What is Single sign-on?
Also called: SSO · OpenID Connect SSO · SAML SSODefinition
Single sign-on (SSO) is an authentication arrangement in which a user signs in once with a central identity provider, such as Microsoft Entra ID, Okta or Google Workspace, and is then trusted by many separate applications without entering another password. The two main standards are SAML 2.0, from OASIS, and OpenID Connect (OIDC), from the OpenID Foundation, which is built on OAuth 2.0. For an LMS, SSO means employees open training with their work account, and access ends when that account is disabled.
In an OpenID Connect flow, the LMS redirects the learner to the company’s identity provider, the learner signs in there (often with multi-factor authentication), and the provider returns a signed ID token stating who they are. The LMS trusts the token and opens the right account. SAML works in a similar way with XML assertions. The application never sees the password.
For corporate L&D, SSO removes the most common support request, forgotten LMS passwords, and raises adoption because training is one click from the intranet. It also helps security: password policy and MFA are enforced centrally. SSO handles sign-in only, though; creating and removing accounts is the job of directory sync such as SCIM. Bodhih LMS supports single sign-on through OpenID Connect with Entra ID, Okta and Google Workspace, and a company can configure several providers.
Common mistakes: turning on SSO without SCIM or another deprovisioning method, so leavers keep LMS accounts; forgetting contractors, dealers or clients who are not in the corporate directory and need another login route; and mismatched email addresses between the LMS and the identity provider.
Key points
- One sign-in with a central identity provider, trusted by many apps.
- Main standards: SAML 2.0 (OASIS) and OpenID Connect (OpenID Foundation).
- OIDC is built on OAuth 2.0 and uses signed ID tokens.
- Handles authentication only; pair with SCIM for provisioning and deactivation.
- Plan a route for users outside the corporate directory.
An example at work
A Noida IT company connects its LMS to Microsoft Entra ID with OpenID Connect. Employees click “Learning” on the intranet and land on their dashboard already signed in, while contractors without company accounts sign in with email and password on the same portal.
Where this is used at Bodhih
Related terms
SCIM
SCIM is an open standard that automatically creates, updates and deactivates user accounts in applications, such as an LMS, from a central directory.
Learning management system
A learning management system (LMS) is software that delivers, assigns, tracks and reports on training, from e-learning courses to classroom sessions and certifications.
Multi-tenant LMS
A multi-tenant LMS is a learning management system that runs many separate organisations or portals, each with its own users, content, branding and admins, on one platform.
LTI
LTI is a 1EdTech standard that lets a learning platform launch an external learning tool securely, passing user identity and context, without a separate login.
More about Single sign-on
What is the difference between SAML and OpenID Connect?
Both provide single sign-on. SAML 2.0 is an older XML-based standard from OASIS, common in enterprise software. OpenID Connect is a newer JSON-based standard from the OpenID Foundation, built on OAuth 2.0, and suits web and mobile apps. Major identity providers such as Entra ID, Okta and Google support both.
Does SSO remove users when they leave the company?
Not on its own. When a leaver’s corporate account is disabled they can no longer sign in through SSO, but their account in the application still exists. Automatic deactivation needs directory sync such as SCIM, which tells the application to deactivate the account.