SAML SSO
Azure AD, Okta, Google Workspace. Domain-based auto-detection.
Students and staff sign in with district credentials. Ember supports SAML 2.0 with Azure AD, Okta, and Google — plus domain-based routing so users land on the right IdP automatically.
At a glance
The challenge
Too many passwords
Students forget LMS passwords; help desks drown in resets.
How Ember helps
One district login
SSO with existing IdP — MFA enforced at the district level.
Real scenarios
When you'll use it
Concrete moments in the school week — not abstract features.
First day of school
Students sign in with existing district credentials — no separate Ember password to forget.
Password reset reduction
Help desk tickets drop when SSO is enabled district-wide.
Staff onboarding
New teachers are provisioned automatically on their first successful IdP login.
Capabilities
Everything included
Major IdP support
Azure AD, Okta, Google Workspace, and custom SAML.
Domain detection
@district.k12.us routes to the correct IdP automatically.
Role mapping
SIS attributes map to teacher, student, parent, admin roles.
Session policies
Configurable timeout and concurrent session limits.
Just-in-time provisioning
Accounts are created automatically on first successful SSO login.
Multi-domain routing
Route different email domains to different IdPs from the same SSO configuration.
How it works
Up and running in three steps
Upload SAML metadata
IT configures IdP with Ember SP endpoints.
Map attributes
Email, role, and school fields map to Ember profiles.
Users sign in once
District credentials work everywhere.
FAQ
Common questions
Full SP support with metadata by URL, uploaded XML, or manual entry for any compliant IdP.
Works great with
Features commonly used together.