Single Sign-On (SSO)
Single Sign-On (SSO) lets a user log in once with a single set of credentials and access multiple connected applications without signing in again. In schools it can let staff use one account across the SIS, LMS and email, improving convenience and security. It reduces password fatigue and simplifies access management for administrators.
A login method letting users access multiple applications with one set of credentials.
Why it matters
In a school the real problem SSO solves is not password fatigue, it is leavers. A teacher who resigns mid-session typically holds separate logins for the student system, the exam module, email and the learning platform, and one of them quietly stays live. Deprovisioning usually falls on a single IT coordinator with no central list of accounts.
In practice
- One identity provider — in schools most often Google Workspace or Microsoft Entra ID — sits in front of every application, connected using SAML or OpenID Connect.
- Connected applications never see the password; they accept a signed assertion that the identity provider has already authenticated the user.
- Disabling the account at the identity provider ends access to every connected system at once, which is the main day-to-day operational gain.
- Roles and permissions normally still live inside each application: SSO answers 'who is this?', not 'what may they do?'.
- Parents and students often sit outside institutional SSO because they hold no school-issued account, so those portals usually keep their own login.
Common mistakes
- Enabling SSO but leaving the old local logins active, so the bypass survives every offboarding.
- Skipping multi-factor authentication on the identity provider, turning one stolen password into access to everything.
- Sharing a single staff-room or office account, which defeats SSO's audit trail entirely.
Common questions
Is single sign-on the same as using one password everywhere?
No, and the difference matters. Reusing a password means every application still stores and checks a credential, so a breach in one exposes the rest. With SSO only the identity provider verifies the user; the other applications trust a signed assertion and never hold the password at all.
Does SSO make a school's systems more secure?
It concentrates control, which cuts both ways. Having one account to disable when staff leave, and one place to enforce multi-factor authentication, is a genuine gain. Equally, one compromised identity opens everything connected to it — which is why MFA on the identity provider is not optional.
Do we need SSO if we run only one school system?
Usually not. SSO earns its cost when staff move between several systems in a day — student records, learning platform, email, accounts. With a single application the same effort is better spent on individual named accounts, clear role separation, and removing leavers promptly.
Comparing school software categories? Edutris is the all-in-one option — SIS, fees, attendance, exams and a parent app on published tiers from ₹2,999/month.
Related terms
SaaS (Software as a Service)
Software delivered over the internet on a subscription, with no local install and automatic updates.
Multi-Tenant
An architecture where many schools share one software instance while their data stays isolated and private.
Parent Portal / App
The online portal or mobile app where parents view attendance, marks, fees, circulars and pay online.
Cloud vs On-Premise
Cloud software runs on the vendor’s servers over the internet; on-premise runs on the school’s own hardware.
Run your school on Edutris
Admissions, attendance, fees, report cards and a parent app — simple tiers from ₹2,999/month, no per-student add-ons.
Book a Demo