Single sign-on (SSO) overview

Single sign-on (SSO) lets users access external services from within Finalsite without logging in again. Authentications work in the opposite direction: letting users log into Finalsite using external credentials. Both are managed in Integrated Services Manager. Finalsite is rolling out a new connected SSO experience to all clients.

💡Quick answers

  • What's the difference between the identity providers (IDP) list and the SSO options list below? The identity providers list is for signing into Finalsite itself using an account from Microsoft, Google, Facebook, Apple, RapidIdentity, or Veracross. The SSO options list is for someone already signed into Finalsite passing through to a different platform, such as Canvas or FACTS, without signing in again there.
  • What is the difference between an SSO and an authentication in Finalsite? An SSO connects Finalsite to an external service so users can access it from Finalsite without a second login; an authentication or IDP connects an external service to Finalsite so users log into Finalsite using external credentials.
  • Where are SSO connections managed? In Integrated Services Manager, found in the Composer module menu.
  • Which external platforms does Finalsite support SSO with? Canvas, Catertrax, CHQ, FACTS, Google Workspace, Magnus Health, MySchool, Naviance, PCR, PeopleGrove, Pick a Time, PowerSchool Learning, PTC Wizard, Rediker Plus Portals, Schoology, Senior Systems, The School Volunteer, Veracross, Vidigami, and Zendesk.
  • What is the new connected SSO experience? An upgraded login system rolling out to all clients that includes multi-factor authentication, support for Google, Microsoft, and Facebook identity providers, and a consistent modern login page across all Finalsite products.
  • Is any action required to transition to the new connected SSO experience? No action needed now; Finalsite is rolling out the upgrade in waves and will notify clients when it applies to their site.

In this article


Single sign-on vs authentication

Single sign-ons (SSOs) and authentications are both ways of leveraging data that you already have to make the experience of using your website easier and smoother for both visitors and site administrators. 

  • An SSO is the connection between Finalsite and another service.
    • Users to log directly into the other service from Finalsite. 
  • An authentication is the connection between another service and Finalsite.
    • Users log directly into Finalsite using the credentials from the other service.
    • Read more in the article, Authentication overview.

SSOs and authentications are maintained in Integrated Services Manager found in the module menu. 

integrated services manager.png

Single sign-on is here!

A connected SSO experience is now rolling out to all Finalsite clients!

This major upgrade includes:

  • enhanced security with multi-factor authentication
  • support for popular identity providers (IdPs) like Google, Microsoft, or Facebook
  • a modern, consistent login experience across all Finalsite products

When enabled, you and your families will automatically be logged out of your Finalsite products. Upon return, you'll see a newly designed login page.

Wondering which login experience you currently have? 

Connected SSO experience Legacy login experience

If you see this login screen, you have been upgraded to the connect SSO experience: 

Finalsite's new login experience is built to boost security, simplify authentication, and create a seamless gateway across products. Whether you're logging in for the first time or switching between tools, learn more about how to manage the features in this newer login experience in the article, "Log in to Finalsite: The connected SSO experience." 

How do I get started with the new connected SSO experience?

Our goal is for all users to eventually transition to a Unified SSO experience to provide a single, seamless login across all Finalsite products.

  • No action is required now: We are rolling out SSO in waves. You will be informed with a notification and we will reach out if any additional action is needed.

  • Stay informed: We will provide full documentation and support throughout the transition process.

Sign in to Finalsite with an account you already have

Sign in directly to Finalsite using login credentials already set up with one of the following providers, instead of creating and remembering a separate Finalsite password. Each of these connects an outside account into Finalsite.

Provider How it works Setup Guide
Apple Sign in to Finalsite using an Apple ID. Apple SSO: Client-managed setup
Facebook Sign in to Finalsite using a Facebook account; most often used by portal users, such as parents. Meta / Facebook SSO: Client-managed setup
Google Workspace Sign in to Finalsite using a Google Workspace account. Google Workspace SSO: Client-managed setup
Microsoft (Entra ID, formerly Azure AD) Sign in to Finalsite using a Microsoft work or school account. Microsoft Entra ID (Azure AD) SSO: Client-managed setup
RapidIdentity Sign in to Finalsite using a RapidIdentity account. RapidIdentity SSO: Client-managed setup
Veracross Sign in to Finalsite using a Veracross account. Veracross SSO and integration: Client-managed setup

Passing the other direction, from Finalsite out to another platform without signing in again there, works differently and is covered in the next section.

