Key takeaways:
- Every tool in your stack is one more login to create, reset, and remember to disable when someone leaves
- Controvo now supports Microsoft 365 single sign-on, rolling out in beta
- An org admin turns on one organization-wide toggle; after that, members sign in with their Microsoft 365 account instead of a separate Controvo password
- Your Controvo roles still govern access, so who can sign in and what they can do stay two separate decisions
- Offboarding gets simpler: disable someone’s 365 account and their Controvo access goes with it
Another Login Nobody Asked For
Run an MSP and count the logins a new technician needs on day one: the PSA, the RMM, the documentation tool, the 3CX consoles, and now Controvo. Every one is a credential to create, a password policy to satisfy, and one more thing to remember to shut off the day that technician moves on.
The passwords are the easy part. The harder part is the gaps. A separate login for every tool means offboarding is a checklist, and checklists get missed. Someone leaves, their 365 account gets disabled the same afternoon, and the standalone logins scattered across a dozen tools quietly keep working until somebody remembers to hunt them down. For a tool that manages your clients’ phone systems, a login that outlives the employee is exactly the kind of thing you don’t want to leave to memory.
What Shipped
Controvo now supports Microsoft 365 single sign-on. It’s rolling out in beta, and turning it on takes one step.
An organization admin flips a single organization-wide toggle. From then on, your team signs in to Controvo with their Microsoft 365 account. No separate Controvo password to set, rotate, or reset. Each person’s username is simply their 365 email.
Signing in and having permission stay two separate questions, which is the important part. Microsoft 365 decides whether someone can authenticate. Their Controvo role still decides what they can see and do once they’re in. Turning on SSO doesn’t hand everyone the keys; it changes how people prove who they are, not what they’re allowed to touch. The role model you’ve already set up carries over unchanged.
Because sign-in now runs through Microsoft 365, offboarding collapses into something you already do. When a technician leaves and you disable their 365 account, their path into Controvo closes at the same moment. There’s no separate Controvo credential sitting around waiting to be cleaned up.
The Knowledge Base has a new “Signing in with Microsoft 365” section under Team Members & Roles walking through the toggle and what to expect, and the Getting Started guide points to it.
Why This Matters
Single sign-on is table stakes for the tools MSPs trust with client infrastructure, and for good reason. It cuts the number of standalone credentials, it puts authentication behind the identity controls you already run in Microsoft 365 (conditional access, MFA, the rest), and it makes the join-and-leave lifecycle one action instead of a scavenger hunt.
For Controvo specifically, it means the tool managing your fleet of 3CX systems is gated by the same identity you already trust to gate everything else. That’s less to administer and less to get wrong.
This is the first step. It’s in beta now so partners can turn it on, live with it, and tell us where it needs to go next. That feedback loop is the whole point of the pilot.
Try It
Microsoft 365 single sign-on is rolling out in beta now. An org admin can enable it from your organization settings; the Knowledge Base guide walks through the toggle. Open Controvo to set it up. Not on Controvo yet? Get started.
For the full list of what shipped this month, see the July 2026 release notes.