Schoology Learning
English Spanish

Configure LDAP single sign-on (SSO)

Use LDAP single sign-on (SSO) to allow users to sign in to Schoology with their LDAP credentials instead of Schoology-managed credentials. After configuration is complete, users sign in through your custom Schoology domain.

Ensure your school firewall is configured to accept connections to your LDAP server from Schoology IP addresses.

  • 18.214.64.235

  • 18.233.173.39

  • 35.171.64.25

  • 52.200.56.106

  • 52.4.171.101

  • 52.5.140.116

  • 52.72.252.227

Configure the LDAP connection

  1. Select Tools and choose School Management.

  2. Choose Integration.

  3. From Authentication, select Cloud/On-Premise Directory.

  4. Select LDAP.

  5. Enter the details in the LDAP Settings area. Refer to the LDAP connection settings table for field details.

  6. Select Save Changes.

While Enable Account Creation is supported for existing customers, Schoology recommends provisioning users through your student information system (SIS), which should serve as the system of record for student data.

LDAP connection settings

Field

Details

LDAP Server Address

External IP address of the LDAP server

Port

LDAP server port

Directory User UPN

Account with read access to the LDAP server

Directory User Password

Password for the directory account

Base DN

Root node used to search for users and groups

Configure user attribute mapping

Configure how Schoology identifies and matches users in LDAP. Schoology supports matching users by:

  • Username

  • Email address

  • Unique ID

Leave attributes that you're not matching to LDAP, except Username RDN Attribute, blank.

If you use Username, Email, or Unique ID for matching, the value stored in Schoology must match the corresponding value in LDAP.

Common attribute settings

Setting

Description

Additional User DN

Limits the scope when searching for users

Username RDN Attribute

Required attribute used to locate users during sign-in

Username Attribute

Username value used to match Schoology and LDAP records

User First Name Attribute

User first name

User Last Name Attribute

User last name

User Email Attribute

User email address

User Unique ID Attribute

User unique identifier

Test the LDAP connection

After configuring LDAP, use Test Login to verify authentication. The test user must exist in both LDAP and Schoology and must be matched using your selected mapping attribute

If the test fails, review the message returned by the test.

Common test login errors

Error

Possible cause

LDAP User Lookup

Incorrect Username RDN attribute or user not found in LDAP

LDAP User Authentication Failure

Password does not match the LDAP password

Schoology User Identification

User mapping values do not match between Schoology and LDAP

Enable the LDAP login page

After successful testing, select Custom Domain. Verify that your custom domain settings are configured.

Contact PowerSchool Support if the Domain Type has not been set or your Domain Alias has not been changed to your school’s custom subdomain.

From the Landing Page, select LDAP Log In Page and click Save Changes. Users will be able to log in to Schoology using your custom domain and LDAP credentials.

Restrict users to LDAP sign-in

To prevent users from signing in outside of your configured authentication provider, enable the Ensure user logs in using an external authentication provider permission.