teechr for IT teams
Last updated: 16 September 2026
Lecturers at your organization can sign in to teechr with their Microsoft work or school account. If your organization lets only administrators approve apps, they see Microsoft's "Need admin approval" message instead, until one of you approves teechr. It takes a minute. teechr gets nothing more than a person's name and email address when they sign in.
Approve teechr for your organization
This opens Microsoft's approval page. Sign in there with an administrator account (see who can approve).
At a glance
- App
- teechr
- Publisher
- KERAPPS, verified by Microsoft (publisher domain kerapps.com)
- Application (client) ID
c2c81501-5451-47c5-b3af-0421934608f8- Protocol
- OpenID Connect on the Microsoft identity platform (v2.0 endpoints), with the authorization code flow and PKCE, from a confidential web app
- Accounts
- Work or school accounts from any Microsoft Entra ID organization, and personal Microsoft accounts
- Provisioning
- None needed. A teechr account is created the first time someone signs in.
- Other ways in
- Google, or an email address and password
What teechr asks for, and why
| Permission | Why teechr needs it |
|---|---|
openid | To sign the person in. |
profile | Their name, shown on their teechr account. |
email | The address their teechr account belongs to, so they reach the same account however they sign in. |
These are delegated permissions, read once from the ID token when someone signs in. teechr doesn't use Microsoft Graph. It can't read mail, files, calendars or anyone else in your directory, and it keeps no Microsoft access or refresh tokens. It identifies each person by your tenant ID and their object ID, not by their email address alone.
teechr also reads the xms_edov claim, which says whether your organization has verified the domain of the person's address. When it hasn't, teechr confirms the address once, with a code sent to it.
Who can approve
Approving teechr for everyone takes one of these Microsoft Entra roles: Global Administrator, Privileged Role Administrator, Cloud Application Administrator, Application Administrator or AI Administrator, or a custom role allowed to grant permissions to applications. Microsoft asks anyone else to sign in with an administrator's account.
Set it up
- Select Approve teechr for your organization above, and sign in with an administrator account.
- Check the three permissions and select Accept. Microsoft sends you back to this page, and the line beside the button says whether the approval went through.
- That's all. teechr now appears in the Microsoft Entra admin center under Enterprise apps, and people in your organization can sign in without being asked.
To let only some people in, open teechr in Enterprise apps, set Assignment required? to Yes under Properties, then add the people or groups under Users and groups.
To review the approval, open teechr in Enterprise apps and select Permissions under Security. To remove teechr, select Delete under Properties. That stops Microsoft sign-in to teechr for your organization, but doesn't delete anyone's teechr account. To have accounts deleted, email us.
Try it with a pilot group
- Set Assignment required? to Yes and assign a pilot group, as above.
- A pilot user opens teechr.co, selects Get started, then Continue with Microsoft, and signs in with their work account. They land in their own teechr studio.
- Someone outside the group gets Microsoft's error AADSTS50105. That means assignment is working.
- When you're ready, assign more people, or set Assignment required? back to No.
Licensing
- Microsoft: no extra license. Sign-in works with every Microsoft Entra ID edition, including Free.
- teechr: each lecturer has their own account. The first lesson is free. After that, plans start at €7.99 a month, VAT included; see Pricing. Students watch lessons without an account.
Troubleshooting
| What someone sees | What it means | What to do |
|---|---|---|
| "Need admin approval" (AADSTS90094) | Only administrators can approve apps in your organization, and teechr isn't approved yet. | Approve teechr, above. |
| AADSTS65001 | teechr's permissions haven't been approved for this person or for your organization. | Approve teechr, above. |
| AADSTS50105 | Assignment is required, and this person isn't assigned. | Assign them, or set Assignment required? to No. |
| AADSTS53003 | A Conditional Access policy blocked the sign-in. | Check the sign-in logs for teechr to see which policy applied. |
| AADSTS7000112 | teechr is disabled in your organization. | Under Properties, set Enabled for users to sign in? to Yes. |
| teechr says "Sign-in with Microsoft was cancelled" | The person backed out, or was stopped at "Need admin approval". | Approve teechr if you haven't, then try again. |
| teechr asks to confirm an email address with a code | Microsoft didn't vouch for the address: a personal Microsoft account, an account without an email address, or a domain your organization hasn't verified. | Type the code once. Later sign-ins go straight in. |
Support
Email hello@teechr.co. Include the error code, the time it happened, and the Correlation ID from Microsoft's error page when there is one. How teechr handles personal data is explained in the privacy policy.
teechr