How to use
Open the school dashboard’s Authentication Settings. Follow the offered WorkOS setup/configuration flow, or the legacy SAML form if the school is configured for that interface. For WorkOS-managed schools, use Share with IT when offered to hand off the supported setup link.
Rules
New/unconfigured schools default to a WorkOS setup prompt; already configured legacy schools or an explicit legacy opt-in can retain the older form. Unit schools may inherit a system school’s identity provider and should not independently overwrite its configuration.
Displayed WorkOS statuses include Active, Pending testing, Setup incomplete, Disabled, and Deleting. Newly enabling SSO requirements is gated until the connection is usable. A school with setup incomplete should finish/test setup rather than trying to force the requirement on.
Troubleshooting
Check whether the school owns, shares, or inherits its identity provider. If the configuration button cannot create a portal link, record the displayed error and contact support. Do not share private setup links outside the authorized IT handoff.
“Require Administrators to sign in with SAML” with WorkOS
The requirement controls also apply to WorkOS-managed school SSO. WorkOS is not excluded merely because the checkbox label says SAML: the controls depend on a usable WorkOS, legacy SAML or shared identity-provider configuration. Have authorized IT verify the working connection and intended administrators before requiring SSO. This does not itself create product access or a last-login report.
Find the SSO UUID without guessing from a school name
In the legacy SAML configuration form, Authentication Settings displays a UUID field. A school’s initial identity-provider UUID is based on its lowercase URL nickname. A capitalized public URL nickname is therefore not the exact value to paste blindly; inspect the stored field. Schools sharing or inheriting another identity provider need the effective provider's configuration, not a newly invented identifier.
WorkOS-managed schools show the WorkOS configuration flow instead of the legacy form. Use that flow or Share with IT when offered. The legacy IDP Metadata Endpoint field describes the identity provider's endpoint; do not assume it is a GiveCampus service-provider metadata download. The settings screen does not confirm the ticket-supplied /auth/saml/metadata?uuid=... recipe. Have support or authorized IT confirm the actual metadata and reply/ACS values for the school's configured integration. Administrator status alone does not make an unrelated or obsolete setup URL valid.
Require SAML label with WorkOS and login-report scope
The label Require Administrators to sign in with SAML also applies to the WorkOS-managed SSO path. An active WorkOS connection supports these school SSO requirements. Confirm the connection works before requiring it. For login reporting, the volunteer activity CSV includes Last Login for volunteers. Do not treat administrator Last Activity as a pure login timestamp: it is the later of recorded administrator activity and user last sign-in. The controls do not confirm one self-service export of last login for every type of user; define the intended population for an authorized support report.
Comments
0 comments
Please sign in to leave a comment.