Sladd og Microsoft Entra ID

Denne siden er skrevet for IT-administratoren hos kunden. Den forklarer nøyaktig hva Sladd ber om tilgang til i Microsoft Entra ID, hvordan appen godkjennes, hvordan de ansatte logger inn, og hvor data havner. English version below.

Kort oppsummert

  • Sladd ber om navn og e-postadresse — det Microsoft kaller grunnleggende OpenID-profil. Ingenting mer.
  • Sladd får ikke lesetilgang til e-post, filer, SharePoint, kalender, kontakter eller katalogen deres.
  • Dokumentene de ansatte sladder, behandles i deres egen nettleser og lastes aldri opp til oss.
  • Innlogging er eneste kobling mellom Sladd og tenanten deres. Sladd kaller ikke Microsoft Graph etter at innloggingen er ferdig.

Appens identitet

Verdiene under er de dere kan sammenligne med det tenanten viser under Enterprise applications.

AppnavnSladd
UtgiverVerge Haugen, org.nr. 935 158 648 (verifisert utgiver i Microsoft Entra)
Partner-ID (MPN)7153662
Application (client) IDf7897416-c1ab-4203-9b0a-aeeb51e7a5fe
KontotyperArbeids- og skolekontoer i enhver Entra-katalog (multitenant). Personlige Microsoft-kontoer (outlook.com, hotmail.com) støttes ikke.
Autoritethttps://login.microsoftonline.com/organizations
ProtokollOpenID Connect på Microsofts identitetsplattform v2.0, authorization code flow. Konfidensiell klient — hemmeligheten ligger på server, aldri i nettleseren.
Redirect URIhttps://nnsydnncsdjqqssyccuj.supabase.co/auth/v1/callback
Innloggingssidehttps://sladd.no/login

Tillatelser appen ber om

Alle tillatelsene er delegerte — de gjelder den innloggede brukeren selv, og gir aldri tilgang til andre brukeres data. Sladd ber ikke om noen applikasjonstillatelse (app-only), og har derfor ingen tilgang til tenanten når ingen er logget inn.

TillatelseTypeHvorfor Sladd trenger den
openidDelegertUtfører selve innloggingen. Uten den kan vi ikke bekrefte hvem brukeren er.
profileDelegertGir visningsnavnet, slik at den ansatte ser hvilken bruker hun er logget inn som.
emailDelegertE-postadressen er kontoidentiteten i Sladd, og domenet i den avgjør hvilken organisasjon kontoen knyttes til.
Samtykkeskjermen kan i tillegg vise «Logg deg på og les profilen din» (User.Read). Det er standardtillatelsen Entra legger inn i enhver ny app-registrering. Sladd kaller ikke Microsoft Graph og bruker den ikke til noe.

Sladd ber ikke om Mail.Read, Mail.Send, Files.Read.All, Sites.Read.All, Calendars.Read, Contacts.Read, Directory.Read.All eller User.Read.All — og ingen skrivetillatelser overhodet. Sladd henter ingen data fra Microsoft 365 og skriver ingenting tilbake til katalogen deres.

Krav og lisens

  • Entra-lisens: enhver utgave, inkludert Microsoft Entra ID Free. P1 eller P2 er ikke nødvendig.
  • Rolle for godkjenning: Application Administrator, Cloud Application Administrator eller Global Administrator. De ansatte trenger ingen rolle.
  • Tilordning i Entra: ikke nødvendig. Tilgang styres av e-postdomenet, ikke av gruppetildeling.
  • Hos Sladd: en bedriftsavtale med avtalt setegrense. Uten avtale kan ansatte fortsatt logge inn med Microsoft, men får da gratisplanen.

Slik godkjenner administratoren appen

Mange tenanter har slått av ansattes rett til å samtykke til tredjepartsapper selv. Da møter den ansatte «Trenger godkjenning fra administrator» ved første innlogging. Én godkjenning dekker hele tenanten, og etter den ser ingen ansatte samtykkeskjermen igjen.

