🔐
Single sign-on (Enterprise)
3 min read
With single sign-on your staff sign in to schedU with the account your school already gives them. What each person can do still comes from your Users page, so access is managed in one place.
Setting it up
- 1An administrator opens Settings and, under Single sign-on, gives your email domain (for example edenschool.edu), chooses OpenID Connect (recommended) or SAML, and adds your identity provider’s details or your IT contact.
- 2We connect your identity provider to that domain and confirm by email.
- 3From then on, staff choose Sign in with SSO on the login page, enter their work email, and are sent to your provider to sign in.
What we need
- •OpenID Connect, the newer standard and our recommendation (Microsoft Entra ID, Okta, Google and most modern providers): the issuer URL, a client ID and a client secret, which we will ask for securely.
- •SAML 2.0, for systems that offer only SAML to outside apps (ADFS, Shibboleth, and many Google Workspace and Entra set-ups already in place): your metadata URL, or the metadata file.
- •The email domain or domains your staff sign in with.
💡 Signing in proves who someone is; it does not give them access on its own. Add each person on your Users page, as administrator, teacher or viewer, as you do today.