Skip to main content

Greetings,

As you know once your CSMs and account executives hear that one client is accessing the LMS from another platform using SSO/SAML they want the same for every client.

 

Is there a way for multiple clients to use SAML/SSO without having all of them become Extended Enterprise clients?

 

Thanks for your time!

~B

@Bkatzman - the short answer is no. As far as I understand it? You can only apply a single SSO instance - not multiple ones - without Extended Enterprise. There may be a path with the custom services group to do it, but you can definitely not achieve it OOTB.


It’s not scalable but you can set up one of each type of supported SSO on a standard LMS instance. i.e. - one SAML, one LDAP, one OpenID etc.


We have done this for one client

 


@lrnlab and ​@nick.tosto - can I ask > Is it fair to say that the examples you are providing - those really aren’t SSO instances though? Those are different authentication approaches?


As far as I know, you can use both. It comes down to how you manage your users. For example you might want to use SAML for your internal employees and the OpenID for your external clients.  


Many identity providers support different protocols so the trick is that you can connect to multiple different identity providers by using different protocols.


I know exactly what you mean here, ​@Bkatzman . We have the same thing happening and we have quite a few Extended Enterprises that were set up just for that. You may want to have a look at a Customer Identity and Access Management (CIAM). We haven’t yet, but some solutions let’s you use the SSO of the client to identify through them. I unfortunately don’t have much more details about this one.

Let us know if you find a solution. 😊


Reply