# SAML-based Single Sign-On (SSO) Authentication

# **SAML-based Single Sign-On Feature Overview**

**SAML-based Single Sign-On** (SSO) is supported in LearningSpace.   
LearningSpace uses **Shibboleth Service Provider (Shibboleth SP)** software to accomplish this. 

Elevate Healthcare handles the Shibboleth LS server-side configuration. 


:::info
***NOTE:*** If SAML SSO authentication is enabled, the [***Easy SP/Learner services***](https://kb.learningspace.elevatehealth.net/s/ent-hs/doc/easy-login-dEbYOLvj5H) will be unavailable. 

:::

Once SAML SSO is enabled, a LearningSpace user will not be able to log in to LS via the [LS login page](https://kb.learningspace.elevatehealth.net/s/ent-hs/doc/login-and-dashboard-RUgPhfwowz). When the user enters **the LearningSpace** URL, the **Shibboleth SP** (which runs on the main application server) redirects them to the **Identity Provider** (IdP) login page.

* On the IdP login page, the user enters their **credentials** (login name and password).
* After successful authentication, the IdP **redirects** the user to LearningSpace.   
  During this phase, the IdP sends a unique attribute in a previously agreed-upon format that is necessary for identifying the user (e.g., *eduPersonPrincipalName* (eppn), e*duPersonTargetedID,* *eduPersonAffiliation,* etc.).
* In case this data is associated (‘mapped’) with a user’s **UCID or email** attribute in the LS database, **LearningSpace will validate** the session, and the user can log in.


:::tip
A so-called ‘mixed login’ can be enabled to keep the original LS login functionality (e.g., for users with no corporate/institutional account but only a local LS account).   
This feature allows users to **access their LearningSpace system directly using their** login credentials (stored locally in the LearningSpace database) by simply adding **‘/email’** to the URL.

:::


:::success
Please reach out to LearningSpace Support to have ‘mixed login’ enabled on your system!

:::

  
The following types of IdPs have been **successfully integrated** with LearningSpace so far:

* Shibboleth (version 2 and version 3)
* OKTA
* ADFS
* AZURE AD 
* Microsoft Entra ID

# Requirements for setting up SAML SSO authentication

LearningSpace support requires the following:


1. **Type and version of the customer’s IdP server** (i.e., Shibboleth, ADFS, etc.) for an easier configuration method;
2. The **unique attribute type and format** that is used for user mapping and identification
3. The IdP server’s **metadata.xml file** or URL (*idp-federation-metadata*);
4. **A test user** created on the IdP side with access to the LearningSpace application. With the help of such a test user, support engineers can test the SAML SSO authentication.   
   To perform this test, the unique attribute’s value for the test user must be shared with support (which will be added to the test user’s **UCID field** in LearningSpace).


:::success
*IMPORTANT REQUIREMENT:* The affected LearningSpace instance must have **a valid SSL certificate.**

:::

# **Installation and setup**


1. LS Support team installs the Shibboleth SP on the **main application server**.
2. LS Support team generates the **SP metadata** (*sp-metadata.xml* file), and sends it to the customer. 
3. The SP metadata needs to be **imported __by the customer__ on the IdP side** (it is required to identify the Shibboleth SP).

| ### LearningSpace SP metadata and endpoints |     |
|-----------------------------------------|-----|
| Identifier URL for the application.     | https://<ls_url>/shibboleth |
| Reply (Assertion) URL for the application. | https://<ls_url>/Shibboleth.sso/SAML2/POST |
| Sign on URL for the application.        | https://<ls_url>/ |
| Relay state URL for the application.    | https://<ls_url>/ |
| Sign out URL for the application.       | https://<ls_url>/Shibboleth.sso/Logout |



:::success
Once the above steps are completed, the SAML SSO authentication **can be activated and used**.

:::

# Optional configurations

* **Global logout**: To configure it, the local IT must provide a **global logout URL**.
* **Mixed Login:** The site is accessed via/email in the URL. (Example: https://<domain>/email or https://<ls_url>/email  )

**JIT (Just in Time Provisioning):** To be able to create (or update) users in LS, the following claims containing the **additional attributes** are required:

*  first name
*  last name
*  email address 
*  unique ID (it will be **mapped to a hidden GUID** and not UCID)
*  group membership/role value (LS will assign the new user to a group and give privileges/roles to the user) 

  
:::tip
  ***Example:*** a new user with a "Learner" value for this attribute will be added to the "SSO Learners" group and the Learner role assigned.

