Overview
mymeddiCAL supports three sign-in methods. They are not interchangeable.
This page is only about staff. Changing SSO does not change how parents sign in. See Inviting a guardian and Accepting an invitation.
Only a Super Admin can open and save SSO Settings. Staff and nurse roles can use SSO to sign in once you have turned it on, but they cannot change the switches.
What you are choosing
Pick one staff model before you invite a large team. You can change later, but people can get locked out if you require SSO before Microsoft/Google actually works. A — Email and password (default)Staff receive an invite, set a password, and sign in at
yourorg.mymeddical.com. No school IT work. Use this unless the school already lives in Microsoft 365 / Google Workspace.
B — Microsoft Entra ID (Azure AD) — typical for schoolsStaff click Continue with Microsoft on your organisation login page and use their school Microsoft account (including MFA your IT already requires). Best when the school already uses Microsoft 365. C — Google Workspace
Same idea with Continue with Google, limited to your school’s Google domain. You can offer Microsoft and Google at the same time. You can also leave password login on as a backup, or turn Require SSO Only so staff cannot use a password.
Before you start (Microsoft / Entra)
You need two people, or one person with both hats:- A mymeddiCAL Super Admin (this page).
- A school IT admin who can open Microsoft Entra admin center (or Azure Portal) for the school’s directory.
- Your organisation URL, e.g.
https://yourschool.mymeddical.com - The school’s Entra tenant ID (a GUID that looks like
xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx) — steps below - The work emails staff already use for Microsoft 365 (you will add the same emails in mymeddiCAL)
Open SSO Settings
- Sign in to your organisation portal as Super Admin (e.g.
https://yourschool.mymeddical.com). - In the left sidebar, click Settings.
- Scroll to the card titled Single Sign-On (SSO) Settings.
- You should see an info banner: Super Admin Settings — Configure SSO to allow users to sign in with social accounts. Changes take effect immediately after saving.
Keep password login (do nothing extra)
New organisations already use password login. You do not need SSO Settings for that. To add staff on password login:- Follow Inviting staff — Add Staff, then Send Invite.
- They set a password from the email (see Accepting an invitation).
- They sign in at your organisation URL with email and password.
Turn on Microsoft / Entra (step by step)
Do these in order. Do not turn on Require SSO Only until step 8 works.Step 1 — Find your Entra tenant ID (school IT)
- Open https://entra.microsoft.com and sign in as a school IT admin.
Alternative: Azure Portal → Microsoft Entra ID. - Open Identity → Overview (Entra) or Microsoft Entra ID → Overview (Azure).
- Copy Tenant ID. It is a GUID, not the school’s web domain, and not your email.
Step 2 — Enable SSO in mymeddiCAL (Super Admin)
- Open Settings → Single Sign-On (SSO) Settings.
- Switch Enable SSO on. Extra options appear.
- Leave Require SSO Only off for now (password still works as a backup).
- Under Providers, switch Microsoft on.
- In Limit sign-in to a specific Microsoft / Azure AD tenant, paste the Tenant ID from step 1.
Do not leave this empty for a school — empty means any Microsoft account (including personal Hotmail/Outlook) could try to sign in. - Optional but recommended: in Allowed Email Domains, type your school domains, comma-separated, with no
@. Example:yourschool.vic.edu.au, yourschool.edu.au - Leave Auto-create Staff Accounts off unless you have read Auto-create staff and still want it.
- Click Save SSO Settings.
- Confirm the status tags show SSO Enabled (and not yet Password Login Disabled).
Step 3 — Restrict who can use the app in Entra (school IT)
mymeddiCAL appears in your directory as an enterprise application after the first successful consent / sign-in. If it is not there yet, complete Super Admin test sign-in in step 4 first, then return here.- In Entra admin center go to Identity → Applications → Enterprise applications.
- Open the mymeddiCAL application (search if the list is long).
- Open Properties.
- Set Assignment required? to Yes. Save.
- Open Users and groups.
- Add user/group. Choose a security group such as
mymeddiCAL staffthat contains only the people who should use the product (nurse, office, first-aid officers — not every teacher mailbox). - If a Permissions / Grant admin consent prompt appears for Microsoft Graph (
openid,profile,email,User.Read), grant admin consent for the organisation.
Step 4 — Test as Super Admin
- Sign out of mymeddiCAL (or use a private browser window).
- Go to
https://yourschool.mymeddical.com. - You should see Continue with Microsoft as well as email/password.
- Click Continue with Microsoft.
- Sign in with the same work email as your mymeddiCAL Super Admin account.
- Complete MFA if Entra asks.
- You should land on the dashboard. That email is now linked to Microsoft for this organisation.
Step 5 — Add staff with matching emails
- Go to Staff & Users → + Add Staff.
- Use each person’s Microsoft 365 email — it must match exactly (including spelling).
