Admin admission

Sign in to the operator console

The admin surface now starts with a dedicated login boundary instead of dropping operators straight into raw EasyAuth redirects or late 403 handling.

Use the Entra path when this environment is honoring the approved object-ID allowlist. Use the local path only with a provisioned operator account that already has a secure password hash and TOTP seed configured.

  • Requested route

    Meta control room

  • Entra policy

    Approved object IDs only

  • Local fallback

    Scrypt-hash plus TOTP

Continue with Entra

Use the shared Entra operator path when this deployment should honor the approved object-ID allowlist.

Sign in with Entra

Target route after sign-in: /meta

Use a local operator account

This fallback path is for provisioned operator credentials that are managed separately from Entra and require both a password and a 6-digit authenticator code.

App-local operator sign-in

Use a provisioned app-local operator account when this environment needs a managed fallback outside the shared Entra path.

Configured usernames: arewelive

Redirect target: /meta