Apply sync settings across the trust
Apply sync settings across the trust
If you run a multi-academy trust (MAT), you often want the same integration configuration on every school — one AD structure, the same Entra provisioning options, the same Apple format. Rather than open each school and set them one by one, this screen lets you set the shareable fields once and push them to as many schools as you choose in a single action.
You reach it from the Apply across MAT button on an integration's per-school settings page (shown to MAT admins), or from MAT Overview. Each integration — Google, Microsoft Entra, Active Directory, Apple — has its own version of this screen.
What "shareable" means
Not every setting can be pushed trust-wide. Each integration marks its fields as either shareable or per-school:
- Shareable fields are the ones that are normally identical across a trust — behaviour toggles, OU/path templates, default passwords, formats, prepends. Only these appear on this screen.
- Per-school fields are unique to each school and are deliberately left off this screen, so you can't accidentally overwrite them. These are the identity/credential fields: Google's domain and admin user, Apple's SFTP host / user / password, and AD's domain name and UPN suffix. Set those on each school's own settings page.
Whatever appears, nothing is pushed unless you tick it — untick a field and each school keeps its own value — and blank password/secret fields are never written, so you can't wipe a stored secret by accident.
Microsoft Entra is a special case. Trusts commonly run one Microsoft 365 tenant across all their schools, so Entra also exposes its connection details (tenant ID, client ID, client secret, UPN domain) on this screen. They behave like every other field — pushed only when ticked, left as-is per school when not. If your schools each have their own tenant, just leave those fields unticked and set them per school.
Entra's Group types to sync selector is shareable too, so you can standardise which kinds of group (Teachers of, Houses, Registration, Role, Year, Subjects, Groups) sync across the whole trust in one apply. Tick it and pick the types once; leaving every type unticked means "sync all types" on the schools you push to. The live Groups that will sync preview is per-school, so it appears only on each school's own Entra settings page, not here.
Before you start
- You must be a MAT admin — an admin authorised for more than one school in the trust. The apply action re-checks this.
- Switch to MAT Overview (the "All schools" option in the school switcher).
- Decide which settings you want to standardise and what their values should be.
Steps
Step 1 — Open the MAT settings for an integration {#step-1}
Open the trust-level settings for the integration you want — Google, Entra, Active Directory or Apple — via Apply across MAT on that integration's settings page, or from MAT Overview. The page is titled with the integration name, e.g. "Active Directory — MAT settings".
Step 2 — Tick the settings to apply {#step-2}
The settings form mirrors the normal per-school page. Use the section tabs (e.g. Connection, Provisioning, Prepends — the exact sections depend on the integration) to move between groups of settings. Tick each field you want to push, and set the value you want it to have. Unticked fields are left untouched on the target schools — only ticked fields are changed. This means you can push just one setting, or a whole configuration, without disturbing anything else. A running count shows how many settings you've ticked across all sections.
Step 3 — Select the target schools {#step-3}
In the Schools panel, tick each school you want to apply to, or use Select all. The count of selected schools is shown. The list only ever contains schools you're authorised for — you can't reach beyond your MAT access.
Step 4 — Apply {#step-4}
Select Apply to selected schools and confirm. Each ticked setting is written to each selected school. A message confirms how many schools were updated. Masked password fields left blank are not pushed, so you won't wipe a school's stored secret by accident.
Step 5 — Review per school {#step-5}
The change takes effect immediately in each school's stored settings and is picked up on the next sync run. To confirm, switch into a school and open the same integration's settings — the values you pushed will be there. Spot-check a couple of schools after a large roll-out.
Notes
- Only fields the integration marks shareable can ever be applied here — even if a request tried to smuggle in a per-school field, it would be refused.
- Applying only ever writes to schools you're authorised for; the selection is constrained to your MAT access on the server side too.
- This complements per-school setup: per-school identity and credential fields still have to be entered on each school — except Microsoft Entra's connection details, which can optionally be pushed here (see above) when a trust shares one tenant.