SSO Settings
Overview
Single Sign-On (SSO) lets users sign in to Manage1to1 with their school district's existing Google, Microsoft 365, or ClassLink account instead of a separate Manage1to1 password. SSO sign-in buttons appear on both the admin login page and the user login page.
When a user clicks one of these buttons, they sign in on Google's or Microsoft's secure page, then return to Manage1to1 already signed in.
Sign in with Google
Available out of the box. No setup required.
Any user whose Manage1to1 email matches a Google Workspace account in the district can sign in with Google. The first time a user signs in this way, Google shows a one-time consent prompt asking them to share their basic profile (name + email) with Manage1to1.
If a user clicks Sign in with Google and their Google email doesn't match an existing Manage1to1 admin or user, the page returns them to the login screen with an "invalid credentials" message. The account must already exist in Manage1to1; SSO does not create new accounts.
Sign in with Microsoft
Available out of the box. No setup required.
Works with any Microsoft Entra ID (formerly Azure AD) tenant — typical for districts running Microsoft 365. Same flow as Google: the user signs in on Microsoft's page, sees a one-time consent prompt the first time, and returns to Manage1to1 signed in.
Personal Microsoft accounts (@outlook.com, @hotmail.com, Xbox accounts) are not accepted. Only work and school accounts issued by a Microsoft 365 / Entra ID tenant can sign in.
The first time someone from your district signs in, Microsoft may ask them to consent to Manage1to1 reading their basic profile. After that first acceptance, future sign-ins are frictionless.
Some districts lock their Entra tenants down so individual users cannot grant consent to third-party apps. In that case, a Microsoft 365 administrator at the district clicks Accept once on behalf of the whole organization (the standard "grant admin consent" prompt every third-party SaaS uses), and every user in the district is then frictionless.
Sign in with ClassLink
Works with any district that uses ClassLink LaunchPad. Users can sign in with the Sign in with ClassLink button on the login page, or launch Manage1to1 straight from the Manage1to1 tile in their ClassLink LaunchPad.
The button works as soon as ClassLink is enabled. Launching from the LaunchPad tile also needs your ClassLink Tenant ID and a tile pointed at Manage1to1. See the ClassLink Sign-In guide for the full setup.
For ClassLink to authenticate a user, the user's ClassLink account must have an email address that matches an existing admin or user record in Manage1to1. Accounts not already in Manage1to1 are bounced back to the login screen with an "invalid credentials" message. SSO does not create new accounts.
Sign in with SAML 2.0
For districts on an enterprise identity provider — Okta, Azure AD / Entra, OneLogin, ADFS, Ping, or Shibboleth — administrators can sign in with SAML 2.0. Unlike the providers above, SAML is per-district: you paste your IdP's metadata, hand a few values to your IdP team, and enable it.
See the SAML 2.0 Sign-In guide for the full setup walkthrough. Running on-premises Microsoft ADFS? The Microsoft ADFS Sign-In guide walks the ADFS-side Relying Party Trust and claim rules.
Force Single Sign On
When Force Single Sign On is enabled, users must sign in with a configured SSO provider and cannot use a Manage1to1 password. Use this if your district has centralized identity management and does not want local Manage1to1 passwords in circulation.
Before enabling Force SSO, confirm:
- At least one SSO provider has been tested with a real account in your district
- Your administrative accounts can sign in via SSO (otherwise you'll lock yourself out)
- You've informed users that the password login form will no longer work
If you accidentally lock yourself out, Manage1to1 support can disable Force SSO from the back end so you can recover access — but plan ahead and avoid that round-trip.
Considerations
- SSO and password login can coexist. Enabling SSO doesn't disable passwords unless Force Single Sign On is also turned on.
- SSO only signs in users who already exist in Manage1to1. It does not create new admin or user accounts on demand.
- An SSO sign-in is logged the same way a password sign-in is — you can see "via Google SSO", "via Microsoft 365 SSO", or "via ClassLink SSO" in the user's profile login history.