Identity and Access Management

What is Single Sign-On

Single Sign-On (SSO) is a functionality that many institutions will configure during the implementation phase of transitioning to Inspera Assessment with their institution. SSO provides many benefits, not the least being that after users sign in to one of the services at an institution they are automatically authenticated into any other service that uses SSO. The user is only required to remember one set of credentials.

Third-party Identity Providers

Inspera Assessment supports authentication with a variety of third-party identity providers. Examples of existing integrations:

  • IMS LTI
  • Google SSO
  • Microsoft ADFS (Active Directory, Office 365, Azure, etc.)
  • Shibboleth
  • EduGain
  • Skolfederation (Sweden)
  • Feide (Norway)

In general adding support for a new identity provider only requires minor amounts of work, assuming one of the following standards is supported:

  • SAML 2
  • OAuth OpenId Connect (Google)

For most of these integrations, a Privacy by design scheme for Inspera Assessment can be used to de-identify personal data. In this way, it is impossible to connect personal data to an identifiable learner without the use of additional information stored outside of our assessment platform.

Recommendation

We recommend all our customers to follow Inspera Assessment's default privacy by design behaviour to minimise personal data processing.