Pass › Single Sign-On (SSO)
Approving the Securly SSO App for Pass & Flex (September 2026 Cutover)
Cutover date: the week of September 28. To avoid any interruption to Pass or Flex sign-in for staff and students, your Google Workspace and/or Microsoft Entra ID (Microsoft 365) administrator should complete the approval steps below before September 25.
Is this email legitimate?
Yes — the "Action needed by Sept 25: Approve the Securly SSO app for Pass & Flex" email is a genuine Securly request, not a phishing attempt. We always appreciate the double-check. The official step-by-step guide is here: Securly SSO App Approval Guide (PDF). If you're ever unsure, you can confirm with your Securly Customer Success contact or support@securly.com.
Do we need to do anything? (Clever / ClassLink districts)
If your district rosters and signs in only through Clever or ClassLink, this change does not apply to you and no action is needed. Clever and ClassLink SSO continue to work exactly as they do today, and your existing OAuth/weblink to https://pass.securly.com/ does not need to change.
You only need to approve the Securly SSO app if any of your staff or students sign in to Pass or Flex directly with Google or Microsoft. If you use both a rostering provider and direct Google/Microsoft login, follow the steps for the Google/Microsoft platform you use.
Why you're receiving this
Pass and Flex currently sign in through a separate single sign-on (SSO) app named "Eduspire Securly App." The rest of the Securly product suite uses a Securly SSO app. (Note: there are two apps named "Securly," so always identify the correct one using the specific Client ID / App ID provided below.)
The week of September 28, Securly is moving Pass and Flex onto that same Securly app. Once your admin approves it, everyone in your district — staff and students — will use one sign-on to move between Pass, Flex, and the rest of your Securly products.
There is one thing to do before then: your Google Workspace admin and/or Microsoft Entra ID (Microsoft 365) admin — whichever your district uses for Pass/Flex sign-in — needs to approve the Securly app. This is an administrator-only task. Teachers, principals, and students don't need to do anything, and no one's login process will change.
Before you begin
- You'll need admin access to your Google Workspace Admin console and/or the Microsoft Entra admin center.
- Have the Securly app identifiers handy — Google Client ID:
476568907389-qipsbu3rb7c689u6k2a4rejrprgtdq6k.apps.googleusercontent.com; Microsoft Entra App ID:32f79990-71d1-43ec-9b49-67e6faffe076(app name "Securly Admin/Student Login"). - Keep your existing "Eduspire Securly App" active. Don't remove or block it yet — Securly will confirm when it's safe to retire, after the cutover is complete.
- Changes in either admin console can take up to 24–48 hours to fully take effect, so please don't wait until the last day.
For Google Workspace administrators
Complete these steps in the Google Admin console (admin.google.com), signed in with a super admin or Services Settings admin account.
- Log in to Google Admin as an admin.
- Go to Menu → Security → Access and data control → API controls.
- Click Manage Third-Party App Access (Manage App Access).
- Click Add app → OAuth App Name or Client ID.
- Paste this Client ID and search:
476568907389-qipsbu3rb7c689u6k2a4rejrprgtdq6k.apps.googleusercontent.com. Note: Securly does not appear if you search by the name "Securly" — you must add it by Client ID. - Select the Securly app, check the box for the Client ID, and click Select.
- Choose Trusted: Can access all Google services, then click Configure.
- Once configured, log out of Google Admin and close your browser.
Important — the "Google Workspace Marketplace allowlist" step is NOT required. Some versions of the announcement said districts with students under 18 should also allowlist the app under Apps → Google Workspace Marketplace apps. Securly's team has confirmed this step is not needed — and Securly will not appear in a Marketplace search anyway. If you completed the Client ID + Trusted step above, your Google setup is complete; you can disregard the Marketplace/allowlist step entirely.
Seeing "Google Workspace Admin" also listed as a trusted/configured app under API controls is expected — that's a separate Google service, not the Securly app, and it does not indicate a problem.
For Microsoft Entra ID (Microsoft 365) administrators
Complete these steps in the Microsoft Entra admin center (entra.microsoft.com), signed in as a Cloud Application Administrator, Application Administrator, or Privileged Role Administrator.
- Go to entra.microsoft.com and sign in as an admin.
- Open the admin-consent URL Securly provides (of the form
login.microsoftonline.com/organizations/…/adminconsent?client_id=…&redirect_uri=https://www.securly.…) and approve it on behalf of your organization. This consent step is what provisions the app into your tenant. - Return to entra.microsoft.com.
- Open Enterprise applications. Add a filter "Application ID starts with" and paste in
32f79990-71d1-43ec-9b49-67e6faffe076. - Open Properties.
- Set "Enabled for users to sign-in?" to Yes.
- Set "User assignment required?" to No.
- Click Save.
If "Securly Admin/Student Login" (App ID 32f79990-71d1-43ec-9b49-67e6faffe076) is not yet in your tenant's Enterprise applications, complete the admin-consent URL step first — approving that consent adds the app to your tenant, after which it appears under Enterprise applications and you can set the properties above. If it still doesn't appear after admin consent, contact support@securly.com so the platform team can assist.
Timeline
- Now – September 25: Approve the Securly app using the steps above. This is a preliminary setup so the transition is seamless; approving early does not change anything for users yet.
- Week of September 28: Securly switches Pass and Flex sign-in to the newly approved Securly app.
- Shortly after cutover: The legacy "Eduspire Securly App" is retired for Pass/Flex. Securly will confirm before this happens.
Frequently asked questions
Is this a phishing email?
No — it's a legitimate Securly request. See "Is this email legitimate?" above.
We use Clever or ClassLink — does this affect us?
Not if that's your only sign-in method; no action is needed. Only districts where users log in directly via Google or Microsoft need to approve the app. See the Clever/ClassLink section above.
Does our Pass or Flex login URL change? Do we need to update our Clever/ClassLink weblink?
No. The Pass URL (https://pass.securly.com/) is unchanged, so existing Clever/ClassLink weblinks stay as-is. A newer pass.securly.com/login link is not active yet and won't be until the cutover — keep using your current link until Securly says otherwise.
I can't find Securly when I search the Google Workspace Marketplace to allowlist it (we have students under 18). What do I do?
Nothing — that Marketplace allowlist step is not required. Securly confirmed it can be disregarded, and Securly does not appear in Marketplace search. Completing the Client ID + Trusted step under API controls is all that's needed.
Do teachers, principals, or students need to do anything?
No. This is an IT administrator task only. Once it's approved, sign-in for everyone else looks and works exactly the same.
Will this change how students or staff log into Pass or Flex?
No. Same Google or Microsoft sign-in button, same accounts. The only change is which approved app is doing the work behind the scenes.
What happens if we don't approve the app before September 28?
Staff and students may be temporarily unable to sign in to Pass or Flex until the new app is approved, since the old app will no longer be the active sign-in path for those products.
Can our district use both the Google and Microsoft instructions?
Yes. If your district federates through both, an admin should approve the app on whichever platform(s) you use for Pass/Flex sign-in.
Need help?
If your IT admin runs into any issues, or you're not sure which admin console your district uses for Pass/Flex sign-in, reach out to your Securly Customer Success contact or email support@securly.com and we'll walk your team through it.