This guide walks you through configuring Single Sign-On (SSO) between Microsoft 365 (Azure AD) and RollCall using SAML 2.0.
Overview
By completing this setup, your users will be able to:
Log into RollCall using their Microsoft 365 credentials
Avoid managing separate passwords
Experience a secure and seamless login process
Before You Begin
Make sure you have:
Admin access to Azure Portal
Access to RollCall SSO Setup Wizard
Your school’s RollCall domain (e.g.
schoolname.rollcall.com.au)
⚙️ Step-by-Step Configuration (Azure AD)
Step 1 – Access Azure Active Directory
Go to: https://portal.azure.com
Navigate to:
Azure Active Directory → Enterprise Applications
Step 2 – Create a New Application
Click New application
Select Create your own application
Enter a name (e.g. RollCall SSO)
Choose:
“Integrate any other application you don't find in the gallery”Click Create
Step 3 – Configure Single Sign-On (SAML)
Open your newly created application
Navigate to: Single sign-on
Select SAML
Step 4 – Basic SAML Configuration
In the Basic SAML Configuration section:
| Field | Value |
|---|---|
| Identifier (Entity ID) | Provided by RollCall (e.g. schoolCodeRollCallSSO) |
| Reply URL (ACS URL) | Provided by RollCall (e.g. https://konect-api-v2.rollcall.com.au/rollcall-sso/v1/acs/) |
? These values are available in the RollCall SSO setup wizard.
Step 5 – Configure User Attributes & Claims
Go to User Attributes & Claims
Ensure the following is configured:
NameID
Format:
EmailAddress(recommended) orPersistentSource:
user.userprincipalname
Important Note ⚠️
If your users’ UPN is NOT their email address:
Add a custom claim:
Name:
emailSource attribute:
user.mail
This ensures RollCall can correctly match users.
Step 6 – Assign Users or Groups
Go to Users and groups
Click Add user/group
Assign:
Staff
Parents (if applicable)
? Recommended for testing:
Start by assigning only a single test user
Step 7 – Download SAML Metadata
Go to SAML Certificates section
Download:
Federation Metadata XML
orCopy the App Federation Metadata URL
Complete Setup in RollCall
Once Azure AD is configured:
Open the RollCall SSO Setup Wizard
Upload or paste your metadata XML / URL
Map required attributes (email, name, etc.)
Run a Test Login
Click Activate SSO
Testing the Integration
Before going live:
Use a test account
Confirm:
Successful login via Microsoft
User is matched correctly in RollCall
❗ Troubleshooting Tips
| Issue | Likely Cause | Solution |
|---|---|---|
| User cannot log in | Email mismatch | Ensure Azure email matches RollCall |
| Login loop / failure | Incorrect ACS URL | Re-check RollCall values |
| User not found | Not assigned in Azure | Assign user to application |
| Missing user data | Incorrect claims | Verify email claim setup |
? Key Notes
RollCall uses email address to identify users
SSO must be activated after testing
Each school’s configuration is isolated and secure
✅ Summary
By completing this setup:
Users log in via Microsoft 365
Authentication is handled securely via SAML
Admins maintain full control through Azure AD
Here to link to:
Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article