Skip to main content

First-time setup

Follow these steps in order when setting up AuthCop for the first time. Each step links to the page that explains it in full. You need the Global Administrator permission for most of them.

Test before you turn it on for everyone

Until your access policies are ready, students can be blocked from signing in. Try your setup with a small test group of students before turning on the external authentication method for all students in Microsoft Entra.

1. Connect AuthCop to Microsoft Entra​

On Settings → Entra Configuration, check the Client Id for AuthCop Verify and for the AuthCop Admin Portal, and upload the admin portal certificate to Microsoft Entra.

2. Add your email domains​

On Settings → Domain Names, add every email domain your staff use, then verify each one with a DNS record. This is how staff find your school when they sign in.

3. Sync your users and staff​

On Settings → SCIM Configuration, copy the URLs and tokens into Microsoft Entra provisioning:

  • the Users URL and token sync students and their groups
  • the Administrators URL and token sync staff who will use the admin portal

Wait for the first sync to finish, then check the Users and Groups pages.

4. Mark your student groups​

Open each group that contains students and turn on Student Group. See Groups. This unlocks student-only features such as teacher requests, classes and caregivers.

5. Give staff their permissions​

On Settings → Admin Users or Admin Groups, give each staff member the permissions they need. See Admin permissions.

6. Import extra school data (optional)​

On Settings → Import Settings, connect your student management system, or upload CSV files. This adds houses, year levels, home groups, campuses, classes and caregivers.

7. Turn on sign-in methods​

On MFA → Methods, turn on the methods students may use, for example QR Code and Teacher.

8. Add your locations​

On Locations, add your school's network (IP) ranges and any countries you want to use in policies.

9. Create your access policies​

On MFA → Access Policies, create the rules that decide who is challenged, who is blocked, and which methods they can use. Add any countries you never want sign-ins from to MFA → Blocked Countries.

10. Give students their QR codes​

On MFA → Generate QR Codes, create QR codes for your student groups and print the cards.

11. Brand the sign-in page​

On Settings → Login Customisation, add your school logo, a background image and your school colour.

12. Test, then go live​

Sign in as a test student and check the Sign-in Logs. When you are happy, turn on the AuthCop external authentication method for all students in Microsoft Entra.