Configuring SAML-Based SSO with PowerSchool

RapidIdentity Platform Documentation

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

PowerSchool supports a SAML-based single sign-on (SSO) service for its web-based application that you can configure in your RapidIdentity portal. These configuration settings are an example and may vary for individual configurations.

Requirements
  • PowerSchool administrator credentials
  • Access to your RapidIdentity administrator portal
  1. Navigate to your RapidIdentity administrator portal.
  2. From the module selector, choose Configuration.
  3. Select Security > Identity Providers > Federation Partners.
  4. Click Add Federation Partner > SAML 2.0, then click Create SAML Relying Party.
  5. In the General section, add a name and the metadata from your PowerSchool administrator portal.
  6. In the SSO Settings section, configure the following settings:
    1. Enable the Include SAML2 Attribute Statement setting.
    2. Sign SAML2 SSO Response: Never or Conditional
    3. Sign SAML2 SSO Assertions: Never or Conditional
    4. Encrypt SAML2 SSO Assertions: Never
    5. Encrypt SAML2 SSO Name IDs: Never
    6. Signature Algorithm: SHA-256
  7. In the Attribute Mapping section, click Add New Attribute + and configure the following attributes:

    The Name ID is authenticationid, configured as extensionAttribute10 with NameID format urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified.

    LDAPSAMLFriendly NameName Format Value
    extensionAttribute10urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified
    extensionAttribute10/idautoPersonAppRoles3authenticationidauthenticationidurn:oasis:names:tc:SAML:2.0:attrname-format:unspecified
    Note:

    The extensionAttribute10/idautoPersonAppRoles3 value may vary in your environment.

  8. Click Create, then click Save.

RapidIdentity and PowerSchool are now integrated, allowing users to authenticate to PowerSchool with their RapidIdentity credentials.