You can configure user sign in options for users in your account from Sign-in Settings. Elevate K-12 Analytics offers several account authentication methods.
Users log in with a personal username and password.
First-time users must enter their institution-provided username and then enter a password to use with their account. They must then check their institution-provided email account for an account verification email. Once verified, users can log in to Elevate K-12 Analytics.
You can allow users to log in using their Gmail account.
You can require users to log in using multi-factor authentication. Before logging into Elevate K-12 Analytics, users must obtain a verification code sent via email. Users can select for Elevate K-12 Analytics to remember their login on the current device.
When enabled, users at your institution can access Elevate K-12 Analytics from a preconfigured link on an intranet website. This method bypasses the login screen. To configure SSO for your account, you need the following information from your identity provider:
In the Navigation Menu, click the Admin link.
In the Security Management Navigation Menu, click the Sign-in Settings link , or on the Security Management Overview page you can click the Sign-in Settings link .
Manage general sign-in settings for your account on the Sign-in Settings page.
To enable personal logins for manually created users in your account, click the Personal logins enabled toggle . This option allows users to create their own password upon login. It also allows users to log in with approved social media accounts.
To specify the social media platforms available for login, click the Social logins checkbox next to the platform name . Currently Elevate K-12 Analytics offers support for login via Google.
Note: First-time users must enter their institution-provided username and then enter a password to use with their account. They must then check their institution-provided email account for an account verification email. Once verified, users can log in to Elevate K-12 Analytics.
To enable single sign-on for your account, click the SSO enabled toggle. This option requires users to log in using your institution's identity authorization provider. You can also specify account SSO options for individual users whose accounts were created manually.
To enable single sign-on for your account, you must configure your institution's SSO for Elevate K-12 Analytics.
Your institution's Elevate K-12 Analytics URL displays in the Redirect URL field . To copy this URL, click the Copy link . Then add the URL to your Identity Provider allow list.
Enter the client ID in the Client ID field  and the client secret in the Client secret field . If you do not know this information, you can obtain it from your identity provider.
Specify the identity provider's level of access in the Scopes field .
Enter the OpenID Connect Provider URL in the Issuer URL field .
To enable SSO configuration using a discovery document, click the User discovery document toggle .
To specify a logout URL for your account, click the Logout URL .
If you turn off the Use discovery document option , you must provide the following information.
Authorization URL : the redirect URL where users can complete authentication.
Token URL : the token endpoint used to obtain an access token, ID token, and refresh token.
Jwks URL : the token endpoint used to obtain an access token, ID token, and refresh token.
You may require multi-factor authentication (MFA) for personal login users. This requires them to enable MFA on their user accounts.
To require MFA, click the MFA required toggle . To set a date for the requirement to begin, enter or select a date in the MFA requirement effective date field .
Note: Even if MFA is not required, individual users with personal logins may set it up for their account.