  :::

# Error messages


1. **Value missing in the database**  
   This error occurs when a user **can log in to the client-side IdP.** The IdP sends the user's unique ID to LearningSpace, but **LS cannot find the user** based on it. 

   ![](https://outline-production-attachments.s3-accelerate.amazonaws.com/uploads/03fa1014-cf0e-4191-ba80-50d24eef65d4/223e6943-fae9-4a69-9832-dd4415b441a8/page%20cannot%20be%20displayed_warning.png?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Content-Sha256=UNSIGNED-PAYLOAD&X-Amz-Credential=AKIA4EOUDTOVUICLPZ4P%2F20260909%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20260909T121500Z&X-Amz-Expires=86400&X-Amz-Signature=64aa38c7dcd1f5dda80db29c1e995789619cc1b61f471a2e3ca6c5d76078a72c&X-Amz-SignedHeaders=host&x-amz-checksum-mode=ENABLED&x-id=GetObject " =556x123")

   The reason could be that the **value is not present in any of the user fields** (email or UCID) in LS, and therefore, the user cannot be identified.  
2. **Value entered incorrectly (Case-sensitivity)**


 ![](https://outline-production-attachments.s3-accelerate.amazonaws.com/uploads/03fa1014-cf0e-4191-ba80-50d24eef65d4/04e9581a-c84f-40f0-91c9-487baa2e49b4/error%20getting%20activity%20list.png?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Content-Sha256=UNSIGNED-PAYLOAD&X-Amz-Credential=AKIA4EOUDTOVUICLPZ4P%2F20260909%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20260909T121500Z&X-Amz-Expires=86400&X-Amz-Signature=dbcac8ba8eda4176d473d483148260641ca78b369c8ba09e8a81907d0534132f&X-Amz-SignedHeaders=host&x-amz-checksum-mode=ENABLED&x-id=GetObject "right-50 =300x127")***NOTE:***  The attribute's value sent to the database is CASE SENSITIVE. If entered incorrectly during SSO login, users will be directed back to the Dashboard (when trying to access Recording or Reports, etc.), and will get the following error:




:::success
If you have any questions regarding the above information, don't hesitate [to get in touch with LearningSpace Support](https://kb.learningspace.elevatehealth.net/s/ent-hs/doc/customer-aftercare-one-pager-GBWMe1BcfS#h-🔵contact-details)!

:::

---

**Documents**

- [User Guide](https://kb.learningspace.elevatehealth.net/s/ent-hs/doc/user-guide-WPv4VxhtWB)
- [FAQ](https://kb.learningspace.elevatehealth.net/s/ent-hs/doc/faq-YoxOQOjvnY)
- [Training Videos](https://kb.learningspace.elevatehealth.net/s/ent-hs/doc/training-videos-D2ycsEwqPt)
- [Module Introduction Videos](https://kb.learningspace.elevatehealth.net/s/ent-hs/doc/module-introduction-videos-I6OQ6H7SUT)
- [Release Notes](https://kb.learningspace.elevatehealth.net/s/ent-hs/doc/release-notes-BcFFMsc0RV)
- [Distance Learning with LearningSpace](https://kb.learningspace.elevatehealth.net/s/ent-hs/doc/distance-learning-with-learningspace-eAfwW23Hxg)
- [Preventing Copy-Paste in LearningSpace](https://kb.learningspace.elevatehealth.net/s/ent-hs/doc/preventing-copy-paste-in-learningspace-sPD0IIUuk0)
- [Important Technical Notification Regarding Adobe Flash Player](https://kb.learningspace.elevatehealth.net/s/ent-hs/doc/important-technical-notification-regarding-adobe-flash-player-eQtMLwLmTJ)
- [iPad support - Technical information](https://kb.learningspace.elevatehealth.net/s/ent-hs/doc/ipad-support-technical-information-dLmeFvKofC)
- [TeamViewer Link](https://kb.learningspace.elevatehealth.net/s/ent-hs/doc/teamviewer-link-QyKZBMqUT9)
- [YouTube videos about LearningSpace](https://kb.learningspace.elevatehealth.net/s/ent-hs/doc/youtube-videos-about-learningspace-TMb3zdc0LC)
- [Customer Aftercare One-Pager](https://kb.learningspace.elevatehealth.net/s/ent-hs/doc/customer-aftercare-one-pager-GBWMe1BcfS)
- [Case Studies](https://kb.learningspace.elevatehealth.net/s/ent-hs/doc/case-studies-VcAbFqXSz7)