PowerSchool supports a SAML-based single sign-on (SSO) service for its web-based
application that you can configure in your RapidIdentity portal. These
configuration settings are an example and may vary for individual
configurations.
Requirements
- PowerSchool administrator credentials
- Access to your RapidIdentity administrator portal
- Navigate to your RapidIdentity administrator portal.
- From the module selector, choose Configuration.
- Select .
- Click , then click Create SAML Relying Party.
- In the General section, add a name and the metadata from your PowerSchool
administrator portal.
- In the SSO Settings section, configure the following settings:
- Enable the Include SAML2 Attribute Statement setting.
- Sign SAML2 SSO Response: Never or
Conditional
- Sign SAML2 SSO Assertions: Never or
Conditional
- Encrypt SAML2 SSO Assertions: Never
- Encrypt SAML2 SSO Name IDs: Never
- Signature Algorithm: SHA-256
- In the Attribute Mapping section, click Add New Attribute
+ and configure the following attributes:
The Name ID is authenticationid, configured as
extensionAttribute10 with NameID format
urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified.
| LDAP | SAML | Friendly Name | Name Format Value |
|---|
extensionAttribute10 | | | urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified |
extensionAttribute10/idautoPersonAppRoles3 | authenticationid | authenticationid | urn:oasis:names:tc:SAML:2.0:attrname-format:unspecified |
Note:
The extensionAttribute10/idautoPersonAppRoles3 value
may vary in your environment.
- Click Create, then click
Save.
RapidIdentity and PowerSchool are now integrated, allowing users to authenticate to
PowerSchool with their RapidIdentity credentials.