Collaborative Document Authoring with Microsoft365

Note Collaborative Document Authoring is a separately licensed component that is only available for Cloud installations.

By default, the Collaborative Document Authoring (CDA) feature uses a third-party document editing system hosted by OnlyOffice. For users of Process Director v6.1.500 and higher, using CDA may also be done in conjunction with the use of your Microsoft365 environment.

Microsoft365® (M365), formerly known as Microsoft Office365 and Microsoft Office Online, is an online version of the Microsoft Office suite of productivity tools. M365 offers secure online storage and access to documents, primarily for those that are editable in Microsoft Word®, PowerPoint®, and Excel®. Some organizations may choose to use M365 for CDA when editing document attachments that have been uploaded to their Process Director installation. This choice requires that all Process Director submitters and reviewers be uniquely authenticated prior to accessing any documents that may be stored in their organization’s Process Director/M365 system.

The authentication methods may vary slightly, depending on the type of account you use to access Process Director, but, in general, every user who accesses documents in Process Director must be authenticated in the M365 system via some sort of Multi-Factor Authentication (MFA).

Important The MFA functionality is completely controlled by Microsoft. It is NOT governed by either your organization or by Process Director.

Many organizations use Windows Single Sign-On to grant access to internal users. In that case, you might be used to being able to access your organization’s M365 application any time you’re logged into your organization’s network. Process Director, however, is an external application that doesn’t sit inside that network. Because the Process Director system accesses your organization’s M365 tenant as an external application, an additional login/authentication is required by Microsoft to validate your access via Process Director.

User Classes

As a user, you will fall into one of three different user classes for authenticating with M365. Irrespective of the user class you fall into, accessing M365 documents will require setting up a Multi-Factor Authentication (MFA) method for accessing documents in the system. The Primary MFA tool used by M365 is through the Microsoft Authenticator app for mobile devices. This app can be downloaded from the Apple App or Google Play store. You should download this app prior to beginning the MFA setup, as having the app on your device will make the account validation and authentication process go more quickly.

The three different user classes that may apply to you are listed below.

SAML/Single Sign-On

If you have an account on your organization’s network that uses a normal Windows account sign-on, or a federated identity system like Okta, your organization will provide a SAML login that enables you to access Process Director without needing to enter a user name or password. When logging into Process Director, the login screen will display a button labeled Login via SAML at the bottom of the screen. Clicking this button will automatically compare your Windows login with the SAML information from your organization, and log you into the system directly.

As a SAML user, you’ll still need to set up MFA to access documents in M365, though you’ll be required to authenticate on a much less frequent basis than other users.

External User (Generic)

If you are an external user that doesn’t have a network login for the organization, logging into Process Director will require that you enter the correct username and password to access Process Director. Accessing any M365 document will require that you authenticate via MFA every time you open a document. For example, if you have a Gmail address, M365 will enable you to access the document by either:

1. Sending an email to you that contains a One-Time Password (OTP) that you can copy and paste into the MFA access screen, or

2. Providing you with a 2-digit authentication code that you can enter into the Microsoft Authenticator Application.

3. Typing in the current OTP that is displayed in the Microsoft Authenticator app. This OTP refreshes every thirty seconds.

External User (Microsoft)

If you are an external user that uses an email service that is controlled by Microsoft, (e.g., and outlook.com email address, You’ll have to log into Process Director using a username and password just like other external users. If you’re logged into your Microsoft email account when accessing any M365 document, Microsoft will automatically use that account login to verify your identity. In that case, M365 won't require you to set up a new MFA instance for your account before you're able to access a document. If your Microsoft account already has MFA configured, M365 might still ask for an MFA authentication by either displaying a two-digit code that you must enter into Microsoft Authenticator, or by asking you to enter the current OTP displayed in the app.