Single sign-on
Sign-in options for staff and students. Configure once, enforce institution-wide.
Supported providers
- Google Workspace for Education — most common at K-12.
- Microsoft Entra ID (formerly Azure AD) — common at higher ed and districts on Microsoft.
- SAML 2.0 — for any IdP that speaks SAML (Okta, OneLogin, custom).
Google Workspace
From the admin console, open Settings → SSO → Google. Enter your domain (or domains, for districts with multiple) and we'll restrict sign-in to those domains. No client-secret sharing required.
Microsoft Entra ID
From Settings → SSO → Microsoft, enter your tenant ID. Optionally restrict to specific groups or security groups so SetFlow access is provisioned the same way as your other apps.
SAML 2.0
From Settings → SSO → SAML, paste your IdP metadata or upload the metadata XML. We'll show the SP metadata you need to configure on your side. Common attribute mappings (email, first name, last name, role) are configurable in the same screen.
Note
Enforcing SSO
Once SSO is configured, you can require it for everyone in your institution — meaning users can't sign in with email/password anymore, only through your IdP. We recommend enforcing SSO once you've confirmed it works for at least one teacher and one student.