  1. 1Logg inn i nettleseren med en konto som har en av rollene over.
  2. 2Åpne lenken under.
  3. 3Les gjennom tillatelsene som vises, og velg «Godta».
https://login.microsoftonline.com/organizations/adminconsent?client_id=f7897416-c1ab-4203-9b0a-aeeb51e7a5fe

Åpne samtykkelenken →

Etter godkjenningen ligger «Sladd» under Identity → Applications → Enterprise applications i tenanten deres. Samme sted kan dere når som helst se, endre eller trekke tilbake tilgangen.

Foretrekker dere å gjøre det fra portalen i stedet for lenken: la én ansatt forsøke å logge inn, gå deretter til Identity → Applications → Enterprise applications → Sladd → Security → Permissions → Grant admin consent.

Slik logger de ansatte inn

  1. 1Gå til sladd.no/login.
  2. 2Velg «Logg inn med Microsoft».
  3. 3Velg arbeidskontoen i Microsoft-dialogen.
  4. 4Første innlogging oppretter Sladd-kontoen automatisk. Ingen registrering, intet eget passord å huske.
Innloggingssiden på sladd.no/login. «Logg inn med Microsoft» er knappen nederst.
Innloggingssiden på sladd.no/login. «Logg inn med Microsoft» er knappen nederst.

Pilottest: la to–tre brukere gjøre stegene over. De skal lande i verktøyet, og organisasjonen skal vises i toppraden. Ser de gratisplanen i stedet, er domenet ennå ikke registrert på avtalen — send det til post@sladd.no.

Tilgang og setegrense

  • Sladd kobler kontoen til organisasjonen ved å sammenligne domenet i den verifiserte e-postadressen mot domenet i avtalen. Innlogging via Entra er alltid verifisert av Microsoft, så domenet kan ikke forfalskes.
  • Alle med bedriftens e-postdomene får tilgang automatisk, opp til den avtalte setegrensen. Ingen invitasjoner, ingen brukerlister å vedlikeholde.
  • Bruker nummer «grense + 1» får ikke plass og faller til gratisplanen med meldingen «Setegrensen er nådd, kontakt administrator». Ingen data går tapt, og plassen frigjøres om noen fjernes.
  • Setegrensen utvides ved å ta kontakt med oss på post@sladd.no.

Når en ansatt slutter

  • En deaktivert eller slettet Entra-konto kan ikke logge inn i Sladd igjen. For Microsoft-brukere finnes ingen egen passordkonto hos oss, så det finnes ingen vei utenom Entra.
  • En Sladd-økt som allerede er åpen i nettleseren, varer til brukeren logger ut eller økten utløper. Skal tilgangen stanses umiddelbart, be oss fjerne medlemskapet på post@sladd.no — det tar effekt med én gang.
  • Hele tenanten kan når som helst trekke tilbake samtykket: Enterprise applications → Sladd → Properties → Delete. Da slutter all Microsoft-innlogging til Sladd å virke for alle ansatte.

Hvor data lagres

  • Dokumentene lagres aldri. Sladdingen skjer i den ansattes egen nettleser. Filene lastes ikke opp, og vi kan ikke se innholdet. Vi kan derfor ikke utlevere et dokument selv om vi ble bedt om det — vi har det ikke.
  • Kontodata (e-postadresse, navn, abonnementsstatus og forbrukstall) ligger hos Supabase i Stockholm (eu-north-1).
  • Drift av nettstedet skjer hos Vercel i Stockholm (arn1).
  • Ingen analyseverktøy, ingen sporingsskript. Én informasjonskapsel, som holder brukeren innlogget.
  • Full erklæring: sladd.no/personvern. Databehandleravtale får dere ved å be om den på post@sladd.no.

