How to set up Microsoft Entra SSO for your Peak body using the new SAML process

Entra admin portal enterprise apps

Summary

  • Create a new Enterprise Application in the Microsoft Entra portal, assign staff and student groups, and collect the Object ID for each group to share with ClickView Support.
  • Exchange two emails with ClickView Support: first to receive your Identifier and Reply URL, then to send your downloaded Base64 certificate, Login URL, and Microsoft Entra Identifier.
  • Configure SAML settings, including the Identifier, Reply URL, and Logout URL, then set the Name ID format to Persistent using user.objectid as the source attribute.
  • Map user attributes for role and grade identification using either Group Claims or a custom attribute, depending on how your Entra environment is structured.
  • Map a separate attribute for school assignment within the peak body, then download and complete the school list spreadsheet and send it to ClickView Support to finalise the configuration.
star icon
Quick tip
How do I set up Microsoft Entra SAML SSO for ClickView in my peak body?
To set up SAML SSO for ClickView, create a custom Enterprise Application in the Microsoft Entra portal, assign your staff and student groups, then work through a two-email exchange with ClickView Support to configure your Identifier, Reply URL, and SAML certificate. Once your SAML settings and user attribute mappings are complete, ClickView Support confirms the setup on their end. After confirmation, staff and students across your peak body can sign in to ClickView at clickview.net using their existing Microsoft credentials.

This guide walks IT administrators through connecting ClickView to their Microsoft Entra environment using SAML-based Single Sign-On. Once complete, staff and students across your peak body can access ClickView using their existing Microsoft credentials.

Before you start: This setup requires email exchanges with ClickView Support at defined points. Each phase builds on the last, so work through them in order.

  • Phase I: Create the ClickView app in Entra and assign user groups
  • Phase II: Configure SAML single sign-on
  • Phase III: Set user attributes and claims to complete the integration

Phase I: Creating the application

Step 1: Create a new Enterprise Application

  1. Within Enterprise applications, select + New application.
    Enterprise applications new application
  2. Select + Create your own application.
    Create your own application
  3. In What’s the name of your app?, enter ClickView. Select Integrate any other application you don’t find in the gallery (Non-gallery), then select Create.
    Select ClickView

Step 2: Assign users and groups

  1. Under the application’s menu, select Assign users and groups, then select + Add user/group.
    Add user/group
  2. Select the None Selected option.
    Select none selected
  3. Select all the staff and student groups to be assigned to the ClickView app, select Select, then select Assign.
    users and groups
    Add assignment, users and groups page

All assigned staff and student groups now have access to the ClickView application through SSO.

Users and groups page

Step 3: Collect Group Object IDs

ClickView Support needs the Object ID of each group you assigned.

  1. In the app, go to Users and groups and select one of the assigned groups.
    select one of the assigned groups
  2. Copy the Object ID value.
    Copy object ID
  3. Repeat for every assigned group and keep a list.

Contact ClickView Support:
Email #1:
Send an email to support@clickvieweducation.com requesting:

  • The Identifier (Entity ID) and Reply URL (Assertion Consumer Service URL) for your institute
  • Include the Object IDs for all assigned groups (from Step 3)

ClickView Support replies with your Identifier and Reply URL. Wait for this reply before continuing.

Phase II: Configuring SAML Single Sign-On

Step 4: Select SAML as the sign-on method

  1. Open your ClickView app in Entra and select the Set up single sign-on tile, then select SAML under Single Sign-On.
    Select SAML under Single Sign-On

Step 5: Add identifier URLs

  1. In the Basic SAML Configuration tile, select Edit.
    Edit basic SAML configuration

In the Basic SAML Configuration window, select Add identifier to edit Identifier (Entity ID), and Add reply URL to edit Reply URL (Assertion Consumer Service URL), using the values below.


Field

Value

Identifier (Entity ID)
Provided in the reply email from the ClickView Support team

Reply URL (ACS URL)
Provided in the reply email from the ClickView Support team

Logout URL

https://login.windows.net/common/oauth2/logout

Sign on URL

Leave blank (provided after onboarding)
SAML basic configuration page

Step 6: Download the certificate and copy URLs

  1. Scroll to SAML Certificates (Step 3 on the Entra page) and download the Certificate (Base64).
    SAML certificates and download

Then scroll to Set up ClickView (Step 4) and copy both:

  • Login URL
  • Microsoft Entra Identifier
Copy login URL and miscrosoft entra identifier

Contact ClickView Support:
Email #2:
Reply to the same email thread as Email #1 (or start a new email to support@clickvieweducation.com) and attach:

  • The Certificate (Base64) file
  • The Login URL
  • The Microsoft Entra Identifier

If any of your SAML attributes differ from what’s shown in this guide, mention the differences in this email. ClickView Support confirms once the setup is complete on their end. Continue to Phase III while you wait.

