Sign in with Microsoft is freely available for all users in all tiers.
Business and Enterprise customers may choose to require organization members to only use Sign in with Microsoft.
Enterprise customers may also configure Microsoft Entra ID as an OpenID Connect (OIDC) identity provider for SSO - see instructions here.
| Free | Pro | Business | Enterprise |
Sign in with Microsoft | ✅ | ✅ | ✅ | ✅ |
Require Microsoft SSO |
|
| ✅ | ✅ |
|
|
| ✅ |
Granting permission for your organization
For organizations with a Microsoft Entra ID tenant, you may need an administrator to grant your users permission to use Microsoft to sign in to Haystack.
As an Entra ID administrator, go to http://thehaystackapp.com/login
Enter your work email address and press “Continue”
On the next screen, select “Sign in with Microsoft”
4. Sign in using the Microsoft login page
5. Select "Accept" to grant consent (and make sure the checkbox is checked)
If successful, Haystack will be automatically added as an Enterprise app in your Entra ID Portal.
Requiring Sign in with Microsoft for your organization
Business and Enterprise customers can require members on specific email domains to sign in only via Sign in with Microsoft. To set this up, contact your Account Manager with the following:
Your Entra ID tenant ID — a GUID identifying your Microsoft tenant. You can find this in the Microsoft Entra admin center under Identity → Overview (labeled Tenant ID). Example:
a1b2c3d4-5678-90ab-cdef-1234567890ab.Email domains — one or more email domains, e.g.
acme.com,acme.co.uk. Users with addresses on these domains will be required to sign in with Microsoft.Admin consent — an Entra ID administrator must grant consent for your organization, following the steps in Granting permission for your organization above.
💡 The order doesn't matter — you can send the details above before or after granting admin consent.
For more information or assistance, please contact your Account Manager.





