Microsoft Entra ID Time Tracking Integration

WebWork connects to Entra ID in two places. Admins bring members into the workspace from the directory, and they can also use it for SSO and sign in to WebWork with an email address only.

Microsoft Entra ID time tracking integration joining the Entra ID and WebWork apps

Bring Members In From the Entra ID Directory

Connecting the two systems puts WebWork member accounts and WebWork sign-in on the Microsoft Entra ID tenant.

Enable the integration to import your Entra ID directory members to WebWork under Integrations > Microsoft Entra ID, with each person's name, email address, and status. Admins select the people they want and invite them into the workspace, so accounts come from the directory rather than being created by hand.

Profile updates made in the directory are pushed to WebWork, and deactivating a person in Entra ID removes their WebWork login access while keeping their information as an inactive user.

WebWork invite screen listing Entra ID directory members ready for Microsoft Entra ID time tracking

Sign In to WebWork Through Microsoft Entra ID

SSO with Microsoft Entra ID lets team members sign in with their Entra ID email address instead of a separate WebWork password. Single sign-on is enabled in WebWork under Settings > Single Sign-On, and an existing WebWork user is linked to their Entra ID account automatically when the email address matches.

Entra ID email address matched to a WebWork account for Microsoft Entra ID time tracking sign-in

How the Microsoft Entra ID Time Tracking Sync Works

The Microsoft Entra ID integration allows you to import and sync members. In the meantime, if you are using SCIM and SAML, you can use Entra ID to handle provisioning and sign-in as well.

The App Integration: Members and Auto-Sync

The app integration is done through Integrations > Microsoft Entra ID, in the Users & Authentication category. Under Members tab, you can invite your co-workers, see the directory of members with Member name, Email, and Status alongside a member count, a search field, and a filter. Under the Auto-Sync tab, you can select between sync options: No sync, Auto-Sync, and Auto-sync & auto-remove. No sync is the default, so directory syncing starts only once an admin selects one of the other two. The integration is available on every plan, with one integration included on Pro and all integrations included from Plus up.

WebWork Auto-Sync tab showing the Microsoft Entra ID time tracking sync options

Use Microsoft Entra ID for Single Sign-On

Single sign-on is set up from Settings > Single Sign-On in WebWork, with SCIM first and SAML second. SCIM connects using the SCIM Tenant URL and SCIM Secret Token from that screen, and once it is running, Entra ID handles four member operations: push new users, push profile updates, push user deactivation, and reactivate users. Deactivating someone removes their login access and keeps their information as an inactive user. SAML connects using the SAML Identifier (Entity ID) and SAML Reply URL (Assertion Consumer Service URL) from the same screen, plus the App Federation Metadata URL from Entra ID, and from then on members sign in through the tenant. Single sign-on is available on the Premium plan, and the Workspace Owner or an Executive Manager enables it.

Built for Teams Who Run on Microsoft Entra ID

IT and Security Administrators Running Microsoft 365

IT and security administrators use the Microsoft Entra ID integration to keep WebWork accounts on the same directory as every other application in the tenant. Provisioning, profile updates, and deactivation are handled in Entra ID, so one directory decides who holds a WebWork account and one sign-in decides how they reach it.

HR and People Ops Teams Handling Onboarding and Offboarding

HR and People Ops teams use the integration to bring new hires into WebWork as part of the same onboarding that creates their directory account. Offboarding runs the same way: deactivating a person in Entra ID removes their WebWork login access and keeps their information as an inactive user.

Distributed and Multi-Site Operations Teams

Distributed and multi-site operations teams use the integration to onboard people across locations without maintaining a second user list. Members are invited from the directory list inside WebWork, and the hours they track appear on timesheets and reports under the account the directory provided.

How to Set Up Microsoft Entra ID Time Tracking in WebWork

There are two methods for enabling the Microsoft Entra ID time tracking integration:

Path 1

The App Integration

  1. In WebWork, go to Integrations > Microsoft Entra ID > Enable.
  2. Open the Members tab to see your directory members with Member name, Email, and Status.
  3. Select the members to invite into the workspace, then open the Auto-Sync tab and choose No sync, Auto-Sync, or Auto-sync & auto-remove.
Path 2

Single Sign-On

  1. In WebWork, go to Settings > Single Sign-On.
  2. In Microsoft Entra ID, create the application through Create your own application, then paste the SCIM Tenant URL and SCIM Secret Token into its provisioning settings.
  3. Set up SAML next, pasting the SAML Identifier (Entity ID) and SAML Reply URL (Assertion Consumer Service URL) into Entra ID and the App Federation Metadata URL back into WebWork.

From Microsoft Entra ID Accounts to Timesheet-Ready Hours

Microsoft Entra ID decides who holds an account and who can sign in. WebWork records the hours those members work and turns them into timesheets.

WebWork directory list with members imported from Entra ID for Microsoft Entra ID time tracking

Onboarding runs from the directory, with members invited from the Entra ID list instead of being created by hand in the workspace.

WebWork sign-in screen with Continue with Entra ID for Entra ID SSO time tracking

Entra ID SSO time tracking uses the tenant's own sign-in, so members reach WebWork with their email address.

WebWork timesheet of hours tracked by Microsoft Entra ID members, ready to approve

Hours tracked by those members appear on timesheets and in reports without a separate round of user administration.

24/7 Global Customer Support

Ranked Top Quality on G2

99.9% Uptime in the Last 90 Days

Advanced Security and Data Privacy

FAQ

The WebWork and Entra ID integration has two parts that are set up separately. The app integration is under Integrations in WebWork and it is where admins invite directory members into the workspace and choose an Auto-Sync option. Single sign-on is meant for stronger security measures and you need to configure it from Microsoft Entra ID with SCIM and SAML. It governs how those members authenticate and how their accounts are provisioned.

The app integration is available on every plan, with one integration included on Pro and all integrations included from Plus up. Single sign-on, including SCIM provisioning and SAML, is available on the Premium plan and is enabled by the Workspace Owner or an Executive Manager.

Yes. Microsoft Entra ID is the current name for what was previously Azure Active Directory, so an azure ad time tracking integration and this one are the same thing. Everything on this page applies to the tenant you administer in the Microsoft Entra admin center.

Yes. When single sign-on is enabled for selected WebWork users, they can only sign in through Microsoft Entra ID using their email address only. Their account itself stays the same but their previous WebWork passwords will no longer work.

Deactivating a person in Microsoft Entra ID removes their WebWork login access and keeps their information in the workspace as an inactive user. Reactivating them in Entra ID restores the account.

Voted Top Time Tracking Software of 2026

Start Microsoft Entra ID Time Tracking with WebWork

Integrate Microsoft Entra ID with WebWork

No credit card Cancel anytime