There is a requirement mandated by the Australian Taxation Office (ATO) for logging on to the easyFBT software which will require each individual user to Sign up for a NEW software login when you start easyFBT (if you don't already have a software login from a previous year's easyFBT).
Note: The easyFBT software login is different/separate to your easyFBT website login (if you have created one for our website).
We use the Auth0 authentication system within easyFBT due to its ability to simplify and securely implement the type of security requested by the ATO.
IMPORTANT: Shared user logins must NOT be used. - this is a requirement of the ATO. Each person logging into easyFBT must have a unique user login and only use that to access easyFBT.
Why do you have to login?
The ATO have mandated that any software that connects to the Standard Business Reporting (SBR) system must provide a comprehensive login system to protect users.
The ATO's Digital Service Provider (DSP) Operational Security Framework (OSF) seeks to protect Taxation, Accounting, Payroll, Business Registry and Superannuation related data and the integrity of the Taxation, Business Registry and Superannuation systems that support the Australian community. This is achieved by setting out a minimum level of security requirements a DSP needs to meet in order to access ATO Digital Services that perform a functional role in the supply chain. The ATO's DSP OSF has been established to respond to business risks and security threats presented by the continual expansion and growth of digital services across the ecosystem.
The ATO's DSP OSF is a response to known examples of:
Information misuse: including identity theft, personal gain or commercial advantage.
Financial system misuse: including tax refund fraud.
Destructive cyber behaviour: including individual or system hacks.
The ATO's DSP OSF applies to any software product or digital service that performs a functional role in the supply chain of transmitting Taxation, Accounting, Payroll, Business Registry or Superannuation data through ATO digital services.
This includes software products that reads, stores, modifies or routes any Taxation, Accounting, Payroll, Business Registry or Superannuation data that:
Connects directly to the ATO digital services.
Connects indirectly to the ATO via a sending Service Provider (SSP) for Payroll services.
Connects indirectly to the ATO via a Gateway for Superannuation Services or SuperStream
On Startup
Each time you start easyFBT you will be presented with the following Log in screen which will allow you to login to the application by either entering your software account credentials or by choosing the optional Continue with Microsoft Account option:
Available account options
First time users will need to either create a standard account credential (via the Sign up option) or by linking your existing Microsoft 365 account to our easyFBT application. There are currently 2 options available to log into easyFBT:
Standard account - create a personalised easyFBT account by entering your email address and creating a password. You will receive an e-mail notification to verify your account and allow access.
Microsoft account - link your existing Microsoft 365 account to easyFBT
Which is the recommended account option?
For ongoing simplification, we recommend (where available) using a Microsoft 365 account as this can be tied to an already existing account. Whilst a standard account is more than suitable for this purpose it will require you to remember an additional account password.
Ongoing easyFBT use
Once you have chosen your account option it will be available and useable for all releases of easyFBT.
Initial Account sign up
Where you haven't already signed up for a software login then to complete the account sign-up process, click on the Sign up link located in the middle of the Log in screen to show the Sign up screen:
Standard account login
If you intend to create a new standard account complete the following:
On the Sign Up screen, enter your email address and create a password (follow the on-screen password requirements). Click the Continue button to create your account.
Once you have created your account, you will be sent a Verify your Account e-mail. Check your inbox or junk mail folder.
From the e-mail, click the VERIFY YOUR ACCOUNT button to finalise your account.
Note: if you get an error message when you click the Verify your Account link, you can safely ignore that message as your e-mail service may have previously self-verified the link as part of its spam validations.
Also, on the "Email Verified" pop-up don't click the Back to all Applications button as this goes nowhere and just shows an irrelevant error message that you can ignore.
Once your account has been verified, in future, on the Log In screen, enter your email address and password and click the Continue button.
Non-activated account
If you don't complete the Verify your Account step, you will not be able to login to easyFBT in future attempts. In this situation each time you attempt to log in to easyFBT we will send you a follow-up Verify your Account e-mail and you will be advised of this via an on-screen prompt. Please access and check your spam/junk folders if you don't see this email in your inbox.
Note: If you have any issues finalising your account, please contact support.
Microsoft account login
When choosing the Continue with Microsoft Account login option, follow the on-screen prompts to login into easyFBT with your first initial attempt linking your account to the software. Your IT area will probably need to authorise you to be able to login into the easyFBT application using your Microsoft account.
Note: at no time does One Plus One Solutions Pty Limited have access to your Microsoft account or password.
Authentication features and conditions
Our easyFBT authentication has a number of additional features and conditions required to be met to access the program.
Closing or cancelling the login prompt
If you fail to successfully provide your account credentials or cancel the login prompt, easyFBT will either not be started or, if already open, will be closed (any unsaved tabs will be automatically saved before easyFBT is closed).
Offline access
The current configuration of the easyFBT/Auth0 authentication process requires online access at the time of logging in. When starting easyFBT, we will validate your online status before showing the log in screen and will advise where an internet connection is not available. Until a valid internet connection is available, easyFBT will not be started.
Re-prompting for your account credentials
After a period of non-activity within easyFBT, you will be re-prompted for your account credentials. Provide your account details again to return to easyFBT.
Failure to provide your account credentials will result in easyFBT being closed (edited data will be automatically saved).
Issues using the Auth0 login process
Depending on the internal IT configuration of your network, occasionally (more so when using Remote Desktop Services [Terminal Services] or Citrix) the Auth0 login window may fail to load, respond with an offline prompt or not complete the login process correctly. In this situation you may need to add a number of URLs to the trusted sites available to your computer and potentially also to your corporate firewall exceptions.
Adding the required URLs to your trusted sites
To add the required site URLs, open the Internet Options dialog on your computer (available via the search box on your Start menu):
On the Security tab select the Trusted sites option and click the Sites button to display the Trusted sites dialog. Enter the required website URLs as outlined below and then click the Close button.
Depending on the account type you are using to login, enter the following URLs:
https://easyfbt.au.auth0.com
Microsoft (when using Microsoft 365 and/or Outlook accounts)
https://login.microsoftonline.com
Adding the required sites to your corporate firewall exceptions
Depending on the status of your corporate firewall, we have a number of clients that have also been required to add the following URLs to their firewall exception rules:
https://easyfbt.au.auth0.com
Microsoft (when using Microsoft 365 and/or Outlook accounts)
https://login.microsoftonline.com
IMPORTANT: Your IT Department will be required to complete this task. Firewall exceptions and how to accept them will be different depending on the hardware and software involved.
Application logging
Additional logging has been added to easyFBT in line with the ATO's DSP OSF requirements. These logs are generated on an application and entity level basis tracking features activated by the logged-in user.
Application level - includes everything done by the user from log-on to close across all activated entities (ApplicationLog.txt file located in the Documents\One Plus One Solutions Pty Limited\easyFBT 20XX\Logs folder)
Entity level - includes everything done by the user specific to the activated entity (EntityLog.txt file located in the specific entity folder)
IMPORTANT: The ATO recommends that these log files are retained for at least 12 months. NOTE: easyFBT does not remove these log files.
Type of information recorded
Including the account name and date/time, anything specific from logging-in, opening features, editing, importing or saving workpapers, viewing reports and completing SBR lodgements.