Identity and Access Management
What is Single Sign-On
Single Sign-On (SSO) is a functionality that many institutions will configure during the implementation phase of transitioning to Inspera Assessment with their institution. SSO provides many benefits, not the least being that after users sign in to one of the services at an institution they are automatically authenticated into any other service that uses SSO. The user is only required to remember one set of credentials.
Third-party Identity Providers
Inspera Assessment supports authentication with a variety of third-party identity providers. Examples of existing integrations:
- IMS LTI
- Google SSO
- Microsoft ADFS (Active Directory, Office 365, Azure, etc.)
- Shibboleth
- EduGain
- Skolfederation (Sweden)
- Feide (Norway)
In general adding support for a new identity provider only requires minor amounts of work, assuming one of the following standards is supported:
- SAML 2
- OAuth OpenId Connect (Google)
For most of these integrations, a Privacy by design scheme for Inspera Assessment can be used to de-identify personal data. In this way, it is impossible to connect personal data to an identifiable learner without the use of additional information stored outside of our assessment platform.
Recommendation