Access other platforms from Finalsite without signing in again

These connections work in the opposite direction from the identity providers above: someone already signed into Finalsite passes through to one of the platforms below without a second login there. The table summarizes each one; click a platform name to jump to its details.

Platform Type What has to match or be set up first
Canvas SAML Username must match between systems; not a fit if users already sign into Canvas with Google or another method.
Catertrax SAML Users access CaterTrax exclusively through the Finalsite SSO link going forward.
CHQ SSO A shared datapoint between Finalsite and CHQ.
FACTS Secure token URL Nothing to set up in advance; accounts link automatically on first sign-in. Not supported if FACTS Enterprise is connected to the FACTS SIS.
Google SSO Third-party IdP passthrough Covers passing into Google Workspace apps after already being signed into Finalsite, configured on Google's side.
Magnus Health SSO + data integration The "Class Of" field populated for students, plus proper relationships in the client data.
MySchool SAML —
Naviance Student SSO only Finalsite ImportID recommended; no parent or faculty option.
PCR SSO Requires the PCR data integration already in place.
PeopleGrove SAML —
Pick a Time SSO pickAtime userID must match a Finalsite ImportID.
PowerSchool Learning Cloud IdP (miniOrange) A unique identifier (usually ImportID) or matching usernames between systems.
PTC Wizard SSO —
Rediker Plus Portals SSO Requires the Rediker data integration; dual-role faculty/parents need the same email on both Rediker accounts.
Schoology SSO An ImportID or username value matching between Finalsite and Schoology.
Senior Systems SSO Requires the Senior Systems data integration and authentication mechanism.
The School Volunteer SSO Existing users get matched to their Finalsite IDs first to avoid duplicates; new users are created automatically on first sign-in.
Veracross SSO Requires the Veracross data integration and authentication mechanism.
Vidigami SSO Primary email must match between systems (case-sensitive).
Zendesk SSO —

Canvas

Finalsite offers a SAML based SSO with Canvas. With this SSO, Finalsite becomes the Identity Provider for Canvas, so if users are currently logging in to Canvas with Google or by other means, this may not be the right option.  Your deployment expert will provide instructions for setting up the SSO on the Canvas side. This SSO is contingent upon the username matching between the two systems.

Catertrax

Finalsite now offers a single sign-on option with CaterTrax. This SSO option uses SAML and requires that the client understand that users will now access CaterTrax exclusively through Finalsite's SSO link.

This SSO can be configured with a default landing page and a default log out page, as well as provisioning options set in CaterTrax.

CHQ

Finalsite offers an SSO with CHQ. There will need to be a shared datapoint between Finalsite and CHQ for this to work as expected.

FACTS

Finalsite offers a single sign on for parents with FACTS Management. The SSO between the two systems uses a secure URL, containing an encrypted token, that is generated for each user in turn. There are a number of different scenarios for the SSO workflow, depending on whether a parent has an account in FACTS and has previously used the SSO from Finalsite.

Important Note

Please be advised that if you have connected FACTS Enterprise with the FACTS SIS, we are unable to support this SSO from Finalsite.

  • Parents with an existing FACTS account: When a parent first clicks the FACTS SSO link in Finalsite, they are transferred to FACTS. They may then enter their FACTS login credentials or register for a new account. If they authenticate successfully, their FACTS account is linked to their Finalsite account and, for all subsequent single sign-ons from Finalsite, they will be taken directly to the FACTS dashboard. 
  • Parents without a FACTS account: A parent who does not have an account in FACTS will not be able to link up their FACTS account to their Finalsite account by logging in to FACTS. Instead, alongside the option to enter FACTS credentials (which they do not have), they have the option of creating a new account.
    • The new account form will be pre-populated with the following data provided by Finalsite:
      • First name
      • Last name
      • Primary email address

Once the account has been created in FACTS, it is linked to their Finalsite account and, for all subsequent single sign-ons from Finalsite, the parent will be taken directly to the FACTS dashboard.

Google SSO 

Users can sign in once to access all of their Google Workspace and enterprise cloud applications. Learn more about SSO in the Google Workplace Admin Help Article, "Set up SSO via a third party identity provider." Once SSO is enabled, users can: 

  • Sign in to their third party identity provider (IdP).
  • Access Google apps without a second sign-in.
  • Set up additional two-step verification. 

