You are using an unsupported browser. Please update your browser to the latest version on or before July 31, 2020.
close
You are viewing the article in preview mode. It is not live at the moment.
Home > Support Center > SIS Integration > Single Sign On (SSO) with SIRAS
Single Sign On (SSO) with SIRAS
print icon
Single Sign-On (SSO) lets staff open SIRAS using the same district-managed account they already use for systems such as Google Workspace, Microsoft 365 / Entra, or OneLogin. This page has two paths: one for staff who need to sign in and one for district IT / administrators configuring SSO.

What Do You Need?

What SSO Does

With SSO, the district's Identity Provider (IdP) controls authentication. If the district requires Multi-Factor Authentication (MFA), that same protection applies when staff access SIRAS through the district SSO application.

SSO also reduces the need for staff to manage a separate SIRAS password because the district account is used for authentication.

Key point: The district controls the login process through its own Identity Provider, while SIRAS recognizes the authenticated user and opens the matching SIRAS account.

For SIRAS Users: Sign In Through Your District SSO

SIRAS does not display a universal “Login with SSO” button on the standard SIRAS homepage. Your district should publish the SIRAS SSO application through its normal user portal or application launcher.

Examples include:

  • Google App Launcher / Google “waffle”;
  • Microsoft My Apps;
  • OneLogin; or
  • another district-managed SSO portal or SIRAS launch link.
If your district normally uses SSO, launch SIRAS the way your district has instructed you to. Do not assume the standard SIRAS username/password screen is the correct login path for an SSO-only district.

For normal Production/Training URLs, bookmarks, first-time account setup, and standard password login help, see Logging Into SIRAS.

If Your District Uses SSO and You Cannot Sign In

If you know your district uses SSO and the normal district login path is not working, contact [email protected].

Please include:

  • your district/LEA name;
  • your SIRAS username, if known;
  • whether you are trying to reach Production or Training;
  • how you normally launch SIRAS (for example Google, Microsoft My Apps, or OneLogin); and
  • a brief description of what happens when you try to sign in.
A standard SIRAS password reset may not solve an SSO login problem. Some districts require users to enter through the district SSO method rather than the normal SIRAS password-login path.

District IT / Administrator: SSO Configuration Guide

In your Identity Provider (IdP) admin console, create a custom SAML application for SIRAS.

Identity ProviderTypical setup path
Google WorkspaceApps → Web and mobile apps → Add custom SAML app
Microsoft Entra (Azure AD)Enterprise applications → New application → Create your own application
OneLoginApplications → Add App → SAML Custom Connector (or equivalent)
Test in Training first. Start with the district's Training SIRAS URL. After validation, update the application to use the Production SIRAS URL.

Required SIRAS URLs

Substitute the appropriate {server URL} for your SELPA/district.

SettingValue
EntityIDhttps://{server URL}/sso/metadata.jsf
Login URL / ACS URL / Recipienthttps://{server URL}/sso/acs.jsf

Server URLs by Region

RegionTrainingProduction
VCOE SIRAShttps://sirastraining.vcoe.orghttps://siras.vcoe.org
Kern SIRAShttps://training.siras-kern.orghttps://siras-kern.org
Main — all other SELPAshttps://training.sirassystems.orghttps://sirassystems.org

Leave other SAML parameters such as Sign-On URL or Logout URL blank or at their defaults unless your IdP specifically requires them.

Publish the SIRAS Application to Users

After the SSO application is configured, publish or assign it through the district's normal IdP user portal or dashboard. Users should launch SIRAS from that published application rather than looking for an SSO button on the standard SIRAS homepage.

Provide IdP Metadata to SIRAS

Share the following values from your Identity Provider with the SIRAS team, or configure them in SIRAS if you have access:

  • Entity ID URL
  • Single Sign-On (SSO) Service URL
  • X.509 Certificate — Base64-encoded; commonly a .pem or Base64 certificate export

Examples

ProviderEntity ID exampleSSO Service URL example
Google https://accounts.google.com/o/saml2?idpid=abc1234 https://accounts.google.com/o/saml2/idp?idpid=abc1234
Microsoft https://sts.windows.net/abc1234/ https://login.microsoftonline.com/abc1234/saml2

Optional: Restrict Password Logins

After SSO is enabled, a district may choose to disable password-based SIRAS logins. If that option is used, users must authenticate through the district SSO method.

Before restricting password logins: confirm that the SSO path has been tested successfully and that staff know how to launch SIRAS through the district Identity Provider.

SIRAS Account & Email Requirements

  • Each SIRAS user's email must match the email used by that person's SSO account.
  • User email addresses must belong to the domain configured for the district's SSO.
  • The SIRAS user account must still exist and be available to the user; SSO authenticates the user but does not replace the underlying SIRAS account.

Microsoft Entra / Microsoft 365 Notes

  • Use Properties → User Access URL for the login link. It typically begins with https://launcher.myapps.microsoft.com/.
  • Provide SIRAS with the Certificate (Base64).
  • Leave Sign-On URL blank unless the tenant configuration specifically requires it.
  • Configure the required Entity ID and Reply / ACS URL.
  • Ensure an email attribute/claim mapping exists, for example emailaddress → user.mail.
  • Assign users or groups to the SIRAS application as required by the district tenant policies.

Additional SSO Behavior

  • When SSO is used, the normal SIRAS password-reset requirement is not evaluated in the same way as password login.
  • A SIRAS account may still be blocked by account policy after an extended period without login.
  • A successful SSO login updates the user's Last Login Date in SIRAS.
  • Logging out of the district Identity Provider does not automatically log the user out of SIRAS. Normal SIRAS logout behavior and session timeouts still apply.
Need help configuring or testing SSO?
Contact [email protected] and include the district/LEA name, Identity Provider, and whether the issue is occurring in Training or Production.

Related Help

  • Logging Into SIRAS — Production/Training URLs, normal login, bookmarking, password help, and first-time account setup.

Back to top

scroll to top icon