Navigating Authentication Page (2.0)

Note: This article is about a new Edrolo feature coming soon 🎁

 

How do I set up Single Sign On (SSO) for my school?

You can turn on Single Sign On (SSO) yourself from the Authentication page in your school's Admin Hub if you have Administration access. It only takes a few minutes, but you'll need three details from your IT team or Identity Provider (IdP) first, so it's worth reading this whole guide before you start.

Tip: run Test SAML configuration before you turn SSO on for everyone. It's the easiest way to catch a typo or a mismatched detail before it affects your staff and students.

Before you start

You'll need these three details from your school's IT team or Identity Provider (IdP), the system your school uses to manage logins (for example, Google Workspace or Microsoft Entra):

  1. Entity ID / Issuer: your Identity Provider's unique identifier.
  2. Metadata certificate (Google) Metadata URL (Microsoft)
  3. Single sign on (SSO) URL: the web address that starts the sign-in process.
  4. Certificate: an X.509 certificate (a standard digital certificate) in PEM format. Your IT team will know this format, it looks like a block of text starting with -----BEGIN CERTIFICATE-----.

You might also see this setup referred to as SAML configuration. Security Assertion Markup Language (SAML) is simply the standard your Identity Provider and Edrolo use to talk to each other.

⚠️ Note: everyone's email address at your school needs to match the domain your Identity Provider covers (for example, @yourschool.edu.au). Personal email addresses, or addresses on an old domain, won't be able to sign in with SSO. It's worth double-checking a sample of staff and student accounts before you continue.

Setting up SSO for the first time

  1. From your Admin Hub dashboard, click Authentication in the left-hand menu. 
  1. Read through the information on the page. It explains what happens to your school's accounts once SSO is switched on, and what to check first.
  2. Tick "I understand the above information and am ready to proceed with SSO setup," then click Continue to setup. 

3. On the bottom field of the authentication page, click on the "Switch to metadata setup" 

4. Paste the metadata URL in the IdP metadata URL field, then click on preview (Microsoft). Or click on the upward arrow to upload the metadata certificate (Google). 

 

5. Click on save SAML configuration. This will route the page back to the manual setup, and the details and certificate will automatically be filled out. 

6. Click Test SAML configuration and wait for it to confirm success. If you see an error message under a field, double-check that detail with your IT team, common issues are a URL that's missing https://, or a certificate that's missing its BEGIN/END lines.

  1. Once the test passes, you have two options:
    • Click Save SAML Configuration on its own if you're not ready to switch everyone over yet. Your settings are saved, but staff and students keep signing in with their usual password for now.
    • Tick Enable SSO for all users, then click Save SAML Configuration, if you're ready to go live. Make sure you've told your staff and students the change is happening first, this takes effect straight away. 

Once SSO is enabled, everyone at your school will be sent to your Identity Provider to sign in the next time they need to log in to Edrolo.

If you have multiple email domains at your school

If your school uses more than one email domain (for example, a staff domain and a separate student domain), you'll see a note on the setup page listing each domain and how many accounts use it. Make sure your SSO configuration covers every domain you want signing in with SSO, any domain that isn't covered will need its emails updated, or those accounts re-provisioned, before you switch SSO on.

If something goes wrong after you turn SSO on

You can turn SSO off again at any time using the same toggle on the Authentication page. This immediately restores sign-in with password for every account, so nobody is locked out while you sort out the issue.

If a particular person can't sign in, it's usually because their email address doesn't match your Identity Provider's domain.

Need more support?

If you have any questions, please feel free to contact us at help@edrolo.com.au. Our friendly Customer Care team will be happy to jump on a phone call or video chat to assist you with the setup.

Was this article helpful?
0 out of 0 found this helpful