Skip to main content

How student sign-in works

Knowing what happens during a sign-in makes the rest of the admin portal much easier to understand. Most settings in the portal change one of the steps below.

Diagram: the student signs in to Microsoft, Microsoft sends them to AuthCop, AuthCop checks the rules, the student proves who they are, and AuthCop sends them back to Microsoft.

The steps​

  1. The student signs in to Microsoft. They enter their school email address and password as usual.
  2. Microsoft asks AuthCop for a second check. Your school's Microsoft Entra settings send the student to the AuthCop sign-in page. This connection is set up on the Entra Configuration page.
  3. AuthCop finds the student. AuthCop matches the Microsoft account to the student's AuthCop user. Users come from Microsoft Entra through SCIM.
  4. AuthCop checks the country. If the student is signing in from a country on your Blocked Countries list, the sign-in stops here.
  5. AuthCop checks your access policies. Your access policies look at the student's groups, where they are, and the time. The policies decide whether the student is blocked or challenged, and which sign-in methods they can use.
  6. The student proves who they are. The sign-in page shows the methods they are allowed to use. For example, they scan their QR code card, enter a code from an authenticator app, enter a code sent to their personal email, or ask a teacher to approve them.
  7. AuthCop sends the student back to Microsoft. Microsoft finishes the sign-in and the student can use their apps.

Every sign-in, successful or not, is recorded in the Sign-in Logs.

Sign-in methods​

A sign-in method is a way for a student to prove who they are. You turn methods on for your school on the MFA Methods page, then choose which ones each policy allows.

MethodWhat the student doesNeeds setting up for each student?
QR CodeHolds their personal QR code card up to the camera.Yes. You generate QR codes for them.
TOTP (authenticator app)Types the 6-digit code from an authenticator app.Yes. You add it from the student's MFA Methods tab.
PasskeyUses a passkey saved on their device.Yes.
Email One-Time PasscodeTypes a code sent to their personal (alternate) email address.No, but the student needs an alternate email address.
TeacherShows a ticket number to a teacher, who approves the request in the admin portal.No. See Teacher MFA requests.
Caregiver (Preview)A parent or caregiver approves the sign-in.No.
Teams (Preview)Approves the sign-in through Microsoft Teams.No.

If a method needs setting up and a student hasn't got one, they won't see that method, even if a policy allows it.

Some changes take a moment to reach the sign-in page​

When you save a change to a user, a sign-in method, a policy, a location or the blocked countries list, AuthCop updates the sign-in page in the background. This usually only takes a short time. If a change doesn't seem to work straight away, wait a few minutes and ask the student to try again.