Skip to main content

Sign-in and SSO setup

Everyone signs in at app.getstructured.ai/login with an account they already have - there are no Structured AI passwords to create or manage.

Three options are available on the sign-in screen:

  • Microsoft - sign in with your work (Microsoft Entra ID / Azure AD) account. This is single sign-on: access follows your company account, so once IT disables that account nobody can sign in with it again. See Offboarding a leaver for the one extra step that closes an already-open session.
  • Google - sign in with a Google Workspace account.
  • Email link - we email you a one-time sign-in link. Useful when IT policy blocks third-party app sign-ins entirely.

Most firms on Microsoft 365 need a one-time admin approval before the Microsoft option works for their staff. If you're the IT administrator who's been sent this page, the next section is for you and takes about two minutes.

For IT administrators: approve Structured AI for Microsoft sign-in

Before a new application can sign in users from your organization, Microsoft Entra ID requires an administrator to approve it once, for everyone (tenant-wide admin consent). Until that happens, staff who try the Microsoft option see "Need admin approval" and are blocked.

The approval link

Signed in to Microsoft as an administrator, open this link and click Accept:

Approve Structured AI for your organization

The same link works for every organization, and it doesn't expire. If your Structured AI contact sent you an organization-specific link instead, use that one - it does exactly the same thing on the Microsoft side, and additionally lets us confirm the approval on our end before anyone from your firm has signed in.

What you're approving

The consent screen shows exactly what's being granted. For reference:

ApplicationStructured AI
PublisherStructured Software Inc - a Microsoft verified publisher (domain getstructured.ai)
Permission requestedMicrosoft Graph User.Read (delegated): Sign in and read user profile
What that gives usThe signed-in user's name and email address, so an account can be created and matched to your organization
What it does not give usAnything else. No mailboxes, no files, no Teams or SharePoint, no directory browsing, no access when the user isn't signed in

This is the standard Microsoft admin consent flow for Entra ID applications; nothing is installed and no configuration is written to your tenant beyond the consent record itself.

Steps

  1. Use an account in your organization's own Microsoft tenant that holds a role able to grant tenant-wide consent: Global Administrator, Privileged Role Administrator, Cloud Application Administrator, or Application Administrator.
  2. Open the approval link above. If you're signed in to several Microsoft accounts, pick the administrator account when prompted.
  3. Review the permission (it's the single User.Read scope described above) and click Accept.
  4. You'll be returned to app.getstructured.ai/login with a confirmation banner. From that moment everyone at your firm can sign in with their normal work account - no per-user setup, no invitations needed.
Use an admin account in your company tenant

The approval must be granted from an account in your organization's own Microsoft tenant. Clicking Accept from a personal Microsoft account, or from a guest account in another company's tenant, completes the screen but doesn't approve the app for your firm, and staff will still see "Need admin approval".

Afterwards: where it lives, and how to restrict or undo it

Once approved, Structured AI appears under Microsoft Entra admin center → Enterprise applications. From there you can:

  • Review the granted permissions under Permissions - you should see only User.Read.
  • Limit who can sign in. Under Properties, set Assignment required to Yes, then add the users or groups who should have access under Users and groups. By default anyone in your tenant can sign in, which is what most firms want; assignment is there if you'd rather allow-list.
  • Apply Conditional Access like any other enterprise app, e.g. require MFA or a compliant device.
  • Remove it at any time by deleting the enterprise application. New sign-ins for your staff stop immediately; sessions already open are covered by the step below.

Offboarding a leaver

Disabling someone's Microsoft account stops them signing in to Structured AI again, immediately and permanently. It does not end a session they already have open: Structured AI issues its own sign-in cookie when they authenticate, and that cookie stays valid for up to 7 days without going back to Microsoft. Someone who leaves with a browser already signed in can therefore keep working in it until it expires.

Two ways to close that window:

  1. Ask us to revoke their sessions - email support@getstructured.ai with the person's email address. We force every existing session for that user to re-authenticate, which they then cannot do. This takes effect straight away.
  2. Do nothing and wait - access ends on its own within 7 days of their last sign-in.

For a departure where the timing matters (a dismissal, a dispute, anything where the 7-day tail is not acceptable), use option 1 and treat the Entra disable as the first of two steps rather than the whole job.

Google Workspace organizations

Sign in directly with the Google option - no admin step is usually required. If your Workspace is configured to block unreviewed third-party apps, your Google admin can allow Structured AI from the Workspace admin console (Security → API controls → App access control), and sign-in works immediately after.

Troubleshooting

  • "Need admin approval" when signing in with Microsoft - the consent step above hasn't been completed yet. Send your Microsoft administrator a link to this page.
  • The admin accepted, but staff are still blocked - check the approval was granted from an admin account in your company's own tenant (see the caution above), then have the user fully sign out of Microsoft and try again. If Assignment required is on for the app, confirm the user or their group is assigned.
  • The admin sees "AADSTS" error text after clicking Accept - take a screenshot of the full message and send it to your Structured AI contact; it's almost always a tenant policy we can talk you through.
  • IT blocks all third-party sign-ins and won't approve apps - use the Email link option on the sign-in screen; it needs nothing from your IT team.
  • Anything else - email your Structured AI contact or info@getstructured.ai and we'll get on a call with your IT team. We do this regularly and it's usually sorted in one short session.
tip

Setting up the Revit add-in too? That's a separate, equally quick step - see Connect Revit.