Schoology Learning
English Spanish

Set up SAML single sign-on (SSO)

System administrators can configure SAML Single Sign-On (SSO) in Schoology. Refer to the Configuration reference section of this page for detailed field descriptions and logout type options.

Configure SSO

  1. Select Tools and choose School Management.

  2. Choose Integration and select Authentication.

  3. Select Cloud/On Premise Directory.

  4. Select SAML.

  5. Enter the details in the SAML Settings area. Refer to the SAML settings field reference table for field descriptions, required status, and guidance.

  6. After entering the Metadata URL, select Fill Fields Below from the Metadata URL button to automatically populate the remaining fields. You may also enter the Login URL, Logout URL, and X.509 Certificate.

  7. From Logout Type, select the appropriate logout option. Refer to the Logout type options table for a comparison of available options and ADFS examples.

  8. Select Save Changes.

  9. Use the SP Metadata URL from the beginning of the page to configure the Schoology metadata in your SAML IdP. This URL will not contain metadata until you have fully configured the SAML integration in Schoology and saved your settings.

  10. If you are using a custom domain or subdomain, select Custom Domain. Change the Landing Page field from Schoology Log In Page to SAML Login Page and click Save Changes.
    This step is required so that navigating to your custom domain or subdomain automatically initiates the SAML workflow. If you access Schoology without using the custom domain, the SP Metadata URL on the config page will not contain the custom domain and will be incorrect. Always use the custom domain URL when referencing SP Metadata.

You can now test the SAML login workflow by going to https://[Custom Domain]/login/saml.

To prevent students and teachers from logging in outside of your custom domain or subdomain, system administrators can enable the Ensure user logs in using an external authentication provider " permission for specific roles.

SSO configuration reference

SAML settings field reference

Field

Required

What to enter

Notes

SP Entity ID

Optional

A custom identifier for the Schoology Service Provider.

Only needed if two organizations share the same IdP. Leave blank for most installations.

ID Attribute

Optional

The SAML attribute used to identify the Schoology account.

Leave blank to use Name ID as the attribute. Attribute names may be sent as URNs, such as urn:oid:1.3.6.1.4.1.14519.1.1.

Match ID to Schoology Account Using

Required

Select the Schoology field to match against the SAML ID attribute: Username, Unique ID, or Email.

Must match what the IdP sends. Common SAML attributes include mail, sAMAccountName, or UserID.

Error URL

Optional

The URL to redirect users to if an authentication error occurs.

Leave blank to use the Schoology-generated error page.

Metadata URL

Required

Your SAML Identity Provider (IdP) Metadata URL.

For ADFS, enter: https://[ADFS Server Host]/FederationMetadata/2007-06/FederationMetadata.xml

X.509 Certificate

Required

Paste the token-signing certificate for the SSO request.

Must match the current certificate in your IdP metadata. Auto-populated if you use the Fill Fields Below button.

Logout type options

Logout Type

Behavior

Logout URL to enter

When to use

Standard

Users are redirected to the specified Logout URL after logging out of Schoology. They may remain logged into the SAML server until the browser is closed, and will be automatically logged back into Schoology when they return to the domain.

Enter the destination URL, such as the district or college homepage. For ADFS: https://[ADFS Server Host]/adfs/ls/IdpInitiatedSignon.aspx

Use when full session termination across all SAML services is not required.

SLO

Single Logout — users are logged out of all active SAML services simultaneously.

Enter the SLO endpoint. For ADFS: https://[ADFS Server Host]/adfs/ls/?wa=wsignout1.0

Use when complete session termination is required. SLO must be configured on your IdP before selecting this option.