What Do You Need?
| I am a SIRAS user trying to sign in with SSO Use your district's published SIRAS SSO application or login path. Get help when the district SSO path is not working. | I am district IT / an administrator configuring SSO Create the SAML application, use the correct SIRAS URLs, provide metadata/certificate information, and test in Training. |
What SSO Does
With SSO, the district's Identity Provider (IdP) controls authentication. If the district requires Multi-Factor Authentication (MFA), that same protection applies when staff access SIRAS through the district SSO application.
SSO also reduces the need for staff to manage a separate SIRAS password because the district account is used for authentication.
For SIRAS Users: Sign In Through Your District SSO
SIRAS does not display a universal “Login with SSO” button on the standard SIRAS homepage. Your district should publish the SIRAS SSO application through its normal user portal or application launcher.
Examples include:
- Google App Launcher / Google “waffle”;
- Microsoft My Apps;
- OneLogin; or
- another district-managed SSO portal or SIRAS launch link.
For normal Production/Training URLs, bookmarks, first-time account setup, and standard password login help, see Logging Into SIRAS.
If Your District Uses SSO and You Cannot Sign In
If you know your district uses SSO and the normal district login path is not working, contact [email protected].
Please include:
- your district/LEA name;
- your SIRAS username, if known;
- whether you are trying to reach Production or Training;
- how you normally launch SIRAS (for example Google, Microsoft My Apps, or OneLogin); and
- a brief description of what happens when you try to sign in.
District IT / Administrator: SSO Configuration Guide
In your Identity Provider (IdP) admin console, create a custom SAML application for SIRAS.
| Identity Provider | Typical setup path |
|---|---|
| Google Workspace | Apps → Web and mobile apps → Add custom SAML app |
| Microsoft Entra (Azure AD) | Enterprise applications → New application → Create your own application |
| OneLogin | Applications → Add App → SAML Custom Connector (or equivalent) |
Required SIRAS URLs
Substitute the appropriate {server URL} for your SELPA/district.
| Setting | Value |
|---|---|
| EntityID | https://{server URL}/sso/metadata.jsf |
| Login URL / ACS URL / Recipient | https://{server URL}/sso/acs.jsf |
Server URLs by Region
| Region | Training | Production |
|---|---|---|
| VCOE SIRAS | https://sirastraining.vcoe.org | https://siras.vcoe.org |
| Kern SIRAS | https://training.siras-kern.org | https://siras-kern.org |
| Main — all other SELPAs | https://training.sirassystems.org | https://sirassystems.org |
Leave other SAML parameters such as Sign-On URL or Logout URL blank or at their defaults unless your IdP specifically requires them.
Publish the SIRAS Application to Users
After the SSO application is configured, publish or assign it through the district's normal IdP user portal or dashboard. Users should launch SIRAS from that published application rather than looking for an SSO button on the standard SIRAS homepage.
Provide IdP Metadata to SIRAS
Share the following values from your Identity Provider with the SIRAS team, or configure them in SIRAS if you have access:
- Entity ID URL
- Single Sign-On (SSO) Service URL
- X.509 Certificate — Base64-encoded; commonly a
.pemor Base64 certificate export
Examples
| Provider | Entity ID example | SSO Service URL example |
|---|---|---|
https://accounts.google.com/o/saml2?idpid=abc1234 |
https://accounts.google.com/o/saml2/idp?idpid=abc1234 |
|
| Microsoft | https://sts.windows.net/abc1234/ |
https://login.microsoftonline.com/abc1234/saml2 |
Optional: Restrict Password Logins
After SSO is enabled, a district may choose to disable password-based SIRAS logins. If that option is used, users must authenticate through the district SSO method.
SIRAS Account & Email Requirements
- Each SIRAS user's email must match the email used by that person's SSO account.
- User email addresses must belong to the domain configured for the district's SSO.
- The SIRAS user account must still exist and be available to the user; SSO authenticates the user but does not replace the underlying SIRAS account.
Microsoft Entra / Microsoft 365 Notes
- Use Properties → User Access URL for the login link. It typically begins with
https://launcher.myapps.microsoft.com/. - Provide SIRAS with the Certificate (Base64).
- Leave Sign-On URL blank unless the tenant configuration specifically requires it.
- Configure the required Entity ID and Reply / ACS URL.
- Ensure an email attribute/claim mapping exists, for example
emailaddress → user.mail. - Assign users or groups to the SIRAS application as required by the district tenant policies.
Additional SSO Behavior
- When SSO is used, the normal SIRAS password-reset requirement is not evaluated in the same way as password login.
- A SIRAS account may still be blocked by account policy after an extended period without login.
- A successful SSO login updates the user's Last Login Date in SIRAS.
- Logging out of the district Identity Provider does not automatically log the user out of SIRAS. Normal SIRAS logout behavior and session timeouts still apply.
Contact [email protected] and include the district/LEA name, Identity Provider, and whether the issue is occurring in Training or Production.
Related Help
- Logging Into SIRAS — Production/Training URLs, normal login, bookmarking, password help, and first-time account setup.

