Tags: product:platform-access intent:sso intent:saml intent:authentication
An authorized administrator can review institution authentication at School Dashboard > Settings > Authentication. The page controls admin login options and, when applicable, volunteer and gift-officer login options.
For a WorkOS-managed connection, select Configure SSO in WorkOS and complete the identity-provider setup. When self-service setup is enabled, Set up Single Sign-On starts the connection. The page may also offer Invite your IT contact, which emails a direct setup link that does not require a GiveCampus account.
Connect and test the identity provider before enabling any Require … to sign in with SAML option. GiveCampus intentionally disables the requirement controls until a working SSO connection exists so an institution cannot lock out its own users. Depending on subscribed products, SAML can be required separately for administrators, gift officers, and volunteers.
For a legacy SAML connection, the page may show the metadata endpoint, entity ID, sign-on URL, sign-out URL, identifier format, certificate, and custom login-button text. Certificates must include the standard BEGIN CERTIFICATE and END CERTIFICATE boundaries.
If a unit inherits SSO from another institution, the Authentication page identifies the source. The inherited relationship cannot be changed from the child unit's page.
Comments
0 comments
Please sign in to leave a comment.