Velaro Site: Logging In
Velaro Site is protected by Azure App Service's built-in authentication (Easy Auth) in front of Microsoft Entra ID (Azure AD). You never enter a separate password for Velaro Site itself — you sign in with your normal Velaro Microsoft 365 account, the same one you use for email.
- Open the admin app's URL. If you're not already signed in, Entra will prompt you to authenticate — this is the standard Microsoft sign-in screen, not a Velaro-branded one.
- After you sign in, the platform passes your identity to the app automatically. There's nothing to configure or a token to copy — it's the same experience as opening any other Microsoft-365-protected internal tool.
- Open Velaro Site from the admin app's navigation.
Why the page can load but every action still fails
Signing in with Entra only proves who you are — it doesn't automatically grant you editing rights inside Velaro Site. A second, separate check (an admin allowlist) decides whether your specific account is allowed to save changes. If your account isn't on that list, the page itself will load normally, but every save, publish, or promote action will come back with an "Admin only" error.
If that happens to you, it isn't a bug — ask whoever administers the tool to add your email to the admin allowlist.
Troubleshooting
| What you see | What it means |
|---|---|
| Redirected to a Microsoft sign-in page you didn't expect | Normal — your session expired and Easy Auth is re-authenticating you. Sign in again and you'll land back where you were. |
| The page loads, but every button says "Admin only" | You're signed in, but your account isn't on the editor allowlist. Ask an admin to add you. |
| "Access denied" on a specific item (like a job or asset) you didn't create | Some items are scoped to their creator; only that person or an admin can view or delete them. |
Was this article helpful?