Entra ID Configuration (SHA-256)

This article provides information on how to configure your Entra ID instance for use with Education Perfect's Single Sign-On (SSO) system.

Please note that we now support logging in with Microsoft Entra ID directly, and it may not be necessary to set up an integration at all!

Please see our help doc here or contact us for more details.

Azure or Entra? New name for Azure Active Directory

Setup in Entra ID

Please note that you will require the Global Administrator role to be able to complete this set up

  1. Visit the Azure portal
  2. Click Microsoft Entra ID

  3. Click Add then Enterprise application

  4. Click Create your own application

  5. Enter 'Education Perfect SAML" as the app name.

    Make sure the last option mentioning (Non-gallery) is selected and ignore any suggested Applications shown

  6. Click Create at the bottom

  7. Click Set up single sign on

  8. Click SAML

  9. Click the Icon next to the App Federation MetaData Url to copy this to the clipboard and send this link, along with the details for a test account to support@educationperfect.com

    Please note that you will be unable to fill out boxes 1 and 2 at this time, and this is expected

  10. With this information we will set things up on our side and should get back to you within a week with the information required for the next steps.

Secondary steps

Once you have received a reply from us, go back into the application where you were before and make the following changes:

  1. Click Edit on the first box (Basic SAML Configuration)

    Click Add Identifier and Add reply URL

    Fill in the Identifer (Entity ID) with the Issuer as provided in the last email.

    Fill in the Reply URL (Assertion Consumer Service URL) with the value from below:

    Worldwide: https://iam.educationperfect.com/samlv2/acs

    Canada: https://iam.ca.educationperfect.com/samlv2/acs

    Click Save

    Click No, I'll test later as this will not work at this time.

  2. Click Edit on the second box (Attributes & Claims)

    Edit the second box User Attributes and Claims. Click to Edit Unique User Identifier (Name ID)

    Click Choose name identifier format and ensure it is set to email address in the drop down

    Click Source attribute and select user.mail

    Click Save and then the Close 'X' on the right

    Click No, I'll test later if it appears as this will not work at this time.

  3. Allow user access to the newly created SAML Application:

    Click Properties on the left hand side bar

    Set Assignment required? to No

  4. Email us and lets us know that this step has been completed: once we received confirmation, we will finalize the connection and commence testing. If you are unable to provide an account for testing, we will likely send you a link to test the log in yourself.

Match existing users to their accounts

If your students have already been using Education Perfect without an Entra ID integration, their EP accounts will need to be linked to the unique identifier Entra ID uses to confirm their identity. The above user claims settings will make this their email address, but we use the test accounts to confirm everything is configured correctly. We'll match up everyone we can on your behalf. We will then send you a list of anyone we couldn't match. Once you send us the details for those people, we'll update them as well.

Please note that until we have completed this step users will get an error if they attempt to log into Education Perfect via Entra ID.

Did you find this article helpful? Thanks! Click the speech bubble below to tell us more. There was a problem submitting your feedback. Please try again later.