- Choose their role. Save.
Step 6 — Tell staff how to sign in
Send them:- Your organisation URL:
https://yourschool.mymeddical.com - Click Continue with Microsoft
- Use their school Microsoft account (the same email you entered under Staff)
Step 7 — Optional: link an existing password account
Staff who already have a password can keep it until you require SSO. After they click Continue with Microsoft once with the same email, Settings → Linked Accounts will show Microsoft connected. They do not need a second mymeddiCAL user.Step 8 — Optional: require SSO only (turn passwords off for staff)
Only after you can sign in with Microsoft:- Settings → SSO Settings.
- Switch Require SSO Only on. The helper text reads: Disable password login — users must use SSO to sign in.
- Save SSO Settings.
- Status should show SSO Enabled and Password Login Disabled.
- Staff sign in with Microsoft (or another provider you left on).
- The add-staff screen tells you no invite email is needed — share the login URL instead.
- Password login is off for staff only. Guardians still use email codes.
Turn on Google Workspace (step by step)
- Settings → SSO Settings → switch Enable SSO on.
- Under Providers, switch Google on.
- In Limit sign-in to a specific Google Workspace domain, enter the domain without
@(e.g.yourschool.vic.edu.au).
If this is empty, any Google account could be used — do not leave it empty for a school. - Optional: set Allowed Email Domains the same way as for Microsoft.
- Leave Auto-create Staff Accounts off unless you intend it.
- Save SSO Settings.
- Sign out, open your organisation URL, click Continue with Google, and sign in with a school Google account that already exists as a staff user (same email).
- Restrict the Google Cloud / Workspace app to your organisational unit if your IT requires it (that work is in Google Admin, not in mymeddiCAL).
Apple
The Apple switch allows Continue with Apple on the staff login page. There is no school-domain box for Apple on this screen — if you enable it, also set Allowed Email Domains so random Apple IDs cannot be used. Most Australian schools should leave Apple off and use Microsoft or Google.Auto-create staff (leave this off unless you mean it)
Auto-create Staff Accounts creates a new staff user on first successful SSO login if that email is not already in your organisation. Leave it off for almost every school. If it is on, and Microsoft tenant ID / Google domain / allowed domains are too loose, people you never invited can appear as staff. If you turn it on:- Still add Microsoft tenant ID or Google hosted domain, and Allowed Email Domains.
- Still use Entra Assignment required.
- Know that new users get the default staff role configured for SSO (typically Staff) — not Super Admin. You must change roles afterwards in Staff & Users.
Government / shared directories
If your Microsoft tenant is shared across many schools:- Always paste the tenant ID (step 1 of Microsoft setup).
- Always set Allowed Email Domains to this school only.
- Always set Entra Assignment required = Yes and assign a group that only contains this school’s staff.
- Keep Auto-create Staff Accounts off.
- Prefer invite-then-SSO (add each staff email yourself) over auto-create.
Adding staff after SSO is on
Use the same email as Entra or Google. A personal Gmail next to a school Microsoft account will not match.
Switch back to password login
- Settings → SSO Settings.
- Switch Require SSO Only off first (passwords become available again). Save.
- If you want SSO gone entirely, switch Enable SSO off. Save. Status should read SSO Disabled.
- Staff who never had a password need a new invitation or a password reset so they can sign in with email and password.
What this never does
- It does not put parents into Entra or Google. Families keep magic link / email code.
- It does not change a staff member’s role (Nurse vs Admin). You still set that under Staff & Users.
- It does not sign people out of Entra when you remove them from mymeddiCAL. Remove them from the Entra group and deactivate them in Staff & Users.
- mymeddiCAL sessions can last up to about 24 hours after you remove someone. Entra MFA and Conditional Access still apply at the Microsoft button on the next login.
Troubleshooting
I don’t see Continue with MicrosoftEnable SSO, enable the Microsoft provider, Save. Hard-refresh the login page. Confirm you are on
yourorg.mymeddical.com, not the generic marketing site.
Microsoft works for me but not for a colleagueTheir Staff & Users email must match their Microsoft email. They must be in the Entra group if assignment is required. Wait a few minutes after group changes. “User not found and auto-provisioning is not enabled”
They are not a staff member in this organisation yet (and auto-create is off). Add them under Staff & Users first. I turned on Require SSO Only and I’m locked out
You still need a Super Admin who can use Microsoft, or contact support@mymeddical.com to turn Require SSO Only off. Test SSO before requiring it. Parents ask for the Microsoft button
They should use the Parent / Guardian path and the email code, not staff SSO. See Accepting an invitation. Department IT asks if they must register their own app
Not for this setup. You use mymeddiCAL’s Microsoft sign-in, locked to your tenant ID. School IT consents and assigns users. Registering a separate school-owned app is not required for this flow.

