How setup works
1
You send us what we need
The email domains you want to claim, your Microsoft Entra tenant ID, and the two choices in the next section. The full list is below.
2
We claim and verify your domains
Mangrove verifies each domain you own. There is no DNS record for you to add and nothing to configure inside your tenant.
3
We configure the connection
Mangrove sets up the connection with the provisioning and password options you chose.
4
We tell you it is live
Nothing changes for your users until we confirm the connection is enabled. Sign-in switches over at that point.
What to send your account team
To start, send them:- The email domains you want to claim, and confirmation that you own them. Mangrove verifies each one; there is no DNS record for you to add.
- Your Microsoft Entra tenant ID. Find it in the Microsoft Entra admin centre under Overview, or at Microsoft’s instructions for locating your tenant ID.
- Whether new users should be created automatically or by invitation only. See below.
- The default role for automatically created users, if you choose automatic. See User roles.
- Whether the sign-in page should still offer a password option.
The three decisions
Which domains you claim
A connection covers the email domains your organization owns. A domain can be claimed by only one organization across Mangrove, so if a subsidiary or an acquired company has already claimed one you want, raise it with your account team rather than assuming it is free. Public mailbox domains such asgmail.com and outlook.com cannot be claimed.
Whether accounts are created automatically
By default they are not. An invitation is still required, so on day one the only people who can sign in are those who already have access to your Mangrove account, plus anyone holding an invitation to it. Ask your account team to turn on automatic creation and anyone in your directory who signs in gets an account, with the default role you chose. That automatic role can never be Admin. An invitation can still carry any role, including Admin, because a person decided to send it. Turn it on where directory membership already means somebody should have access to your carbon data. Leave it off where it does not.Whether the sign-in page still offers a password
A connection can be enforced, which removes the “sign in with a password instead” option from the sign-in page.What changes for your users
The sign-in page asks for an email address first.- An address at a claimed domain goes on to Microsoft and comes back signed in.
- Any other address gets the password field, with the address already filled in.
When somebody leaves
Revoke their access in Mangrove as part of offboarding. Mangrove does not sync with your directory, so removing them there does not remove them here.What Mangrove reads from your directory
Sign-in requests theopenid, profile and email scopes only, so Mangrove sees the signed-in person’s name and email address and nothing else.