Skip to main content

Spellbook Authentication Migration — Guide for IT Admins & Security Teams

M
Written by Mustafa Jamal

What's changing, and why

Spellbook is moving the Word Add-in from using your Microsoft Office email to an explicit, account-based sign-in. The same login system being used in Spellbook Associate.

The goal is one account and one consistent, more secure sign-in experience across the Word Add-in and Associate.

What this does not affect:

  • Your data: Existing playbooks, prompts, and Projects are preserved and carried over automatically — no re-entry needed.

  • How the Add-in is deployed: Deployment/provisioning through the Microsoft 365 Admin Center is unchanged. This migration is about authentication only — how users prove who they are, not how the app gets to their machine.


What end users will see

  • A short in-app banner ahead of the cutover, with a "Learn more" link.

  • After the change goes live, users see a new Spellbook sign-in screen — but only on their next reload, not mid-session. They'll need to quit and reopen Word (or refresh the add-in) to see it.

  • If your organization already relies on Microsoft SSO, Spellbook will restrict your users to "Continue with Microsoft" only ahead of the cutover, to preserve your existing sign-in experience. Most users in this situation won't notice a functional change beyond the extra click.

  • Otherwise, users choosing to sign in are offered up to four methods (see Section 4).

  • Existing users may see two new options in the Add-in menu: Sign out and Merge Accounts.

    • Automatic merge: If the Microsoft identity a user signs in with is different from their existing Spellbook account, and that Microsoft identity already exists as a separate account in our database, Spellbook merges the two accounts automatically in the background. The user gets a confirmation email once it's done (they may need to reload the app afterward).

    • Manual merge: A user can trigger a merge at any time via the Merge Accounts menu option, then signing in to the Microsoft account they want to merge in.


What IT admins need to do

A. Sign-in configuration

If your organization would like to restrict the sign-in methods available to its users or configure a third-party SSO connection, please contact the Spellbook Support team.

Through a support request, your organization can:

  • Restrict available sign-in methods to any combination of email and password, email verification code, Google, or Microsoft.

  • Request assistance configuring SSO through a third-party identity provider.

These settings govern authentication and are separate from the Microsoft Entra ID configuration described below, which governs deployment and consent for the Spellbook Add-in within Microsoft 365.

B. Microsoft Entra ID — Enterprise Applications

During the rollout, you may see two Spellbook-related Enterprise Applications in Entra ID:

  • Spellbook Word Add-in (existing) - Required for legacy Office SSO authentication, deployment of the Word Add-In, and connection to OneDrive for Spellbook Library

  • Spellbook - new — this is the shared authentication backend now used by the Add-in as well

    • Note: the Spellbook Associate app has been renamed to Spellbook — new tenants will see it as "Spellbook," while existing tenants will continue to see "Spellbook Associate."

Action needed:

  1. Grant Admin Consent to both Enterprise Applications.

  2. Confirm affected users are listed under Users and Groups for both apps. If you assign access via security groups, add users to the relevant group(s) for both.

New users will be prompted to create a Spellbook account the first time they sign in under the new flow — this is expected, doesn't create a duplicate license, and existing playbooks/prompts are carried over automatically.


Common errors and how to resolve them

Symptom

Likely cause

Resolution

"Ask your tenant administrator to provide consent for this application" (AADSTS90097)

Admin Consent hasn't been granted (or re-granted) for one of the two Enterprise Apps

In Entra ID → Enterprise Applications, locate both Spellbook apps and grant Admin Consent to each

User sees the Add-in icon in Word but is stuck on an approval/justification screen

Same root cause as above — often specifically the newer Spellbook Associate app not yet consented

Same fix — check consent status on both apps

Add-in is deployed and visible, but the user still can't sign in

Deployment (Enterprise App assignment) and authentication (WorkOS/consent) are handled separately

Confirm the user is in Users & Groups for both apps, and that consent has been granted — deployment alone doesn't guarantee sign-in works

"This email is not available" on sign-up

An account was already provisioned for the user ahead of time using their old email; they need to recover that existing account rather than create a new one

Have the user recover their account via Forgot password (email/password), or by signing in with email magic code, Google Sign-In, or Microsoft Sign-In


FAQ

How will our users know if SSO is set up for them?

They generally won't need to know — this is managed on the backend by your IT team and Spellbook.

How do we set up SSO?

An Admin requests this to be setup by our Support team at success@spellbook.com.

Does this change how we deploy the Add-in or provision access?

No. Deployment and provisioning in Microsoft 365 are unchanged. This migration affects sign-in only.

Will our current SSO setup keep working through the transition?

We've tried to restrict existing users to Microsoft Sign-In to preserve your experience through the cutover. If your organization requires SSO or specific authentication methods configured, contact your Spellbook Customer Success contact to get an admin portal link and configure this before rollout.

Will our data — playbooks, prompts, etc. — be affected?

No. Everything is preserved and carried over to the new account automatically.


Pre-migration checklist

  • Confirm with your Spellbook Customer Success contact whether you require SSO or specific authentication methods configured.

  • Reach out to Spellbook support to get SSO setup

  • When prompted in Entra ID, grant Admin Consent to both "Spellbook Word Add-in" and "Spellbook Associate."

  • Verify affected users are in Users & Groups for both apps.

  • Let end users know they may need to sign in again on next launch, and that a "Merge Accounts" prompt is expected and safe to complete if they see it.


Getting help

Contact your Spellbook Customer Success contact or Support for SSO connection setup or any admin-consent issue that persists after working through Section 5.

If you have any trouble during this process, please don't hesitate to reach out to our Support team at success@spellbook.com and we can help get you set up right away

Did this answer your question?