Feilsøking

MeldingKodeLøsning
Trenger godkjenning fra administratorAADSTS65001 / 90094Tenanten tillater ikke at brukere samtykker selv. En administrator åpner samtykkelenken over.
Kontoen finnes ikke i katalogenAADSTS50020Brukeren forsøkte med en personlig Microsoft-konto. Bruk arbeids- eller skolekontoen.
Applikasjonen ble ikke funnetAADSTS700016Appen er ikke godkjent i tenanten, eller er slettet fra Enterprise applications. Kjør samtykkelenken på nytt.
Ikke tildelt en rolleAADSTS50105Appen står med «Assignment required = Yes» i tenanten. Tildel brukerne, eller sett innstillingen til No.
Setegrensen er nåddFra SladdFlere har logget inn enn avtalen dekker. Kontakt post@sladd.no for å utvide.
Gratisplan etter innloggingFra SladdE-postdomenet er ikke registrert på avtalen. Send domenet til post@sladd.no.

Kontakt

Teknisk kontakt og brukerstøtte for denne integrasjonen: post@sladd.no. Vi svarer normalt innen én virkedag. Oppgi gjerne domenet deres og hva den ansatte så på skjermen.

Sladd and Microsoft Entra ID

This page is written for the customer’s IT administrator. It states exactly what Sladd asks for in Microsoft Entra ID, how the application is approved, how employees sign in, and where data is stored.

In short

  • Sladd asks for name and email address — what Microsoft calls the basic OpenID profile. Nothing else.
  • Sladd does not get read access to mail, files, SharePoint, calendars, contacts or your directory.
  • The documents your employees redact are processed in their own browser and are never uploaded to us.
  • Sign-in is the only connection between Sladd and your tenant. Sladd does not call Microsoft Graph once sign-in has completed.

Application identity

Compare these values with what your tenant shows under Enterprise applications.

Application nameSladd
PublisherVerge Haugen, Norwegian org. no. 935 158 648 (verified publisher in Microsoft Entra)
Partner ID (MPN)7153662
Application (client) IDf7897416-c1ab-4203-9b0a-aeeb51e7a5fe
Account typesWork and school accounts in any Entra directory (multitenant). Personal Microsoft accounts (outlook.com, hotmail.com) are not supported.
Authorityhttps://login.microsoftonline.com/organizations
ProtocolOpenID Connect on the Microsoft identity platform v2.0, authorization code flow. Confidential client — the secret is held server-side, never in the browser.
Redirect URIhttps://nnsydnncsdjqqssyccuj.supabase.co/auth/v1/callback
Sign-in pagehttps://sladd.no/login

Permissions requested

Every permission is delegated — it applies to the signed-in user only and never grants access to other users’ data. Sladd requests no application (app-only) permission, and therefore has no access to your tenant when nobody is signed in.

PermissionTypeWhy Sladd needs it
openidDelegatedPerforms the sign-in itself. Without it we cannot establish who the user is.
profileDelegatedProvides the display name, so the employee can see which account they are signed in as.
emailDelegatedThe email address is the account identity in Sladd, and its domain determines which organisation the account is linked to.
The consent screen may additionally list “Sign you in and read your profile” (User.Read). That is the default permission Entra adds to every new app registration. Sladd does not call Microsoft Graph and does not use it.

Sladd does not request Mail.Read, Mail.Send, Files.Read.All, Sites.Read.All, Calendars.Read, Contacts.Read, Directory.Read.All or User.Read.All — and no write permissions of any kind. Sladd reads no data from Microsoft 365 and writes nothing back to your directory.

Requirements and licensing

  • Entra licence: any edition, including Microsoft Entra ID Free. P1 or P2 is not required.
  • Role required to approve: Application Administrator, Cloud Application Administrator or Global Administrator. Employees need no role.
  • Assignment in Entra: not required. Access is governed by the email domain, not by group assignment.
  • On the Sladd side: a business agreement with an agreed seat limit. Without one, employees can still sign in with Microsoft but land on the free plan.

