# SAML-based Single Sign-On (SSO) Authentication

# **SAML-based Single Sign-On Feature Overview**

The **SAML-based Single Sign-On** (SAML SSO) authentication is supported in LearningSpace.   
LearningSpace uses a **Shibboleth Service Provider (Shibboleth SP)** software to accomplish this. 

Elevate Healthcare takes care of the Shibboleth LS server-side configuration. 


:::info
Once SAML SSO is enabled, and a LearningSpace user would like to **log into** LS, they will not be able to do that via the [LS login page](https://kb.learningspace.elevatehealth.net/s/ess-hs/doc/login-and-dashboard-PPgObXJSm0). When the user enters **the URL of LearningSpace**, they will be **redirected** by the **Shibboleth SP** (that runs on the main application server) to the **Identity Provider** (IdP) login surface.

:::

* On the IdP login page, the user enters their **credentials** (login name and password).
* After successfully completing the authentication, the IdP **redirects** the user to LearningSpace.   
  During this phase, the IdP sends a unique attribute – in a previously agreed format – necessary for identifying the user in question (e.g., *eduPersonPrincipalName,* i.e., eppn or e*duPersonTargetedID,* *eduPersonAffiliation,* etc.).
* In case this data is associated (‘mapped’) with a user’s **UCID or email** attribute in the LS database, **LearningSpace will validate** the session, and the user can log in.


:::tip
A so-called ‘mixed login’ can be enabled to keep the original LS login functionality (e.g., for users with no corporate/institutional account but only a local LS account).   
This feature allows the users to **access their LearningSpace system directly with their** login credentials (stored locally in the LearningSpace database), by simply adding **‘/email’** at the end of the URL.

:::


:::success
Please reach out to LearningSpace Support to have ‘mixed login’ enabled on your system!

:::

  
The following types of IdPs have been **successfully integrated** with LearningSpace so far:

* Shibboleth (version 2 and version 3)
* OKTA
* ADFS
* AZURE AD 

# Requirements for setting up SAML SSO authentication

LearningSpace support requires the following:


1. **Type and version of the customer’s IdP server** (i.e., Shibboleth, ADFS, etc.) for an easier configuration method;
2. The **unique attribute type and format** that is used for user mapping and identification
3. The IdP server’s **metadata.xml file** or URL (*idp-federation-metadata*);
4. **A test user** created on the IdP side with access to LearningSpace application. With the help of such a test user, support engineers can test the SAML SSO authentication.   
   In order to be able to perform this test, the unique attribute’s value of the test user must be shared with the support (which will be added to the test user’s **UCID field** in LearningSpace).


:::success
*IMPORTANT REQUIREMENT:* The affected LearningSpace instance must have **a valid SSL certificate.**

:::

# **Installation and setup**


1. LS Support team installs the Shibboleth SP on the **main application server**.
2. LS Support team generates the **SP metadata** (*sp-metadata.xml* file), and sends it to the customer. 
3. The SP metadata needs to be **imported __by the customer__ on the IdP side** (it is necessary for identifying the Shibboleth SP).

| ### LearningSpace SP metadata and endpoints |     |
|-----------------------------------------|-----|
| Identifier URL for the application.     | https://<ls_url>/shibboleth |
| Reply (Assertion) URL for the application. | https://<ls_url>/Shibboleth.sso/SAML2/POST |
| Sign on URL for the application.        | https://<ls_url>/ |
| Relay state URL for the application.    | https://<ls_url>/ |
| Sign out URL for the application.       | https://<ls_url>/Shibboleth.sso/Logout |



:::success
Once the above steps are completed, the SAML SSO authentication **can be activated and used**.

:::

# Optional configurations

* **Global logout**: To be able to configure that, the local IT must provide a **global logout URL**.
* **Mixed Login:**  The site is accessed via the /email in the URL. (Example: https://<domain>/email or https://<ls_url>/email  )

**JIT (Just in Time Provisioning):** To be able to create (or update) users in LS, the following claims containing the **additional attributes** are required:

*  first name
*  last name
*  email address 
*  unique ID (it will be **mapped to a hidden GUID** and not UCID)
*  group membership/role value (LS will assign the new user to a group and give privileges/roles to the user) 

  
:::tip
  ***Example:*** a new user who has a "Learner" value as this attribute will be added to the "SSO Learners" group and the Learner role assigned.

  :::

# Error messages



1. **Value missing in the database**  
   This error occurs if a user **can log in on the client-side IdP** and the IdP sends the user's unique ID to LearningSpace, but **LS cannot find the user** based on that. 

   
   ![](https://outline-production-attachments.s3-accelerate.amazonaws.com/uploads/03fa1014-cf0e-4191-ba80-50d24eef65d4/223e6943-fae9-4a69-9832-dd4415b441a8/page%20cannot%20be%20displayed_warning.png?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Content-Sha256=UNSIGNED-PAYLOAD&X-Amz-Credential=AKIA4EOUDTOVUICLPZ4P%2F20260909%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20260909T151500Z&X-Amz-Expires=86400&X-Amz-Signature=4698e3b6ab0f6d060eeb9c8b92f383f93e8de9e4bb050e5b661e505f50aa19c6&X-Amz-SignedHeaders=host&x-amz-checksum-mode=ENABLED&x-id=GetObject " =556x123")

   
   The reason could be that the **value is not present in any of the user fields** (email or UCID) in LS, and therefore, the user cannot be identified.
2. **Value entered incorrectly (Case-sensitivity)**

***NOTE:***  The attribute's value sent to the database is CASE SENSITIVE. If entered incorrectly during SSO login, users will be directed back to the Dashboard (when trying to access Recording or Reports, etc.), and will get the following error:


 ![](https://outline-production-attachments.s3-accelerate.amazonaws.com/uploads/03fa1014-cf0e-4191-ba80-50d24eef65d4/04e9581a-c84f-40f0-91c9-487baa2e49b4/error%20getting%20activity%20list.png?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Content-Sha256=UNSIGNED-PAYLOAD&X-Amz-Credential=AKIA4EOUDTOVUICLPZ4P%2F20260909%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20260909T151500Z&X-Amz-Expires=86400&X-Amz-Signature=7f16925d99677f53d0c7a0f965b1443d5c3e7dbe603f854100605034113cc7c0&X-Amz-SignedHeaders=host&x-amz-checksum-mode=ENABLED&x-id=GetObject " =385x163")



:::info
If you have any questions regarding the above information, don't hesitate [to get in touch with LearningSpace Support](https://kb.learningspace.elevatehealth.net/doc/customer-aftercare-one-pager-GOIZYTEgud#h-🟢-contact-details)!

:::

---

**Documents**

- [User Guide](https://kb.learningspace.elevatehealth.net/s/ess-hs/doc/user-guide-QPZfKJ0BV1)
- [FAQ](https://kb.learningspace.elevatehealth.net/s/ess-hs/doc/faq-AZnS7tDFgM)
- [Release Notes](https://kb.learningspace.elevatehealth.net/s/ess-hs/doc/release-notes-fqaGSPScxH)
- [iPad support - Technical information](https://kb.learningspace.elevatehealth.net/s/ess-hs/doc/ipad-support-technical-information-iHec00YAzm)
- [Customer Aftercare One-Pager](https://kb.learningspace.elevatehealth.net/s/ess-hs/doc/customer-aftercare-one-pager-GOIZYTEgud)
- [Preventing Copy-Paste in LearningSpace](https://kb.learningspace.elevatehealth.net/s/ess-hs/doc/preventing-copy-paste-in-learningspace-uEubHwXVD2)