How to set up Microsoft Entra SSO for your school

SSO School setup hero

Summary

  • Sign in to the Microsoft Entra admin center.
  • Create a non-gallery Enterprise application named “ClickView”.
  • Go to Single Sign-On and select SAML.
  • Enter your region Identifier and Reply URL in Basic SAML Configuration.
  • Assign your school users or security groups to the ClickView application.
  • Review Attributes & Claims, then add required claims and a group claim.
  • Submit your App Federation Metadata URL and your school’s security groups for onboarding.
star icon
Quick tip
When should a school set up Entra SSO on its own instead of using a District configuration?
Use the school setup when your school manages its own Microsoft Entra environment and security groups. If your district manages Entra centrally for multiple schools, follow the District SSO setup so group and mapping decisions are handled consistently across the district.

Set up ClickView with Microsoft Entra for schools

Follow these steps to integrate ClickView with Microsoft Entra for Single Sign-On (SSO) at the school level. This setup is intended for school administrators and school IT teams configuring access for one school and its users.

  1. Sign in to the Entra portal and select Enterprise apps.
  2. Within Enterprise applications, select +New application.
    Microsoft new application
  3. Select +Create your own application.
    Microsoft create your own application
  4. In What’s the name of your app?, enter ClickView. Select Integrate any other application you don’t find in the gallery (Non-gallery), then select Create.
    Integrate application

Configure SAML single sign-on for ClickView

  1. Under the application’s menu, choose Single sign-on.
    Single sign on
  2. Select the SAML tile.
    SMAL option
  3. In the Basic SAML Configuration tile, select Edit.
    Basic SAML configuration

Set up basic SAML configuration

In the Basic SAML Configuration window, enter the following region-specific values:

  1. Identifier: https://saml-in1.clickview.us/shibboleth
  2. Reply URL: https://saml-in1.clickview.us/Shibboleth.sso/SAML2/POST
    Add identifier
    input values
  3. Logout URL (default for all regions): https://login.windows.net/common/oauth2/logout
    Logout URL
  4. Click Save.

Additional settings:

  • Leave Sign on URL blank. This is optional and will be provided after onboarding.

You will then see the updated Basic SAML Configuration:

Basic SAML configuration final

Assign school users and groups to the ClickView application

This step controls who at your school can sign in to ClickView using Microsoft Entra.

  1. In Microsoft Entra, open Enterprise applications, then select your ClickView application.
  2. Go to Users and groups.
    Assign users and groups
  3. Select +Add user/group.
    Add user/group option
  4. Select None selected.
    None selected option
  5. Search for and select the users or security groups you want to assign.
    Search grade groups
  6. Assign them to the ClickView application.
    User and groups selected
  7. The assigned groups then appear in the ClickView application.
    Users and groups that are selected

Set user attributes and claims

  1. Go to the Attributes & Claims tile and select Edit.
    User Attributes and claims edit
  2. Confirm the default attributes are present:
    • givenname
    • surname
    • emailaddress
    • name
  3. To add a group claim, select + Add a group claim.
    Add a group claim option
  4. Select Groups assigned to the application, then select the appropriate Source attribute (for example, Group ID), then select Save.
    Groups assigned to the application option

Complete SSO onboarding with ClickView

To complete onboarding, provide ClickView Product Support with:

  1. Your App Federation Metadata URL
  2. A list of your school’s staff and student security groups used for access and (if applicable) grade-level mapping
  3. Test staff and student account details for validation

App Federation Metadata URL

To obtain your App Federation Metadata URL:

  1. Open your ClickView enterprise application.
  2. Go to Single sign-on and select SAML.
  3. In the SAML Certificates (or SAML Signing Certificate) tile, locate App Federation Metadata Url.
    App federation metadata url
  4. Select the copy icon to copy the URL.
    Copy App federation URL

Staff and student security groups

Provide the security group names your school uses to represent staff and students (and any grade-level groupings if you use them).

In the Microsoft Entra admin center:

  1. Go to Groups.
  2. Select All groups, then search for the groups you plan to use.

Important points to note

  • If your school uses local Active Directory groups, you may need to synchronize them with Microsoft Entra using Entra Connect Sync.
  • For group claims setup, configuration steps are available on the Microsoft website.
  • Microsoft Entra supports up to 150 user groups in a SAML token. If a user exceeds this limit, ClickView cannot retrieve groups via API. Reduce group assignments for affected users or limit which groups are sent in the claim.
  • Keep your school assignment list aligned with your ClickView rollout plan. Only assigned users and groups can sign in.

Start your onboarding process

Once you have completed the steps above, start onboarding by submitting your school details via the onboarding form.

Frequently asked questions

Yes. Only users or groups assigned to the ClickView enterprise application can sign in and be validated during testing.
Use the region-specific values listed in the Basic SAML Configuration section of this article.
Open the ClickView enterprise application, go to Single sign-on > SAML, then copy the App Federation Metadata Url from the SAML Certificates (or SAML Signing Certificate) tile.
You still need a clear way to identify staff and students, typically through assigned users or security groups. If you do not use grade-level groups, provide the groups you do use for access control.
Yes. Microsoft Entra supports up to 150 user groups in a SAML token. If users exceed the limit, reduce group assignments or limit which groups are sent in the claim.

Get in touch

If you’re having trouble finding the right topics or videos, just reach out! Our team - Andrew photoNischal photoJanice photoPfreya photo Andrew, Nisch, Janice, Pfreya, or any of us at ClickView - will be happy to help you get sorted.

Give feedback

Was this guide helpful?

Up Next

How to set up Okta SAML SSO with ClickView

This article explains how to configure a SAML 2.0 application in Okta for use with ClickView and submit the required metadata so the SSO instance can be set up.