Wise Timetable

How-to

Setting up Microsoft sign-in

Single sign-on with Microsoft Entra ID takes about ten minutes for a whole school: one approval by your Microsoft 365 administrator, two settings in the school’s own web settings, and lecturer records whose addresses match. Nothing is registered at your end, and nothing is read from mailboxes, calendars or files.

What Wise Timetable asks Microsoft for

For the security review. The sign-in itself happens at Microsoft, so multi-factor authentication and your Conditional Access policies apply exactly as they do for Outlook.

AspectWhat it is
ProtocolOpenID Connect, authorization code flow with PKCE. The code is exchanged on our server, never in the browser.
ApplicationWise Timetable, one multi-tenant application registered and operated by Wise Technologies in Microsoft Entra ID (formerly Azure AD). You register nothing yourself.
Permissionsopenid, profile and email, all delegated — sign-in and basic profile only. No token to call Microsoft Graph is asked for, and no mail, calendars, files, Teams or directory data are read.
PasswordsTyped on Microsoft’s page only. Wise Timetable receives a signed statement of who the person is, never a password.
What is keptThe signed statement is checked and discarded. The lecturer is found, and the same Wise Timetable session a password sign-in gets begins, for up to eight hours.

Who is let in, and as whom

  • Only accounts from your own tenant. The school names its tenant in its settings, and a signed statement from any other directory is refused.
  • Personal Microsoft accounts are refused — outlook.com, hotmail.com, live.com — and so are guest accounts invited into your tenant from another organisation. Only accounts your institution itself issued can sign in.
  • A person is matched by their sign-in name, the user principal name such as j.novak@your-university.edu, against the E-mail on their lecturer record. Capital letters and surrounding spaces are ignored. The separate, unverified email attribute in Entra ID is deliberately not trusted for this.
  • The rights come from the lecturer record, not from Microsoft. A Microsoft sign-in gets exactly what the same person would get with a password — the Administrator tick decides access to the administration — and nothing about the Microsoft account can add to it.
  • Two records with the same address: the one with the Administrator tick is chosen, then the older record, and the duplicate is noted in the server’s log so it can be tidied up.

Switching it on

Two people, about ten minutes: your Microsoft 365 administrator once, then the timetable office.

  1. Approve Wise Timetable, once

    An administrator of your tenant who may grant tenant-wide consent — Global Administrator, Privileged Role Administrator, Cloud Application Administrator or Application Administrator — opens the consent address below with your own domain in it and presses Accept. That grants the permissions for the whole institution, so no member of staff is ever asked to consent.

  2. Name your tenant

    On the school’s web timetable, signed in as a configuration administrator, open Settings › Access. In Microsoft tenant enter your domain in Microsoft 365 — the part after the @ in staff sign-in names — or your tenant ID. It is checked with Microsoft when you save, so a typing mistake is caught there.

  3. Check the addresses

    Every member of staff who books rooms or works in the administration needs the E-mail on their lecturer record to be the address they sign in to Microsoft with. Where people have a mail alias that differs from their sign-in name, enter the sign-in name.

  4. Try it with one person

    Set Sign in with Microsoft to Microsoft, and passwords as before, and let one person from the timetable office sign in before anybody else is told. Passwords keep working throughout.

Opened once by your Microsoft 365 administrator, with your own domain in place of your-university.edu. Microsoft shows the application Wise Timetable and the permissions above, and after Accept returns the administrator to a Wise Timetable page — that is expected, and there is nothing to do there. Until it is done, staff who press the button are told the school has not yet approved Wise Timetable.

Address
https://login.microsoftonline.com/your-university.edu/adminconsent?client_id=da9abd7c-069c-4e2a-90bc-c5c3880b5ae0

Controlling it from Entra ID

After the approval, Wise Timetable appears in the Microsoft Entra admin centre under Enterprise applications. Two of its Properties are worth knowing, and deleting the application withdraws the approval entirely.

PropertyEffect
Assignment required? set to YesOnly the users and groups you assign under Users and groups can sign in to Wise Timetable with Microsoft — a good way to start with the timetable office alone.
Enabled for users to sign-in? set to NoSwitches Microsoft sign-in to Wise Timetable off for the whole tenant at once.

The three choices

Sign in with Microsoft, on the same settings screen as the tenant. Half a configuration switches nothing on: while Microsoft tenant is empty the school behaves as Off, whatever this setting says, so nobody can be locked out by settings saved in the wrong order.

ChoiceWhat staff get
Off – username and password onlyNo Microsoft button. This is where every school starts.
Microsoft, and passwords as beforeThe Microsoft button first, and the username and password form under it. Both work.
Microsoft onlyThe Microsoft button. Lecturer passwords are refused, before they are even checked.

Microsoft only, when you are ready

  • It can be saved only by somebody signed in with Microsoft at that moment. The settings screen refuses it from a password session, which proves the new way in works before the old one closes. The same applies to changing the tenant of a school that is already Microsoft only.
  • The accounts Wise Technologies set up for your school by hand keep their passwords. They are the way back in if the Microsoft side is ever misconfigured; on the sign-in page the form is folded away under Sign in with a username and password instead.
  • Going back is never locked. Microsoft, and passwords as before can be chosen from any session, and the old passwords work again.
  • The mobile apps are not part of it. The setting Mobile app: a lecturer’s timetable needs that lecturer’s password uses the Wise Timetable password, so at a school that signs in with Microsoft only, leave it off.

What is checked on every sign-in

What the server verifies before anybody is let in. A sign-in that fails any of it gets one neutral sentence on the page, and the precise reason goes to the server’s log.

  • The signature, against Microsoft’s published signing keys, RS256 only.
  • That the statement was issued to Wise Timetable, by your tenant, and is current — audience, tenant and issuer, and the issued, not-before and expiry times, with two minutes’ tolerance for clock drift.
  • A one-time value tied to this browser’s sign-in, and a state that can be used once and expires after ten minutes, so a sign-in cannot be replayed, or started in one browser and finished in another.
  • That the account is neither a guest nor a personal Microsoft account.
  • Only then, the lecturer record with that sign-in name at this school.

Troubleshooting

What staff see, why, and what puts it right.

Staff seeCauseFix
No Microsoft button at allThe school is at Off, or Microsoft tenant is empty.Name the tenant and choose a mode.
… has not yet approved Wise Timetable.The consent has not been given, or was withdrawn.The consent address above.
… no lecturer at this school has that e-mail address.The lecturer record has no address, or a different one, such as a mail alias.Put the sign-in name shown in the message on the record.
That Microsoft account does not belong to this school.An account from another tenant, or Microsoft tenant names the wrong one.Check the setting; otherwise the person picks the right account.
That is a guest account … or That is a personal Microsoft account.A B2B guest, or an outlook.com, hotmail.com or live.com account.Only accounts your tenant issued can sign in.
Signing in with Microsoft did not work.Anything else.Note the time and write to us; the server log names the reason.

Want to see this working?

Book a 45-minute online presentation and we will walk through it against your institution's own scheduling problem.