Signing in
Strata uses Microsoft single sign-on; you sign in with a Microsoft work account and no separate password is created.
Before you start
- Strata accepts Microsoft organizational (work) accounts, not personal Microsoft accounts.
- Your account must already exist in your organization's Strata tenant. Either an admin invited you (see [Invitations]), or your identity provider provisioned you through SCIM, or you accepted an organization invitation via email.
- Allow pop-up windows for the Strata site in your browser. Sign-in runs in a pop-up; if your browser blocks it, the flow ends immediately.
Sign in
- Open the Strata web app.
- On the sign-in screen, click Continue with Microsoft.
- A pop-up window opens to Microsoft's sign-in page. Choose your work account and complete any multi-factor prompts your organization requires.
- The pop-up shows a brief Signed In confirmation and closes automatically.
- The Strata app swaps from the sign-in screen to the chat workspace. Your account name appears in the lower-left corner of the sidebar.
The first time you sign in, your account is created automatically — no extra setup is required. Strata never stores your Microsoft password or multi-factor secrets.
Staying signed in
Your session is a rolling 12-hour window and survives browser restarts. Each time you use Strata the window slides forward, so an active session keeps renewing. A session that sits idle for 12 hours expires, and every session has a 7-day hard cap from the original sign-in — after that you sign in again regardless of activity. If you reload the page, refresh a tab, or come back later inside the window, Strata signs you in silently using the session cookie set when you completed the Microsoft sign-in.
If your session expires while you have the app open, Strata detects the 401 response on its next API call, surfaces a Signed out — Your session expired. Please sign in again notification, and returns you to the sign-in screen. Click Continue with Microsoft again to start a fresh session.
Signing out
- In the sidebar, click your account row at the bottom (your name and avatar).
- In the menu that opens, click Log out.
- Confirm Sign Out in the dialog.
Signing out clears your session both in memory and on the server. Returning to Strata afterward shows the sign-in screen again.
An admin can also revoke any session from Admin → Active Sessions — when that happens your next API call gets a 401 and you are returned to the sign-in screen.
Signing in from the Outlook add-in
Strata for Outlook (the task pane that runs inside Outlook) has its own sign-in step, because the cross-site session cookie the web app relies on does not work inside Outlook's embedded WebView — especially Outlook desktop on Mac.
- In the Strata task pane, click Sign in to Strata.
- A small Office dialog opens to Microsoft's sign-in page. Choose your work account and complete any prompts.
- After Microsoft confirms, the dialog hands a secure token back to the task pane and closes — the pane is now signed in and reads the open email.
You sign in with the same Microsoft work account as the web app, and the same access rules apply. If the dialog is blocked or closes early, click Sign in to Strata in the pane again.
What can go wrong
- The button shows "Signing you in..." but nothing happens. Your browser blocked the pop-up. Allow pop-ups for the Strata site and click Continue with Microsoft again.
- The pop-up closes without signing you in. You either closed it manually or completed the Microsoft flow but the postMessage back to the app was dropped. Strata also re-checks your session when the main tab regains focus, so refreshing the sign-in screen usually completes the sign-in. If it does not, click Continue with Microsoft to try again.
- "Sign-in expired or invalid. Please try again." The OAuth state cookie aged out (10-minute window) before you finished Microsoft's sign-in flow, or it was tampered with. Click Continue with Microsoft to restart.
- "Too many sign-in attempts. Please wait a few minutes and try again." Sign-in is rate-limited at 30 attempts per 15 minutes per IP. Wait and try again.
- HTTP 503 "Authentication not configured" when initiating sign-in. The deployment is missing its Microsoft SSO configuration. This is an environment problem, not a user problem — contact your administrator or support@kronisys.com.
- The pop-up shows "Sign-in failed". Microsoft rejected the sign-in. The most common causes are: your account is not a member of the tenant Strata is configured against; your account exists but is not yet a Strata user (an admin still needs to invite you); your IT policies block the sign-in (conditional access, location, device compliance). The pop-up surfaces Microsoft's error message — paste it into a support request if it is not obvious.
- You sign in but land on the sign-in screen again. Your browser is blocking third-party cookies or stripping the session cookie. Check that cookies are enabled for the Strata domain, then try again.
For deeper triage of any of the above, see Troubleshooting.
Related
- Quickstart: your first conversation
- The Strata interface
- Onboarding your organization
- Strata for Outlook (add-in)
[Invitations]: /docs/admin/invitations