Migrating to the new authentication engine FAQ
Answers to common questions about moving your district to the new authentication engine.
Why is SchoolDay making this change?
A: The new authentication engine is a security and reliability upgrade. It's a modernized authentication system built on current identity standards, giving you stronger account protection, improved performance, and a more stable, scalable foundation for future SSO capabilities.
When will our organization be migrated, and how will we know?
A: The migration is gradual — no one is switched over all at once. We're moving customers in coordinated groups, and every organization is contacted directly ahead of its own transition date. You don't need to start the process yourself. If you have questions before you hear from us, contact Support.
How do I switch to the new authentication engine?
A: Contact Support to schedule your migration. Support will let you know what to prepare before the switch.
How will the migration look for me as a district admin?
On your agreed transition date, the SchoolDay Support team switches your organization over to the Authentication engine. This takes only a few minutes on our side. To finish setting up your own account, follow these steps.
To set up your account:
- Open the email with the subject line SchoolDay: Set Up Your Password and select the setup link.
- Enter and confirm a new password for your Authentication engine account.
- Set up multi-factor authentication (MFA) using a TOTP authenticator app:
- Scan the QR code.
- Download your recovery codes and store them securely.
- Confirm that you've saved them.
- Note: MFA enrollment is mandatory. You cannot proceed without completing it.
- Test your sign-in: navigate to sso.schoolday.com, enter your email address and password, then complete the MFA prompt.
- Result: You land on the Connect home page.
- Reply to Support to confirm sign-in succeeded, or report an issue immediately if it didn't. Support relies on this confirmation to verify your district's migration completed successfully.
What changes for me on the new authentication engine?
A: It depends on how your district uses SchoolDay. If your district uses SchoolDay for rostering only, your roster integration stays intact — the change affects only how your district admins sign in, with a new sign-in address and a simplified sign-in flow, both described below. If your district uses SSO, the change reaches all your users. Once it's complete, your users sign in through the new authentication engine, and they land on the redesigned Resources page instead of the AppStore dashboard. Personal folders aren't available after migration — bookmarks that were inside them remain at the top level of the Resources page.
Does the way users sign in change?
A: Yes, and it gets simpler. Today users select their organization first, then enter their credentials. On the Authentication engine, users enter their email address first, and their organization is identified automatically — one step fewer. This works the same way whether a user signs in with a password or through an identity provider such as Google or Microsoft Azure.
Does the sign-in address change?
A: Yes. For migrated organizations, the sign-in host changes from sso.gg4l.com to sso.schoolday.com. Let your users know to expect this, and to update any saved bookmarks when your organization's transition date arrives.
Is the AppStore going away?
A: Not as part of this migration. During migration, Connect synchronizes data with both AppStore and the new authentication engine, and AppStore remains available as a fallback until your district's migration is complete and verified.