This entry covers passing from Finalsite into other Google apps after already being signed into Finalsite. For signing into Finalsite itself with a Google Workspace account, see Sign in to Finalsite with an account you already have.

Magnus Health

Magnus Health is health software for K-12 Schools. Our offering is an SSO and an integration. We push student and parent data into Magnus for the client, from their Finalsite data, and receive a token that we can then use to allow parents to pass from Finalsite into Magnus without a second login.

Datapoints that can be pushed are listed below:  

Parent datapoints Student datapoints

Address

Phone

Work phone

Mobile phone

First name

Last name

Email

Username

First name

Last name

Phone number

Birthdate

Username

Address

Please note that this requires that a school utilize the "Class Of" field for their students as well as proper relationships in the client data.

MySchool

Finalsite offers a SAML based SSO with MySchool.

Naviance

Finalsite supports a Student SSO into Naviance.  Naviance does not offer Parent or Faculty options. It is recommended that the client setup the accounts in Naviance utilizing the Finalsite ImportID. We can support a different datapoint, but it may complicate configuration.

PCR

Finalsite offers a Single Sign on into PCR for clients who are also using the PCR data integration.

People Grove

Finalsite offers a SAML SSO option with PeopleGrove to facilitate a passthrough from Finalsite into PeopleGrove.

Pick a Time

Finalsite offers an SSO with Pick a Timethat will allow users to pass from Finalsite into Pick a Time without being challenged for credentials. Your deployment expert will work with you to ensure that the data is setup properly for the SSO to function. This requires pickAtime userID to match a Finalsite importID.

Powerschool Learning

Finalsite offers a way to enable SSO to PS Learning via the SSO option called miniOrange IdP which is a cloud based integration. 

This implementation requires that we either have a unique identifier in Finalsite (most commonly the ImportID) that matches a value set to the corresponding user in Powerschool OR that we have matching usernames.

PTC Wizard

Finalsite offers an SSO with PTC Wizard. This can be used to pass from FS to PTC Wizard without a second challenge for credentials. Finalsite Support can help you with the data work to ensure the SSO works as expected.

Rediker Plus Portals

Finalsite offers Student, Parent, and Faculty SSO into Rediker's PlusPortals for clients also using the Rediker data integration. Note that this requires dual role faculty/parents to have the same email on both accounts in Rediker to see parent and faculty info in a single SSO passthrough.

Schoology

Finalsite offers an SSO with Schoology. In order for this to function, either an ImportID value or a username value will need to match in Finalsite and Schoology. Your deployment expert will work with you on configuring this SSO on the Schoology side.

Senior Systems

The SSO with Senior Systems MyBackpack is contingent upon using the Senior Systems Data Integration and the Senior Systems Authentication mechanism. Once configured, it allows parents, students, and faculty to pass from the Finalsite portal into MyBackpack without a second challenge for credentials.

The School Volunteer

Finalsite offers an SSO with The School Volunteer.  If users already exist in The School Volunteer prior to implementing the SSO, your deployment expert will work with you to add the appropriate Finalsite IDs to those users in TSV to ensure they are not duplicated.  New users will be created in TSV when using the SSO the first time.

There are a few options for "deeplinks" with this SSO that will land users in specific sections of The School Volunteer including: "View My Schedule", "Nominate Leadership", and "View Committee".

Veracross

The SSO offered between Finalsite and Veracross requires using the Veracross Data Integration and Authentication mechanism. Once configured, users will be able to pass from the Finalsite Portal into a variety of locations in Veracross.

This entry covers passing from the Finalsite Portal into Veracross after already being signed into Finalsite. For signing into Finalsite itself with a Veracross account, see Sign in to Finalsite with an account you already have.

Vidigami

Finalsite offers an SSO option for Vidigami. It's simple to setup and allows for passing from Finalsite into Vidigami without a second set of credentials. It is important that the primary email in Finalsite match the email in Vidigami (case-sensitive)

Zendesk

Finalsite now offers a single sign-on with Zendesk. This will allow users to pass from a Finalsite portal into Zendesk without a second request for authentication.

Was this article helpful?
2 out of 4 found this helpful

Comments

0 comments

Please Sign in to leave a comment if you don't see the comment box below.