Skip to main content

Internal SSO: Match Internal Users by School ID or SSO ID | May 2026

Staff and faculty can now have a School ID or SSO ID identity for SSO matching, expanding internal user SSO beyond email.

Written by Michael Stephenson

Released: May 21, 2026

Overview Header

Internal users (staff and faculty) can now be assigned identity values beyond email, with two new types: School ID and SSO ID. This expands Internal SSO matching: when an identity provider sends either value in its SAML response, Element451 authenticates the internal user against that identity instead of requiring an email match. Identities are managed directly from the internal user's Basic Info section, where they can be added, updated, or removed.

Details Header
  • Two New Identity Types for Internal Users: Internal users can now store a School ID and an SSO ID. Previously, internal users had no identity values and could only be matched on email.
    ​

  • SSO Matching by Identity: SAML ACS now matches internal users on either identity:SCHOOL_ID or identity:SSO_ID, so institutions whose IdPs return a non-email identifier can authenticate staff and faculty reliably.
    ​

  • Manage Identities from Basic Info: Users with the Administer Internal Users permission can add, update, or delete School ID and SSO ID values directly in the Basic Info section of the internal user profile.
    ​

  • Uniqueness Enforced: Each identity value must be unique across internal users; duplicates are rejected when attempting to save changes.

Benefit Header

Institutions whose SSO providers send a non-email identifier no longer have to force email as the matching field for internal user logins. IT teams can configure Internal SSO against the same School ID or SSO ID their IdP already issues, removing a common blocker during SSO rollouts.

Did this answer your question?