Single sign-on (SSO) lets users access external services from within Finalsite without logging in again. Authentications work in the opposite direction: letting users log into Finalsite using external credentials. Both are managed in Integrated Services Manager. Finalsite is rolling out a new connected SSO experience to all clients.
💡Quick answers
- What's the difference between the identity providers (IDP) list and the SSO options list below? The identity providers list is for signing into Finalsite itself using an account from Microsoft, Google, Facebook, Apple, RapidIdentity, or Veracross. The SSO options list is for someone already signed into Finalsite passing through to a different platform, such as Canvas or FACTS, without signing in again there.
- What is the difference between an SSO and an authentication in Finalsite? An SSO connects Finalsite to an external service so users can access it from Finalsite without a second login; an authentication or IDP connects an external service to Finalsite so users log into Finalsite using external credentials.
- Where are SSO connections managed? In Integrated Services Manager, found in the Composer module menu.
- Which external platforms does Finalsite support SSO with? Canvas, Catertrax, CHQ, FACTS, Google Workspace, Magnus Health, MySchool, Naviance, PCR, PeopleGrove, Pick a Time, PowerSchool Learning, PTC Wizard, Rediker Plus Portals, Schoology, Senior Systems, The School Volunteer, Veracross, Vidigami, and Zendesk.
- What is the new connected SSO experience? An upgraded login system rolling out to all clients that includes multi-factor authentication, support for Google, Microsoft, and Facebook identity providers, and a consistent modern login page across all Finalsite products.
- Is any action required to transition to the new connected SSO experience? No action needed now; Finalsite is rolling out the upgrade in waves and will notify clients when it applies to their site.
In this article
- Single sign-on vs authentication
- Sign in to Finalsite with an account you already have
- Access other platforms from Finalsite without signing in again
Single sign-on vs authentication
Single sign-ons (SSOs) and authentications are both ways of leveraging data that you already have to make the experience of using your website easier and smoother for both visitors and site administrators.Â
- An SSO is the connection between Finalsite and another service.
- Users to log directly into the other service from Finalsite.Â
- An authentication is the connection between another service and Finalsite.
- Users log directly into Finalsite using the credentials from the other service.
- Read more in the article, Authentication overview.
SSOs and authentications are maintained in Integrated Services Manager found in the module menu.Â
Single sign-on is here!
A connected SSO experience is now rolling out to all Finalsite clients!
This major upgrade includes:
- enhanced security with multi-factor authentication
- support for popular identity providers (IdPs) like Google, Microsoft, or Facebook
- a modern, consistent login experience across all Finalsite products
When enabled, you and your families will automatically be logged out of your Finalsite products. Upon return, you'll see a newly designed login page.
Wondering which login experience you currently have?Â
If you see this login screen, you have been upgraded to the connect SSO experience:Â
Finalsite's new login experience is built to boost security, simplify authentication, and create a seamless gateway across products. Whether you're logging in for the first time or switching between tools, learn more about how to manage the features in this newer login experience in the article, "Log in to Finalsite: The connected SSO experience."Â
If you are a Finalsite client that has not yet been moved over to the universal, connected SSO screen, you may still see this legacy log in experience:Â
To learn more about how to manage the legacy login features, check out the article, "Log in to Finalsite: The legacy login experience."
How do I get started with the new connected SSO experience?
Our goal is for all users to eventually transition to a Unified SSO experience to provide a single, seamless login across all Finalsite products.
No action is required now: We are rolling out SSO in waves. You will be informed with a notification and we will reach out if any additional action is needed.
Stay informed: We will provide full documentation and support throughout the transition process.
Sign in to Finalsite with an account you already have
Sign in directly to Finalsite using login credentials already set up with one of the following providers, instead of creating and remembering a separate Finalsite password. Each of these connects an outside account into Finalsite.
| Provider | How it works | Setup Guide |
|---|---|---|
| Apple | Sign in to Finalsite using an Apple ID. | Apple SSO: Client-managed setup |
| Sign in to Finalsite using a Facebook account; most often used by portal users, such as parents. | Meta / Facebook SSO: Client-managed setup | |
| Google Workspace | Sign in to Finalsite using a Google Workspace account. | Google Workspace SSO: Client-managed setup |
| Microsoft (Entra ID, formerly Azure AD) | Sign in to Finalsite using a Microsoft work or school account. | Microsoft Entra ID (Azure AD) SSO: Client-managed setup |
| RapidIdentity | Sign in to Finalsite using a RapidIdentity account. | RapidIdentity SSO: Client-managed setup |
| Veracross | Sign in to Finalsite using a Veracross account. | Veracross SSO and integration: Client-managed setup |
Passing the other direction, from Finalsite out to another platform without signing in again there, works differently and is covered in the next section.
