Microsoft 365

Microsoft 365 Login: How to Sign In to MS 365

Sign in to Microsoft 365 at microsoft365.com or office.com using your work email address and password. If your organisation uses MFA, you'll also complete a verification step. This guide covers sign-in on desktop, browser and mobile, plus troubleshooting for the most common Microsoft 365 login problems.

AT

AMVIA Team

Editorial

5 min read·Mar 2026

The AMVIA Team | 5 min read · Mar 2026

A login screen looks trivial. The decisions behind it — who can sign in, from which device, with which second factor — are where most Microsoft 365 tenants are won or lost on security. We manage these tenants for a living, so this guide answers the practical question ("how do I sign in?") and the one IT Directors actually worry about ("is our sign-in configured safely?"). For the full picture on hardening accounts, start with our Microsoft 365 security pillar.

How do you sign in to Microsoft 365?

The central portal is microsoft365.com. Open it in any browser, click Sign In, and enter the work email tied to your Microsoft 365 licence — usually `yourname@yourcompany.co.uk`. Click Next, type your password, and approve any MFA prompt. You then land on the home screen with app tiles.

You can also reach the same portal at office.com, which redirects to microsoft365.com. Once signed in you'll see tiles for Outlook, Teams, Word, Excel, SharePoint and OneDrive. Clicking a tile opens that app in the browser, or launches the installed desktop version if you have one.

The credential you sign in with is a Microsoft Entra ID (formerly Azure Active Directory) account. That single identity governs every app, every device and every security policy on the tenant — which is why getting the identity layer right matters more than any individual app setting. See how we lock that layer down on our Microsoft Entra ID management page.

How do you sign in to Microsoft 365 desktop apps?

Outlook, Word, Excel and Teams each prompt for sign-in the first time you open them, but they all authenticate against the same Microsoft 365 account. Enter your work email once and the Microsoft identity service signs you into the app — no separate password per app.

On a managed Windows device joined to Microsoft Entra ID, you're often signed in automatically. The device's joined account authenticates the Office apps in the background, so users open Outlook or Word and they simply work — no extra login. This single sign-on behaviour is one of the main reasons to join business devices to Entra ID rather than leaving them as unmanaged personal machines.

That convenience is also a risk if the device itself isn't controlled. A signed-in laptop with no disk encryption or screen lock is an open door to the whole tenant. Device compliance — enforced through Intune — is what turns automatic sign-in from a liability into a control, and it sits at the heart of a properly managed tenant.

How do you access Microsoft 365 on mobile?

Each Microsoft 365 service has its own mobile app. Download them from the App Store (iOS) or Google Play (Android) and sign in once with your work Microsoft 365 account. The Outlook mobile app is the most-used because it combines email, calendar and one-tap Teams meeting joins in a single interface.

The core mobile apps:

  • Microsoft 365 (Office) app — open Word, Excel and PowerPoint documents from one place
  • Outlook — email and calendar
  • Teams — chat, calls and meetings
  • OneDrive — personal file storage
  • SharePoint — shared team document libraries

Mobile is where the security trade-off is sharpest. Staff want email on personal phones; you want company data wiped if that phone is lost. The answer is app-level controls and remote wipe rather than blanket bans — a managed approach to bring-your-own-device that keeps corporate data inside the managed apps.

What do you do if you can't sign in to Microsoft 365?

Most failed sign-ins fall into five categories: forgotten password, locked account, MFA not arriving, account not yet created, or a device blocked by policy. The table below maps each to the fastest fix.

Sign-in problemWhat's happeningFastest fix
Forgotten passwordWrong or expired passwordUse Forgot my password (if Self-Service Password Reset is on) or ask IT
Account lockedToo many failed attempts triggered lockoutWait for the lockout window to clear, or ask an admin to enable
MFA prompt not arrivingNo signal, or Authenticator notification missedOpen Authenticator manually; check phone connectivity
Account doesn't existNo account or licence assigned yetIT must create the account and assign a licence
Device blockedConditional Access requires a compliant deviceEnrol the device in Intune to meet policy

Forgotten password

On the sign-in page, click Forgot my password below the password field. If your organisation has Self-Service Password Reset (SSPR) enabled, verify with a backup method — phone, email or the Authenticator app — and set a new password immediately. If SSPR isn't configured, your IT administrator resets it from the Microsoft 365 Admin Centre. Microsoft documents the full SSPR flow in its reset-password guidance.

Account locked

A locked account usually follows several failed sign-in attempts — Microsoft Entra "smart lockout" protects against password-guessing. Accounts enable automatically after a short lockout period, which an administrator can configure, or an admin can enable the account immediately from Microsoft Entra ID in the admin centre.

MFA not arriving

If no Authenticator notification or text arrives, first check the phone has signal or internet. Then open the Authenticator app manually — there's often a pending approval waiting. If your MFA method has changed (new phone or number), your IT administrator updates your authentication methods. MFA is the single highest-value control on a tenant: the NCSC recommends multi-factor authentication as a baseline defence for online accounts. We set it up correctly on our MFA setup for Microsoft 365 page.

Account doesn't exist

If Microsoft says your account doesn't exist, check you've typed the work email correctly. New starters can't sign in until IT has created the account and assigned a licence — confirm with your manager or IT team.

Device blocked by Conditional Access

A message that your device "doesn't meet requirements" means a Conditional Access policy is requiring a managed or compliant device — common on Business Premium and Enterprise tenants. Your IT team enrols the device in Intune to satisfy the policy. We explain how these rules work on our Conditional Access page.

How do you stay signed in to Microsoft 365 securely?

On a trusted personal or work device, Microsoft 365 keeps you signed in by default, so you don't re-authenticate every session. On shared or public computers, always sign out afterwards and never save the password in the browser. Staying signed in is a convenience you only extend to devices you control.

If you're prompted to re-authenticate or re-do MFA more often than expected, that's usually deliberate. Administrators set session timeouts and Conditional Access token lifetimes to limit how long a stolen session stays valid. It feels like friction; it's a security control. The right balance — long enough sessions that staff aren't nagged, short enough that a lost laptop isn't a free pass — is a policy decision, and it's exactly the kind of tuning our managed Microsoft 365 service handles for clients.

One control people forget at the login layer: backup. Sign-in protects access to data, but it doesn't protect the data itself from accidental deletion or ransomware. Microsoft 365's native retention is not a backup. We cover that gap on our Microsoft 365 backup page.

Need Microsoft 365 Admin Support?

AMVIA manages Microsoft 365 accounts, licences and sign-in policies for UK businesses. Get the admin support your team needs.

Frequently Asked Questions