Integrated database password management and authentication failovers

This article covers password caching and failover authentication in SIS-integrated Finalsite sites, including testing the SIS connection and switching login to the Finalsite database.

💡 Quick answers

  • How do I enable password caching for failover authentication? In Integrated Services Manager, open the Authentication tab, click the school's SIS name, and confirm Enable Cached Passwords is checked.
  • Why isn't failover login working for a user? Users must have logged into the site at least once for their credentials to be cached; anyone who never logged in cannot use the failover.
  • How do I test whether the SIS connection is actually the problem? In Integrated Services Manager's Authentication tab, click the SIS name, then use Test Authentication with a valid username and password; an authentication failure confirms a connection issue.
  • How do I switch users to log in through Finalsite instead of the SIS? On the Authentication tab, select the failing authentication, open Role Settings, and click the checkbox next to each role to route those users through Finalsite.
  • How do I switch back to SIS authentication once it's fixed? Return to the same Role Settings screen and click the black X, which turns to a green checkmark, routing users back through SIS authentication.
  • Why would only some users be unable to log in, not all? If only a few accounts fail while the SIS connection is otherwise working, the issue is likely with those specific accounts rather than the network connection itself.

In this article


How password caching and failover authentication work

Some Finalsite installations are "integrated" with Student Information Systems (SIS) to manage user data and login credentials, streamlining access to school resources. This integration allows Composer admins to maintain a single database, giving users one account for all online resources. The connection between the website and the SIS enables remote authentication, where user credentials are verified against the SIS database. If that connection fails, Finalsite can use a failover procedure that relies on a cached copy of credentials to keep access working.

Configuring the remote authentication failover process involves two parts: setting up password caching, and establishing the method of authentication for each constituent role. Password caching means the Finalsite installation maintains a separate record, or "cache," of user login information. The method of authentication determines which record the website checks when authenticating a site user: the SIS record or the website record.

When this article applies

This procedure applies to sites with an SIS integration that are experiencing authentication failures tied to the SIS connection. It does not cover isolated password resets or login issues unrelated to the SIS integration.

Enable password caching

To set up the failover functionality, password caching must be enabled in the Authentication settings in Integrated Services Manager.

To check whether password caching is already configured, open Integrated Services Manager and click the Authentication tab at the top of the window.

The available methods of authentication appear in the left-hand menu. One is "finalsite"; the other or others are the school's SIS (in this example, LDAP; other examples might include SeniorSystems, Veracross, PCR, or another provider).

Click the name of the school's SIS (not "finalsite") to display its settings, and confirm the checkbox marked Enable Cached Passwords is selected.

If the checkbox is not selected, contact Finalsite Support to enable it. With this checkbox enabled, the Finalsite installation maintains a separate record of user credentials that can be used if the network connection to the SIS database becomes unavailable. Password caching is optional, but it is the only way Finalsite can ensure continued login access if a connection problem occurs.

⚠️ Important Note

Users must log into the website at least once before the failover can work for them. Anyone who has never logged in with their credentials cannot use the failover if the network connection to the SIS database is disrupted.

Resolve SIS login issues with failover authentication

If users are having trouble logging in through the SIS authentication process, it may be necessary to enable the failover and authenticate against the cached passwords instead.

 Real-world scenarios

Common situations where failover authentication comes into play:

  • The school's SIS connection goes down during the morning login rush. Support tests the connection, confirms an authentication failure, and switches the affected roles to failover so students and staff can keep logging in while the connection is restored.
  • Only a handful of users report login failures while everyone else logs in normally. Testing the SIS connection succeeds, pointing to an issue with those specific SIS accounts rather than the integration itself.

Test the SIS connection

Before switching from SIS authentication to Finalsite authentication, test the network connection to the SIS to confirm the problem actually lies with that connection.

  • Step 1: Open Integrated Services Manager and select the Authentication tab.
  • Step 2: Click the name of the school's integration database (not "finalsite").
  • Step 3: Select Test Authentication, then enter a valid username and password in the fields.

An authentication failure confirms an issue with the connection to the SIS database. Continue to Enable failover authentication below.

⚠️ Important Note

Test multiple user credentials to rule out a problem with one specific account rather than the connection itself. When the network connection to the SIS is down, all users authenticated through it typically cannot log in. If only a few users cannot log in, the issue is most likely with their accounts in the SIS rather than the network connection.

Enable failover authentication

After testing the SIS authentication and confirming a problem, turn off that authentication and turn on the finalsite authentication.

  • Step 1: On the Authentication tab, select the authentication that is failing.
  • Step 2: Select Role Settings in the upper-right corner.

    A list of roles that use that authentication appears.

  • Step 3: Click the green checkbox next to the role to disable the authentication and route those users through Finalsite.

Switch back to SIS authentication

Once the SIS issue is resolved, return to the same Role Settings screen and click the black X next to the role, which turns to a green checkmark. This routes those users back through the SIS authentication.

Was this article helpful?
2 out of 2 found this helpful

Comments

0 comments

Please Sign in to leave a comment if you don't see the comment box below.