Access other platforms from Finalsite without signing in again
These connections work in the opposite direction from the identity providers above: someone already signed into Finalsite passes through to one of the platforms below without a second login there. The table summarizes each one; click a platform name to jump to its details.
| Platform | Type | What has to match or be set up first |
|---|---|---|
| Canvas | SAML | Username must match between systems; not a fit if users already sign into Canvas with Google or another method. |
| Catertrax | SAML | Users access CaterTrax exclusively through the Finalsite SSO link going forward. |
| CHQ | SSO | A shared datapoint between Finalsite and CHQ. |
| FACTS | Secure token URL | Nothing to set up in advance; accounts link automatically on first sign-in. Not supported if FACTS Enterprise is connected to the FACTS SIS. |
| Google SSO | Third-party IdP passthrough | Covers passing into Google Workspace apps after already being signed into Finalsite, configured on Google's side. |
| Magnus Health | SSO + data integration | The "Class Of" field populated for students, plus proper relationships in the client data. |
| MySchool | SAML | — |
| Naviance | Student SSO only | Finalsite ImportID recommended; no parent or faculty option. |
| PCR | SSO | Requires the PCR data integration already in place. |
| PeopleGrove | SAML | — |
| Pick a Time | SSO | pickAtime userID must match a Finalsite ImportID. |
| PowerSchool Learning | Cloud IdP (miniOrange) | A unique identifier (usually ImportID) or matching usernames between systems. |
| PTC Wizard | SSO | — |
| Rediker Plus Portals | SSO | Requires the Rediker data integration; dual-role faculty/parents need the same email on both Rediker accounts. |
| Schoology | SSO | An ImportID or username value matching between Finalsite and Schoology. |
| Senior Systems | SSO | Requires the Senior Systems data integration and authentication mechanism. |
| The School Volunteer | SSO | Existing users get matched to their Finalsite IDs first to avoid duplicates; new users are created automatically on first sign-in. |
| Veracross | SSO | Requires the Veracross data integration and authentication mechanism. |
| Vidigami | SSO | Primary email must match between systems (case-sensitive). |
| Zendesk | SSO | — |
Canvas
Finalsite offers a SAML based SSO with Canvas. With this SSO, Finalsite becomes the Identity Provider for Canvas, so if users are currently logging in to Canvas with Google or by other means, this may not be the right option. Your deployment expert will provide instructions for setting up the SSO on the Canvas side. This SSO is contingent upon the username matching between the two systems.
Catertrax
Finalsite now offers a single sign-on option with CaterTrax. This SSO option uses SAML and requires that the client understand that users will now access CaterTrax exclusively through Finalsite's SSO link.
This SSO can be configured with a default landing page and a default log out page, as well as provisioning options set in CaterTrax.
CHQ
Finalsite offers an SSO with CHQ. There will need to be a shared datapoint between Finalsite and CHQ for this to work as expected.
FACTS
Finalsite offers a single sign on for parents with FACTS Management. The SSO between the two systems uses a secure URL, containing an encrypted token, that is generated for each user in turn. There are a number of different scenarios for the SSO workflow, depending on whether a parent has an account in FACTS and has previously used the SSO from Finalsite.
Important Note
Please be advised that if you have connected FACTS Enterprise with the FACTS SIS, we are unable to support this SSO from Finalsite.
- Parents with an existing FACTS account: When a parent first clicks the FACTS SSO link in Finalsite, they are transferred to FACTS. They may then enter their FACTS login credentials or register for a new account. If they authenticate successfully, their FACTS account is linked to their Finalsite account and, for all subsequent single sign-ons from Finalsite, they will be taken directly to the FACTS dashboard.Â
-
Parents without a FACTS account: A parent who does not have an account in FACTS will not be able to link up their FACTS account to their Finalsite account by logging in to FACTS. Instead, alongside the option to enter FACTS credentials (which they do not have), they have the option of creating a new account.
- The new account form will be pre-populated with the following data provided by Finalsite:
- First name
- Last name
- Primary email address
- The new account form will be pre-populated with the following data provided by Finalsite:
Once the account has been created in FACTS, it is linked to their Finalsite account and, for all subsequent single sign-ons from Finalsite, the parent will be taken directly to the FACTS dashboard.