Many tenants disable end-user consent to third-party applications. Employees then see “Need admin approval” on first sign-in. One approval covers the whole tenant, and no employee sees the consent screen afterwards.

  1. 1Sign in to the browser with an account holding one of the roles above.
  2. 2Open the link below.
  3. 3Review the permissions shown and select Accept.
https://login.microsoftonline.com/organizations/adminconsent?client_id=f7897416-c1ab-4203-9b0a-aeeb51e7a5fe

Open the admin consent link →

After approval, “Sladd” appears under Identity → Applications → Enterprise applications in your tenant. From there you can review, change or revoke the access at any time.

To do this from the portal instead of the link: have one employee attempt to sign in, then go to Identity → Applications → Enterprise applications → Sladd → Security → Permissions → Grant admin consent.

How employees sign in

  1. 1Go to sladd.no/login.
  2. 2Select Logg inn med Microsoft (“Sign in with Microsoft” — the interface is Norwegian).
  3. 3Pick the work account in the Microsoft dialog.
  4. 4The first sign-in creates the Sladd account automatically. No registration, no separate password.
The sign-in page at sladd.no/login. «Logg inn med Microsoft» is the bottom button.
The sign-in page at sladd.no/login. «Logg inn med Microsoft» is the bottom button.

Pilot test: have two or three users complete the steps above. They should land in the tool with the organisation shown in the top bar. If they see the free plan instead, the domain is not yet registered on the agreement — send it to post@sladd.no.

Access and seat limit

  • Sladd links the account to the organisation by matching the domain of the verified email address against the domain on the agreement. Entra sign-in is always verified by Microsoft, so the domain cannot be spoofed.
  • Everyone with the company email domain gets access automatically, up to the agreed seat limit. No invitations, no user lists to maintain.
  • User number “limit + 1” does not get a seat and falls back to the free plan with the message “Setegrensen er nådd, kontakt administrator” (seat limit reached). No data is lost, and a seat is freed if someone is removed.
  • Contact us at post@sladd.no to raise the seat limit.

When an employee leaves

  • A disabled or deleted Entra account cannot sign in to Sladd again. Microsoft users have no separate password account with us, so there is no route around Entra.
  • A Sladd session already open in the browser lasts until the user signs out or the session expires. To cut access immediately, ask us to remove the membership at post@sladd.no — it takes effect at once.
  • The whole tenant can revoke consent at any time: Enterprise applications → Sladd → Properties → Delete. Microsoft sign-in to Sladd then stops working for every employee.

Where data is stored

  • Documents are never stored. Redaction runs in the employee’s own browser. Files are not uploaded and we cannot see their contents. We could not hand over a document even if asked — we do not have it.
  • Account data (email address, name, subscription status and usage counts) is held by Supabase in Stockholm (eu-north-1).
  • The website is hosted by Vercel in Stockholm (arn1).
  • No analytics, no tracking scripts. One cookie, which keeps the user signed in.
  • Full statement (Norwegian): sladd.no/personvern. A data processing agreement is available on request at post@sladd.no.

Troubleshooting

MessageCodeResolution
Need admin approvalAADSTS65001 / 90094The tenant does not allow user consent. An administrator opens the admin consent link above.
Account does not exist in directoryAADSTS50020The user tried a personal Microsoft account. Use the work or school account instead.
Application not foundAADSTS700016The app is not consented in the tenant, or was deleted from Enterprise applications. Run the admin consent link again.
Not assigned to a roleAADSTS50105The app is set to «Assignment required = Yes» in the tenant. Assign the users, or set it to No.
Seat limit reachedFrom SladdMore people signed in than the agreement covers. Contact post@sladd.no to extend it.
Free plan after sign-inFrom SladdThe email domain is not registered on the agreement. Send it to post@sladd.no.

Contact

Engineering and support contact for this integration: post@sladd.no. We normally reply within one business day. Please include your domain and what the employee saw on screen.