| Access policy | A rule that decides whether a sign-in is blocked or challenged, and which sign-in methods are allowed. See Access policies. |
| Admin portal | The website school staff use to manage AuthCop. |
| Alternate email address | A student's personal email address, outside the school. Used for the Email One-Time Passcode method. |
| Audit log | A record of every change made in the admin portal. See Audit Logs. |
| Block | A policy action that stops the sign-in. |
| Caregiver | A parent or guardian linked to a student. (Preview) |
| Challenge | A policy action that lets the student continue, as long as they prove who they are with an allowed sign-in method. |
| CIDR | A short way of writing a range of IP addresses, such as 203.0.113.0/24. |
| External authentication method (EAM) | The Microsoft Entra feature that lets Microsoft hand part of the sign-in to another service, in this case AuthCop. |
| External ID | The ID a person or class has in your student management system. Used to match imported data. |
| Group | A set of users. Groups can come from Microsoft Entra (synced) or be made in AuthCop. |
| IP address | The internet address a sign-in comes from. Your school network has its own IP addresses. |
| Location | A named set of IP ranges and countries, used in access policies. See Locations. |
| MFA (multi-factor authentication) | Proving who you are with something extra, not just a password. |
| Microsoft Entra | Microsoft's sign-in service (previously called Azure Active Directory). Your school accounts live here. |
| Number matching | An extra check for teacher and caregiver approvals. The approver must match the number shown on the student's screen. |
| Passkey | A sign-in method that uses a key saved on the student's device instead of a code. |
| QR code | A square barcode. Each student's QR code card is unique to them and proves who they are. |
| SCIM | The standard Microsoft Entra uses to copy users and groups into AuthCop automatically. See SCIM Configuration. |
| Sign-in method | A way to prove who you are, such as a QR code or a teacher approval. See MFA Methods. |
| Student | A user who is a member of at least one Student Group. See Groups. |
| Synced | Copied from Microsoft Entra. Synced users and groups show a synced icon, and most of their details can only be changed in Microsoft Entra. |
| Tenant | Your school's own space in AuthCop (or in Microsoft Entra). |
| TOTP | Time-based one-time passcode. A 6-digit code from an authenticator app that changes every 30 seconds. |
| Weight | A number that sets the order AuthCop checks access policies in. Higher weights are checked first. |