Google SSOÂ
Users can sign in once to access all of their Google Workspace and enterprise cloud applications. Learn more about SSO in the Google Workplace Admin Help Article, "Set up SSO via a third party identity provider." Once SSO is enabled, users can:Â
- Sign in to their third party identity provider (IdP).
- Access Google apps without a second sign-in.
- Set up additional two-step verification.Â
This entry covers passing from Finalsite into other Google apps after already being signed into Finalsite. For signing into Finalsite itself with a Google Workspace account, see Sign in to Finalsite with an account you already have.
Magnus Health
Magnus Health is health software for K-12 Schools. Our offering is an SSO and an integration. We push student and parent data into Magnus for the client, from their Finalsite data, and receive a token that we can then use to allow parents to pass from Finalsite into Magnus without a second login.
Datapoints that can be pushed are listed below:Â Â
| Parent datapoints | Student datapoints |
|---|---|
|
Address Phone Work phone Mobile phone First name Last name Username |
First name Last name Phone number Birthdate Username Address |
Please note that this requires that a school utilize the "Class Of" field for their students as well as proper relationships in the client data.
MySchool
Finalsite offers a SAML based SSO with MySchool.
Naviance
Finalsite supports a Student SSO into Naviance. Naviance does not offer Parent or Faculty options. It is recommended that the client setup the accounts in Naviance utilizing the Finalsite ImportID. We can support a different datapoint, but it may complicate configuration.
PCR
Finalsite offers a Single Sign on into PCR for clients who are also using the PCR data integration.
People Grove
Finalsite offers a SAML SSO option with PeopleGrove to facilitate a passthrough from Finalsite into PeopleGrove.
Pick a Time
Finalsite offers an SSO with Pick a Timethat will allow users to pass from Finalsite into Pick a Time without being challenged for credentials. Your deployment expert will work with you to ensure that the data is setup properly for the SSO to function. This requires pickAtime userID to match a Finalsite importID.
Powerschool Learning
Finalsite offers a way to enable SSO to PS Learning via the SSO option called miniOrange IdP which is a cloud based integration.Â
This implementation requires that we either have a unique identifier in Finalsite (most commonly the ImportID) that matches a value set to the corresponding user in Powerschool OR that we have matching usernames.
PTC Wizard
Finalsite offers an SSO with PTC Wizard. This can be used to pass from FS to PTC Wizard without a second challenge for credentials. Finalsite Support can help you with the data work to ensure the SSO works as expected.
Rediker Plus Portals
Finalsite offers Student, Parent, and Faculty SSO into Rediker's PlusPortals for clients also using the Rediker data integration. Note that this requires dual role faculty/parents to have the same email on both accounts in Rediker to see parent and faculty info in a single SSO passthrough.
Schoology
Finalsite offers an SSO with Schoology. In order for this to function, either an ImportID value or a username value will need to match in Finalsite and Schoology. Your deployment expert will work with you on configuring this SSO on the Schoology side.
Senior Systems
The SSO with Senior Systems MyBackpack is contingent upon using the Senior Systems Data Integration and the Senior Systems Authentication mechanism. Once configured, it allows parents, students, and faculty to pass from the Finalsite portal into MyBackpack without a second challenge for credentials.
The School Volunteer
Finalsite offers an SSO with The School Volunteer. If users already exist in The School Volunteer prior to implementing the SSO, your deployment expert will work with you to add the appropriate Finalsite IDs to those users in TSV to ensure they are not duplicated. New users will be created in TSV when using the SSO the first time.
There are a few options for "deeplinks" with this SSO that will land users in specific sections of The School Volunteer including: "View My Schedule", "Nominate Leadership", and "View Committee".
Veracross
The SSO offered between Finalsite and Veracross requires using the Veracross Data Integration and Authentication mechanism. Once configured, users will be able to pass from the Finalsite Portal into a variety of locations in Veracross.
This entry covers passing from the Finalsite Portal into Veracross after already being signed into Finalsite. For signing into Finalsite itself with a Veracross account, see Sign in to Finalsite with an account you already have.
Vidigami
Finalsite offers an SSO option for Vidigami. It's simple to setup and allows for passing from Finalsite into Vidigami without a second set of credentials. It is important that the primary email in Finalsite match the email in Vidigami (case-sensitive)
Zendesk
Finalsite now offers a single sign-on with Zendesk. This will allow users to pass from a Finalsite portal into Zendesk without a second request for authentication.
Comments
Please Sign in to leave a comment if you don't see the comment box below.