Skip to main content
All CollectionsSettings + PermissionsSecurity
Configuring + Managing Single-Sign-On (SSO)
Configuring + Managing Single-Sign-On (SSO)
Michael Stephenson avatar
Written by Michael Stephenson
Updated over a week ago

Overview

Element451 supports Single Sign-On (SSO) for both internal users (staff/faculty) and external users (students). This guide walks you through configuring SSO, managing metadata updates, and ensuring seamless authentication for your users.

If you're looking for guidance on enabling SSO or other authentication methods, visit our Security + Authentication Settings help article.


Configuration of SSO

To use your school's SAML2 SSO provider for either internal users (staff) or external users (students/contacts), you'll need to add your metadata to the SSO Authentication Settings:

  1. Navigate to SSO Settings

    • Settings > Manage Users > Security

  2. Find the Appropriate User Type Section

    • SSO must be configured separately for Internal Users (staff/admins) and External Users (students).

    • On this page, locate the relevant section:

      • SSO Authentication for Internal Users

      • SSO Authentication for External Users

  3. Create a New SSO Configuration

    • Click the + Create SSO Authentication button.

  4. Enter Metadata

    • Paste your SSO Metadata URL or XML provided by your Identity Provider (IdP). If you're also prompted to enter a single sign-on service provider URL, please contact Element451 Live Support for assistance.

  5. Save your Configuration

  6. Confirm that SSO is enabled for the user type(s) in Internal and/or External Authentication Settings.

  • NameID Mapping: Ensure that the SAML2 NameID attribute is mapped to the emailAddress value in your IdP settings.

  • For successful SSO login, the email address must match a user account in Element451.

Learn how to add internal users to Element451 here.


Renewing Your SSO Certificate

If your SSO signing certificate is set to expire, you’ll need to update the certificate to maintain uninterrupted authentication. Element451 does not actively monitor your metadata for updates. Therefore, it’s important to remember to update your metadata when your certificate is renewed:

  1. Work with your SSO provider to regenerate your SSO signing certificate. Once this is done, the updated certificate will be reflected in your metadata URL/file.

  2. Navigate to Settings > Manage Users > Security.

  3. Locate the expired authentication.

  4. Replace the current metadata with your updated metadata URL or file.

  5. Save your changes.

Did this answer your question?