Duplicate users
Two directories to provision.
Azure AD Integration connects ScholarERP to Microsoft Entra ID so staff (and optionally students) authenticate with existing school Microsoft accounts and group mappings.
IT already manages Entra ID; a parallel ERP password directory doubles offboarding risk.
Two directories to provision.
Microsoft disabled, ERP still open.
ERP roles ignore M365 groups.
Password resets everywhere.
Operational depth your team will use every cycle — not a shallow feature list.
OIDC/SAML patterns per deployment.
Security groups → ScholarERP roles.
Provision on first login when allowed.
Support multi-tenant trusts carefully.
Respect org CA policies at IdP.
Align staff email with Staff Management.
Success/failure events.
Local admin fallback.
A clear path your staff and parents can follow without training manuals.
App registration in Entra ID.
Groups to roles.
IT + one department.
Staff SSO campus-wide.
The right people see the right slice of the pipeline.
Owns Entra app & maps.
Uses school Microsoft account.
Applies CA at IdP.
Checks SSO audits.
Each module is an edge in the campus operating graph — not a silo.
Measurable ops wins institutions report once this module runs inside ScholarERP.
“Entra SSO let us retire a whole class of ERP password tickets.”
Straight answers for setup, integrations, and day-two operations.
Same Microsoft identity platform — we use current Entra ID naming with Azure AD still widely searched.
Yes — different populations or campuses can use different IdPs.
SSO covers login. Teams/Meet provisioning is a separate collaboration connector where enabled.
Student SSO can be enabled when licenses and policy allow.
Map one security group to Teacher role and test login.