Administering the system
Single sign-on
Letting a school sign in with its own tenant, and why this site does not then ask for a code.
On this page
A school with its own identity provider can sign in with it instead of with a password here. It is set up per organisation at Single sign-on.
Setting one up
You need three things from the school's own IT: the issuer address, a client identifier and a secret. Add them against the organisation and a button appears on the sign-in page for that school.
The connection is checked when it is used rather than trusted because it was typed. A sign-in that was not started here is refused, which is the ordinary protection against somebody replaying a response.
What it changes for the school
People at that school sign in through their own tenant. They have no password here to forget, no password here to reset, and no account here that can be locked out by somebody guessing at it.
Their account, role, permissions and record here are exactly as before. Single sign-on changes how somebody proves who they are, not what they may do.
This site does not then ask for a code
Somebody arriving through their own tenant is not asked for a second factor here, even where their role would otherwise require it.
That is deliberate rather than an oversight. The school has already applied whatever its own policy requires — which is very often more than this — and asking again would be this system's idea of security overruling the school's own. The place to argue about a school's authentication policy is with the school.
Mixed schools
A school can have both: single sign-on for staff on the domain, and passwords for a governor or a peripatetic colleague who has no account there. Both routes lead to the same account if the email address matches.
When it breaks
Nearly always one of three things: the secret has been rotated at the school's end, the redirect address has not been registered there, or the addresses do not match because the tenant sends a different one from the one the account was created with.
None of those lock a school out permanently. Removing the configuration puts that school back to passwords, and everybody uses the reset link to set one. Say so when you are setting up: it is worth a school's IT knowing there is a way back.
Removing it
Delete the configuration. The button disappears from the sign-in page and nobody loses an account.
Not what you were after?
Ask City Council in the bubble at the corner of any page, or open your help conversation in full. It is one conversation that never closes, so there is nothing to raise and no subject line to invent.