Back to case studies // federation

University Adaptive Learning SSO

A university unified its adaptive-learning platforms behind a single Veripass sign-on, federating the campus directory over OIDC so students moved between tools without re-authenticating.

March 10, 2025 · Veripass
University Adaptive Learning SSO

Adaptive learning lives across many tools — a courseware platform here, an assessment engine there, a content library, a tutoring system. Each one promises personalization, but for a student each one also used to mean another login. A university adopting a portfolio of adaptive-learning products needed them to feel like one environment, not a relay race of credentials.

The challenge

The university had assembled best-of-breed adaptive-learning tools, and the seams showed. Students re-authenticated every time they crossed from one platform to the next, sometimes with subtly different credentials, and faculty fielded a steady stream of “which login is this one” support tickets. The campus directory was the natural source of truth, but each tool had been integrated independently, so account state drifted and de-provisioning a departing student meant chasing them through every system.

The university wanted one sign-on across the whole adaptive-learning portfolio, anchored to the existing directory.

What Veripass deployed

Veripass became the single sign-on layer in front of the adaptive-learning portfolio. The campus directory stayed the source of truth: Veripass federated with it over OIDC so students and faculty authenticated against the identity they already had. SAML covered any platform that spoke it instead, and SCIM kept account lifecycle in sync so a student added or removed in the directory propagated automatically across every connected tool.

Each platform was registered once against the university’s organization tenant and granted to the right population, so a student saw exactly the tools their enrollment entitled them to. Authorization rode on claims, capabilities, roles, and access profiles, which let the university express “undergraduate,” “graduate,” “instructor,” and “teaching assistant” as composable entitlements rather than per-tool configuration. Context-aware policy added adaptive step-up MFA over email or phone TOTP for sensitive surfaces such as grade entry.

  • Single sign-on across the adaptive-learning portfolio
  • Campus directory federation over OIDC, with SAML where needed
  • SCIM lifecycle sync across every connected platform
  • RBAC via claims, capabilities, roles, and access profiles
  • Context-aware step-up MFA for sensitive surfaces

Outcome

Students stopped noticing the boundaries between tools. One sign-on carried them across the entire adaptive-learning environment, and the “which login” support tickets largely disappeared. Because lifecycle flows through SCIM, a student’s access now appears and vanishes in lockstep with their directory record — no more orphaned accounts in a forgotten platform.

The university also gained a single place to reason about who can reach which learning tool and why. As the adaptive-learning portfolio evolves and new platforms are added, each one federates into the same sign-on rather than reintroducing a separate login.

More deployments

Affiliated Hospital Federation

Affiliated Hospital Federation

A network of affiliated hospitals federated identity across independent facilities, so rotating clinicians worked at any site under one identity while each hospital kept its own directory and audit boundary.

Cross-Industry Workforce Federation

Cross-Industry Workforce Federation

A holding company unified identity across retail, finance, and facilities operations into one federated control plane, so shared staff move between business units without duplicate accounts.

Global Bank Identity Hub

Global Bank Identity Hub

A multinational bank consolidated dozens of fragmented login surfaces into a single Veripass control plane, federating Entra ID and Google Workspace while keeping every regional directory authoritative.