Provisioning
After federation is configured, you need to provision users in BlokSec so they can authenticate. Provisioning creates a BlokSec account for each user and sends them an invitation to set up the BlokSec authenticator app on their phone.
How provisioning works
Section titled “How provisioning works”Each user needs two things:
- A BlokSec account linked to their Microsoft 365 email address
- The BlokSec app installed on their phone with their account activated
When a user signs in to Microsoft 365, BlokSec looks up their account by email address. If the account exists and is active, BlokSec sends a push notification (or displays a QR code) for the user to approve. If the account doesn’t exist, the user sees an error.
Invite users
Section titled “Invite users”- In the BlokSec admin console, navigate to your Microsoft 365 application
- Go to the Users tab
- Click Invite User
- Enter the user’s email address (must match their Microsoft 365 email)
- Click Send Invitation
The user will receive an invitation email with a QR code and a link. They can either:
- Tap the link on their phone to open it in the BlokSec app
- Scan the QR code with their phone’s camera if they received the email on another device
Bulk provisioning
Section titled “Bulk provisioning”For larger organizations, you can invite multiple users at once:
- Go to the Users tab
- Click Bulk Invite
- Upload a CSV file with one email address per row
- Click Send Invitations
User activation
Section titled “User activation”After receiving the invitation, the user:
- Downloads the BlokSec app (if they haven’t already)
- Opens the invitation link or scans the QR code
- Authenticates with their phone’s biometrics (Face ID, fingerprint, or device PIN)
- Their account is now active and ready for passwordless sign-in
You can track which users have activated their accounts in the Users tab. Users who haven’t activated yet will show as “Invited”.
Removing a user
Section titled “Removing a user”To remove a user from BlokSec:
- Go to the Users tab
- Find the user and click the menu icon
- Select Remove User
The user will no longer be able to authenticate with BlokSec. If the domain is still federated, they won’t be able to sign in to Microsoft 365 until they are re-provisioned or federation is removed.