — no invitation, no join link. It's the fastest way to onboard a team that already lives in Microsoft 365 / Entra ID.
Setting it up
- Open the organisation in your admin dashboard and go to the Identity tab.
- Under Microsoft / Azure AD Auto-Join, enter your organisation's email domain — for
example
contoso.comoryourcompany.onmicrosoft.com— and click Save. - Tell staff to install Reach and choose Sign in with Microsoft.
While a domain is set, the tab shows Active: users with @yourdomain addresses are auto-joined on Microsoft sign-in. Click Clear to switch it off.
Public email domains (outlook.com, gmail.com and the like) can't be used — the domain
has to be one your organisation owns.
Exactly what happens at sign-in
When someone signs in with a Microsoft account whose email domain matches:
- if they're not yet a member and the organisation is below its seat count (Settings tab), they're added and their account becomes unmetered immediately;
- if they're already a member, nothing changes;
- if the organisation is at its seat count, they are not added (this is logged on our side) — raise the seat count and have them sign in again.
Auto-join only runs for Microsoft sign-ins. Someone from your domain who signs in with Google or an email/password TYO ID isn't auto-joined — invite them from the Members tab instead.
What auto-join is — and isn't
- It is a way to let Microsoft-authenticated staff into your Reach organisation without invitations.
- It is not SAML or SCIM provisioning, and it doesn't read your directory, groups or licences.
- It is not enterprise directory federation. If your organisation needs Reach to federate with your own identity provider (Azure AD / Entra ID, OIDC), that's available on request — see SSO & MFA.
Common questions
Can I use more than one domain?
One domain per organisation today. If you have several, choose the one most staff sign in with and invite the rest.
Does this replace MFA?
No. Members still get Reach's own MFA and push-to-approve; you can require MFA for the whole organisation from SSO & MFA.
Someone signed in with Microsoft but wasn't added.
Check, in order: their email domain matches exactly (subdomains don't match); the organisation isn't at its seat count; they used Sign in with Microsoft, not Google or a password.