Phase III: Set User Attributes & Claims

Complete this phase while waiting for Support’s confirmation.

Step 7: Set up attributes

  1. Go to the Attributes & Claims tile and select Edit.
    Edit attributes and claim
  2. Confirm the default attributes are present:
    • givenname
    • surname
    • emailaddress
    • name
  3. Select the Unique User Identifier (Name ID) claim
     Select the Unique User Identifier (Name ID) claim
  4. In the ‘Name identifier format’, select the ‘Persistent’ option:
    Select persistent option
  5. In the Source attribute drop-down, select user.objectid.
    Select user.objectid

Step 8: Map attributes for user roles and grade levels
ClickView needs to know which users are staff and which are students, and for students, their year level. Choose the method that fits your Entra environment.

Option A: Use Group Claims (recommended)
If your groups already reflect staff/student roles and year levels, the group claim covers this. To add a group claim:

  1. Select + Add a group claim.
    Select + Add a group claim.
  2. Select Groups assigned to the application, select the Group ID option, then select Save.
    Select Groups assigned to the application, select the Group ID option, then select Save

Option B: Add a custom attribute
If you use a separate attribute in Entra for role or grade identification, add it as a custom claim:

  1. In the Attributes & Claims tile, select Edit, then select + Add new claim.
  2. Enter a Name for the claim, using a single word with no spaces (for example, department or yearLevel).
  3. Select the Source attribute whose values identify the user’s role or year level.
  4. Select Save.

Note: Attribute names and values vary depending on your environment. The example above is for illustration only, and your actual attribute names and source attributes may differ

Step 9: Map an attribute for school assignment

For peak body environments, ClickView also needs to identify which school within the peak body each user belongs to. This requires a separate attribute mapping, using the same process as Step 8.

Option A: Use Group Claims
If your groups already identify which school a user belongs to, and you added the group claim in Step 8, no additional configuration is needed.

Option B: Add a custom attribute
If a different attribute identifies a user’s school, add it as a custom claim:

  1. Go to the Attributes & Claims tile and select Edit.
    edit attributes and claims
  2. Select + Add new claim.
    Select + Add new claim.
  3. Enter a Name for the claim, using a single word with no spaces, and select the Source attribute whose values identify the user’s school
    manage claim

Note: This is an example for demonstration only. The actual attribute names and source attributes vary depending on your environment.

Step 10: Share attribute details with ClickView Support

Once you have confirmed your attribute mappings for both role/year and school assignment:

  1. Download the peak body /School List spreadsheet.

Once ClickView Support confirms the setup is complete on their end, your users can sign in to ClickView via SAML SSO through Microsoft Entra. Test the login at https://clickview.net/.

Quick reference


Phase

What you do
Then

Phase 1

Create app, assign groups, collect Object IDs

Send Email #1 to ClickView Support and wait

Phase 2

Configure SAML settings, download certificate

Send Email #2 to ClickView Support and wait

Phase 3

Map basic attributes, configure role + school identification

Email completed spreadsheet containing attribute details to Support team.
Test the login after confirmation via: https://clickview.net/

Frequently asked questions

You’ll need to send at least two emails. The first is to request your Identifier and Reply URL along with your group Object IDs, and the second is to share your Base64 certificate, Login URL, and Microsoft Entra Identifier.
In the Entra portal, open your ClickView app, go to Users and groups, select each assigned group, and copy the Object ID value shown in the group details panel.
Group Claims are recommended if your existing groups already reflect staff, student, and year level distinctions. If your environment uses a separate attribute for role or grade identification, add it as a custom claim in the Attributes & Claims tile instead.
Yes, for peak body environments, ClickView requires a separate attribute mapping to identify each user’s school. This can be covered by Group Claims if your groups already reflect school membership, or added as a custom attribute if a different field is used in your environment.
Contact ClickView Support at support@clickvieweducation.com with your attribute configuration details and any error messages, and they’ll help you troubleshoot.