How-to
Setting up Microsoft sign-in
Single sign-on with Microsoft Entra ID takes about ten minutes for a whole school: one approval by your Microsoft 365 administrator, two settings in the school’s own web settings, and lecturer records whose addresses match. Nothing is registered at your end, and nothing is read from mailboxes, calendars or files.
What Wise Timetable asks Microsoft for
For the security review. The sign-in itself happens at Microsoft, so multi-factor authentication and your Conditional Access policies apply exactly as they do for Outlook.
| Aspect | What it is |
|---|---|
| Protocol | OpenID Connect, authorization code flow with PKCE. The code is exchanged on our server, never in the browser. |
| Application | Wise Timetable, one multi-tenant application registered and operated by Wise Technologies in Microsoft Entra ID (formerly Azure AD). You register nothing yourself. |
| Permissions | openid, profile and email, all delegated — sign-in and basic profile only. No token to call Microsoft Graph is asked for, and no mail, calendars, files, Teams or directory data are read. |
| Passwords | Typed on Microsoft’s page only. Wise Timetable receives a signed statement of who the person is, never a password. |
| What is kept | The signed statement is checked and discarded. The lecturer is found, and the same Wise Timetable session a password sign-in gets begins, for up to eight hours. |
Who is let in, and as whom
- Only accounts from your own tenant. The school names its tenant in its settings, and a signed statement from any other directory is refused.
- Personal Microsoft accounts are refused — outlook.com, hotmail.com, live.com — and so are guest accounts invited into your tenant from another organisation. Only accounts your institution itself issued can sign in.
- A person is matched by their sign-in name, the user principal name such as j.novak@your-university.edu, against the E-mail on their lecturer record. Capital letters and surrounding spaces are ignored. The separate, unverified email attribute in Entra ID is deliberately not trusted for this.
- The rights come from the lecturer record, not from Microsoft. A Microsoft sign-in gets exactly what the same person would get with a password — the Administrator tick decides access to the administration — and nothing about the Microsoft account can add to it.
- Two records with the same address: the one with the Administrator tick is chosen, then the older record, and the duplicate is noted in the server’s log so it can be tidied up.
Switching it on
Two people, about ten minutes: your Microsoft 365 administrator once, then the timetable office.
Approve Wise Timetable, once
An administrator of your tenant who may grant tenant-wide consent — Global Administrator, Privileged Role Administrator, Cloud Application Administrator or Application Administrator — opens the consent address below with your own domain in it and presses Accept. That grants the permissions for the whole institution, so no member of staff is ever asked to consent.
Name your tenant
On the school’s web timetable, signed in as a configuration administrator, open Settings › Access. In Microsoft tenant enter your domain in Microsoft 365 — the part after the @ in staff sign-in names — or your tenant ID. It is checked with Microsoft when you save, so a typing mistake is caught there.
Check the addresses
Every member of staff who books rooms or works in the administration needs the E-mail on their lecturer record to be the address they sign in to Microsoft with. Where people have a mail alias that differs from their sign-in name, enter the sign-in name.
Try it with one person
Set Sign in with Microsoft to Microsoft, and passwords as before, and let one person from the timetable office sign in before anybody else is told. Passwords keep working throughout.
The consent address
Opened once by your Microsoft 365 administrator, with your own domain in place of your-university.edu. Microsoft shows the application Wise Timetable and the permissions above, and after Accept returns the administrator to a Wise Timetable page — that is expected, and there is nothing to do there. Until it is done, staff who press the button are told the school has not yet approved Wise Timetable.
| Address |
|---|
https://login.microsoftonline.com/your-university.edu/adminconsent?client_id=da9abd7c-069c-4e2a-90bc-c5c3880b5ae0 |
Controlling it from Entra ID
After the approval, Wise Timetable appears in the Microsoft Entra admin centre under Enterprise applications. Two of its Properties are worth knowing, and deleting the application withdraws the approval entirely.
| Property | Effect |
|---|---|
| Assignment required? set to Yes | Only the users and groups you assign under Users and groups can sign in to Wise Timetable with Microsoft — a good way to start with the timetable office alone. |
| Enabled for users to sign-in? set to No | Switches Microsoft sign-in to Wise Timetable off for the whole tenant at once. |
The three choices
Sign in with Microsoft, on the same settings screen as the tenant. Half a configuration switches nothing on: while Microsoft tenant is empty the school behaves as Off, whatever this setting says, so nobody can be locked out by settings saved in the wrong order.
| Choice | What staff get |
|---|---|
| Off – username and password only | No Microsoft button. This is where every school starts. |
| Microsoft, and passwords as before | The Microsoft button first, and the username and password form under it. Both work. |
| Microsoft only | The Microsoft button. Lecturer passwords are refused, before they are even checked. |
Microsoft only, when you are ready
- It can be saved only by somebody signed in with Microsoft at that moment. The settings screen refuses it from a password session, which proves the new way in works before the old one closes. The same applies to changing the tenant of a school that is already Microsoft only.
- The accounts Wise Technologies set up for your school by hand keep their passwords. They are the way back in if the Microsoft side is ever misconfigured; on the sign-in page the form is folded away under Sign in with a username and password instead.
- Going back is never locked. Microsoft, and passwords as before can be chosen from any session, and the old passwords work again.
- The mobile apps are not part of it. The setting Mobile app: a lecturer’s timetable needs that lecturer’s password uses the Wise Timetable password, so at a school that signs in with Microsoft only, leave it off.
What is checked on every sign-in
What the server verifies before anybody is let in. A sign-in that fails any of it gets one neutral sentence on the page, and the precise reason goes to the server’s log.
- The signature, against Microsoft’s published signing keys, RS256 only.
- That the statement was issued to Wise Timetable, by your tenant, and is current — audience, tenant and issuer, and the issued, not-before and expiry times, with two minutes’ tolerance for clock drift.
- A one-time value tied to this browser’s sign-in, and a state that can be used once and expires after ten minutes, so a sign-in cannot be replayed, or started in one browser and finished in another.
- That the account is neither a guest nor a personal Microsoft account.
- Only then, the lecturer record with that sign-in name at this school.
Troubleshooting
What staff see, why, and what puts it right.
| Staff see | Cause | Fix |
|---|---|---|
| No Microsoft button at all | The school is at Off, or Microsoft tenant is empty. | Name the tenant and choose a mode. |
| … has not yet approved Wise Timetable. | The consent has not been given, or was withdrawn. | The consent address above. |
| … no lecturer at this school has that e-mail address. | The lecturer record has no address, or a different one, such as a mail alias. | Put the sign-in name shown in the message on the record. |
| That Microsoft account does not belong to this school. | An account from another tenant, or Microsoft tenant names the wrong one. | Check the setting; otherwise the person picks the right account. |
| That is a guest account … or That is a personal Microsoft account. | A B2B guest, or an outlook.com, hotmail.com or live.com account. | Only accounts your tenant issued can sign in. |
| Signing in with Microsoft did not work. | Anything else. | Note the time and write to us; the server log names the reason. |
Related
- Signing in with MicrosoftThe staff side: the steps, Microsoft’s one-time set-up, and what each message means.
- Setting up Microsoft sign-in, the PDFThis page as an eight-page guide for IT and the timetable office, to attach to a security review.
- Integration with your other systemsStudent records, HR, calendars and single sign-on: every route in and out of the timetable.
- Installing in productionFrom the installer to a working timetable: what to run, in what order, and what the server needs.
Want to see this working?
Book a 45-minute online presentation and we will walk through it against your institution's own scheduling problem.