Skip to main content

Entra configuration

This page holds the details that connect AuthCop to your school's Microsoft Entra. There are two connections: one for student sign-in (AuthCop Verify) and one for staff sign-in to the admin portal.

Who can use this page: Global Administrator.

Changes here can stop everyone signing in

A wrong value on this page can stop all students signing in, or stop all staff signing in to the admin portal. Only change these settings when you are setting up AuthCop or have been asked to by AuthCop support.

The Entra Configuration page, with the AuthCop Verify Client Id, the Admin Portal Client Id, and the client certificate details.

AuthCop Verify​

SettingWhat it is
Client IdThe Application (client) ID of the app registration in Microsoft Entra that your AuthCop external authentication method uses. You'll find it in the Microsoft Entra admin center, on the app registration's Overview page.

How this affects sign-in: AuthCop uses this ID to check that sign-in requests really come from your Microsoft Entra. If it doesn't match the external authentication method in Entra, students can't sign in.

AuthCop Admin Portal​

SettingWhat it is
Client IdThe Application (client) ID of the AuthCop admin app registration in Microsoft Entra. Staff sign in to the admin portal through this app.

Client certificate​

AuthCop uses a certificate to prove itself to Microsoft Entra when staff sign in to the admin portal. It is also used when AuthCop changes Microsoft Entra groups for travel plans.

The page shows the certificate's Thumbprint and Expiry Date.

Download the certificate

  1. Select Download Certificate.
  2. In the Microsoft Entra admin center, open the AuthCop admin app registration.
  3. Go to Certificates & secrets → Certificates and upload the file.
The Certificates & secrets page of an app registration in Microsoft Entra, with the Upload certificate button.

Regenerate the certificate

Do this before the certificate expires, or if you think it has been compromised.

  1. Select Regenerate Certificate and confirm.
  2. Straight away, select Download Certificate and upload the new certificate to the admin app registration in Microsoft Entra.
warning

After regenerating, nobody can sign in to the admin portal until the new certificate is uploaded to Microsoft Entra. Stay signed in until you have finished.

Save your changes​

Select Save after changing a Client Id. A message confirms the settings were saved.