Campus-Wide Student SSO
A university gave every student one login for the entire campus stack by federating Google Workspace and the student directory through Veripass, ending the credential sprawl across portals and services.
A modern campus runs on dozens of digital services: the learning management system, the library, the registration portal, email, lab schedulers, the printing system, the meal plan. Each one had grown its own front door. For students, “logging into campus” had quietly become “remembering which password goes where,” and for IT it had become a help desk dominated by resets.
The challenge
The university’s services had accreted over years, each with its own authentication. Some integrated with Google Workspace, which the campus already used for student email; others kept independent account stores with their own password rules and expiry schedules. The result was credential sprawl: students juggled multiple logins, reused passwords across services out of fatigue, and flooded the help desk every term. There was no single answer to “what can this student reach.”
The university wanted one identity per student, spanning the entire campus stack.
What Veripass deployed
Veripass established a single campus sign-on with Google Workspace as the federated source of truth. Students authenticated against the Google Workspace identity they already used for email over OIDC, and Veripass carried that session across every connected service. Legacy portals that could not speak OIDC were brought in over SAML, and SCIM synchronized account lifecycle so enrollment, holds, and graduation flowed automatically into the services rather than being maintained by hand.
Every campus service was registered against the university’s organization tenant and granted to the appropriate population. Authorization through claims, capabilities, roles, and access profiles let the university model the natural distinctions — full-time, part-time, on-campus resident, online-only — as composable entitlements, so a student’s access matched their actual status. Context-aware policy applied adaptive step-up MFA over email or phone TOTP when a session reached more sensitive surfaces such as financial-aid records.
- Campus-wide single sign-on for every student service
- Google Workspace federation over OIDC, SAML for legacy portals
- SCIM lifecycle sync tied to enrollment status
- RBAC via claims, capabilities, roles, and access profiles
- Adaptive step-up MFA for sensitive student records
Outcome
One login now opens the whole campus. Password-reset tickets — long the single largest category at the help desk — dropped sharply, because students maintain one credential instead of a dozen. Reusing weak passwords across services stopped being a coping strategy, since there is no longer a sprawl to cope with.
The university also gained a coherent answer to “what can this student reach,” expressed once through entitlements rather than scattered across service configurations. As new services join the campus stack, they federate into the same student sign-on instead of minting yet another password for students to forget.
More deployments
Clinician EHR Single Sign-On
A hospital network gave clinicians one federated sign-on across the EHR and clinical applications, cutting repeated logins at the bedside while keeping every access policy-governed and audited.
Fingerprint Turnstile Entry
A manufacturing site replaced badge tailgating at its turnstiles with fingerprint biometric verification bound to identity, so every entry proved the person was physically present and authorized.
Maison Loyalty Verification
A luxury maison protected its high-tier loyalty program with biometric identity verification at enrollment and step-up at redemption, stopping account takeover of accounts holding significant stored value.


