Authentication
Authentication
Sign in
Enter your email and password on the login page and click Sign in.
After a successful login you land on your preferred workspace.

If you forgot your password, use "Forgot password?" to receive a recovery email and set a new one.
Multi-factor authentication (MFA)
MFA adds a second verification step with a temporary code (TOTP) generated by an authenticator app such as Microsoft Authenticator or Google Authenticator.
Enable MFA
1. Open your security settings
Go to your profile and select Enable MFA.
2. Scan the QR code
Scan the QR code with your authenticator app.
3. Confirm with a code
Enter the 6-digit code shown by the app to complete the enrollment.
Sign in with MFA
Once MFA is active, after entering your email and password Crestone asks for the current code from your authenticator app. Enter it and click Submit.
If you lose access to your authenticator app, contact your administrator to reset the second factor.
Sign in with Azure AD (SSO)
If your company enabled single sign-on, the login page shows a "Sign in with Microsoft" option.
- On your first access, Crestone creates your profile automatically and assigns you to your default workspace.
- Authentication is completed by Azure AD; you are returned to Crestone at
/auth/callbackwith your session started.

SSO availability depends on your installation. Ask your administrator if the option is not visible.
Session lifetime
Your session token is renewed automatically while you work; you don't need to sign in again during normal use. When the session can no longer be renewed (for example after a long period of inactivity), Crestone redirects you to the login page.