What's changing, and why
Spellbook is moving the Word Add-in from using your Microsoft Office email to an explicit, account-based sign-in. The same login system being used in Spellbook Associate.
The goal is one account and one consistent, more secure sign-in experience across the Word Add-in and Associate.
What this does not affect:
Your data: Existing playbooks, prompts, and Projects are preserved and carried over automatically — no re-entry needed.
How the Add-in is deployed: Deployment/provisioning through the Microsoft 365 Admin Center is unchanged. This migration is about authentication only — how users prove who they are, not how the app gets to their machine.
What end users will see
A short in-app banner ahead of the cutover, with a "Learn more" link.
After the change goes live, users see a new Spellbook sign-in screen — but only on their next reload, not mid-session. They'll need to quit and reopen Word (or refresh the add-in) to see it.
If your organization already relies on Microsoft SSO, Spellbook will restrict your users to "Continue with Microsoft" only ahead of the cutover, to preserve your existing sign-in experience. Most users in this situation won't notice a functional change beyond the extra click.
Otherwise, users choosing to sign in are offered up to four methods (see Section 4).
Existing users may see two new options in the Add-in menu: Sign out and Merge Accounts.
Automatic merge: If the Microsoft identity a user signs in with is different from their existing Spellbook account, and that Microsoft identity already exists as a separate account in our database, Spellbook merges the two accounts automatically in the background. The user gets a confirmation email once it's done (they may need to reload the app afterward).
Manual merge: A user can trigger a merge at any time via the Merge Accounts menu option, then signing in to the Microsoft account they want to merge in.
What IT admins need to do
A. Sign-in configuration — WorkOS Admin Portal
Spellbook will invite an admin on your team to the WorkOS Admin Portal (the same portal used for Associate, if your org already has it). Portal access is only strictly required if your organization wants to configure SSO — you can also use it to restrict available sign-in methods, but that step is optional. From there, your team can:
Restrict which sign-in methods are available to your org (any combination of email/password, email magic link, Google, Microsoft), or
Configure your own SSO connection if you use a third-party identity provider.
This portal governs authentication. It's separate from the Microsoft Entra ID configuration below, which governs deployment and consent for the Add-in inside Microsoft 365.
B. Microsoft Entra ID — Enterprise Applications
During the rollout, you may see two Spellbook-related Enterprise Applications in Entra ID:
Spellbook Word Add-in (existing) - Required for legacy Office SSO authentication, deployment of the Word Add-In, and connection to OneDrive for Spellbook Library
Spellbook Associate (new — this is the shared authentication backend now used by the Add-in as well).
Note: this app has been renamed to Spellbook — new tenants will see it as "Spellbook," while existing tenants will continue to see "Spellbook Associate."
Action needed:
Grant Admin Consent to both Enterprise Applications.
Confirm affected users are listed under Users and Groups for both apps. If you assign access via security groups, add users to the relevant group(s) for both.
New users will be prompted to create a Spellbook account the first time they sign in under the new flow — this is expected, doesn't create a duplicate license, and existing playbooks/prompts are carried over automatically.
Default sign-in methods
Unless your org has restricted sign-in (Section 3A), users can choose from:
Method | Notes |
Email & password | Standard credential sign-in |
Email magic link | No password needed |
Google (OAuth) | Social login |
Microsoft (OAuth) | Social login — this is the path SSO-restricted orgs are limited to |
If a user forgets their password, they can use Forgot password at sign-in, or the email magic link option if it's enabled for your org.
Common errors and how to resolve them
Symptom | Likely cause | Resolution |
"Ask your tenant administrator to provide consent for this application" (AADSTS90097) | Admin Consent hasn't been granted (or re-granted) for one of the two Enterprise Apps | In Entra ID → Enterprise Applications, locate both Spellbook apps and grant Admin Consent to each |
User sees the Add-in icon in Word but is stuck on an approval/justification screen | Same root cause as above — often specifically the newer Spellbook Associate app not yet consented | Same fix — check consent status on both apps |
Add-in is deployed and visible, but the user still can't sign in | Deployment (Enterprise App assignment) and authentication (WorkOS/consent) are handled separately | Confirm the user is in Users & Groups for both apps, and that consent has been granted — deployment alone doesn't guarantee sign-in works |
"This email is not available" on sign-up | An account was already provisioned for the user ahead of time using their old email; they need to recover that existing account rather than create a new one | Have the user recover their account via Forgot password (email/password), or by signing in with email magic code, Google Sign-In, or Microsoft Sign-In |
FAQ
How will our users know if SSO is set up for them?
How will our users know if SSO is set up for them?
They generally won't need to know — this is managed on the backend by your IT team and Spellbook via the WorkOS Admin Portal.
How do we set up SSO?
How do we set up SSO?
Spellbook invites an admin on your team to the WorkOS Admin Portal (the same one used for Associate) to configure it.
Does this change how we deploy the Add-in or provision access?
Does this change how we deploy the Add-in or provision access?
No. Deployment and provisioning in Microsoft 365 are unchanged. This migration affects sign-in only.
Will our current SSO setup keep working through the transition?
Will our current SSO setup keep working through the transition?
We've tried to restrict existing users to Microsoft Sign-In to preserve your experience through the cutover. If your organization requires SSO or specific authentication methods configured, contact your Spellbook Customer Success contact to get an admin portal link and configure this before rollout.
Will our data — playbooks, prompts, etc. — be affected?
Will our data — playbooks, prompts, etc. — be affected?
No. Everything is preserved and carried over to the new account automatically.
Pre-migration checklist
Confirm with your Spellbook Customer Success contact whether you require SSO or specific authentication methods configured.
[ ] Identify who on your team should hold WorkOS Admin Portal access.
[ ] When prompted in Entra ID, grant Admin Consent to both "Spellbook Word Add-in" and "Spellbook Associate."
[ ] Verify affected users are in Users & Groups for both apps.
[ ] Let end users know they may need to sign in again on next launch, and that a "Merge Accounts" prompt is expected and safe to complete if they see it.
Getting help
Contact your Spellbook Customer Success contact or Support for: WorkOS Admin Portal invites, SSO connection setup, or any admin-consent issue that persists after working through Section 5.
If you have any trouble during this process, please don't hesitate to reach out to our Support team at success@spellbook.com and we can help get you set up right away