Appearance
Identity provider pilot runbooks
End-to-end checklists for connecting SchoolRota to your school's identity provider. SCIM roster sync, OIDC sign-in, group roles, optional Microsoft profile photos, and pilot testing in one place.
| Provider | Runbook | Best for |
|---|---|---|
| Microsoft Entra ID | Entra pilot runbook | Most UK school pilots; full SCIM + SSO + optional photos |
| Okta | Okta pilot runbook | Trusts and MATs on Okta |
| Google Workspace | Google pilot runbook | Google-first schools; SSO-first, SCIM via bridge or Entra/Okta |
Generic reference
Use these when you need API details rather than IdP click-paths:
- SCIM provisioning: one SCIM endpoint for all providers
- SSO setup. OIDC redirect URI and Admin form
Typical pilot flow
- Collect SchoolRota URLs and tokens from Admin
- Configure SCIM in your IdP (users + groups)
- Configure OIDC for login
- Map security groups to SchoolRota roles
- Run the provider runbook test checklist
- Expand from pilot group to full staff
- Microsoft 365 schools: optionally enable profile photos after staff have access
SAML
SchoolRota supports OIDC only today. Configure OIDC on Entra, Okta, or Google: not SAML.

