Single sign-on: one click in, zero passwords to steal.
Training adoption dies at the login screen, and security teams die a little at every new credential store. SSO solves both: learners reach practice in one click from the identity they already have, and your IdP keeps sole custody of authentication.
Every extra login is an adherence leak and an attack surface
A daily-practice product lives or dies on friction: each credential prompt sheds a share of that day’s sessions, and the habit the retention model depends on erodes at the login screen. Meanwhile every independent password store your vendors accumulate is another phishing target and another offboarding checkbox that gets missed.
SSO removes both failure modes at once. Learners arrive authenticated from the tools they’re already in; security keeps MFA, conditional access and session policy at the IdP where they belong; and offboarding is what it should be — one identity disabled, everything closed.
Works with the IdP you run
SAML 2.0 and OIDC cover Azure AD / Entra, Okta, Google Workspace, OneLogin, JumpCloud and standards-compliant peers. Metadata exchange, attribute mapping, test logins — typically one session with your identity team.
Roles arrive with the login
Group and attribute claims map to platform roles, so a manager lands in manager views and a learner in practice — provisioning logic your IdP already encodes, respected here.
Security review, pre-answered
No local passwords, IdP-side MFA and conditional access, logged sessions, immediate deprovisioning — the SSO section of your security questionnaire mostly fills itself. The security page carries the rest.
One login, every device
SAML or OIDC against your IdP, SCIM for lifecycle — access that follows the identity, not another password.
| Provider | Protocol | Tested | State |
|---|---|---|---|
| Okta | SAML 2.0 | tested | Supported |
| Azure AD | OIDC | tested | Supported |
| OIDC | tested | Supported | |
| Any IdP | SAML / OIDC | generic | Supported |
Interface shown as an illustration with representative numbers, not a screenshot — the layout is the product’s.
Loop in your identity team early.
SSO setup is a one-session job when the right people are on the call — we’ll bring the metadata and the checklist.
The evidence this page stands on
Questions buyers ask
Which protocols and providers are supported?
SAML 2.0 and OIDC — which covers Azure AD / Entra, Okta, Google Workspace, OneLogin, JumpCloud and any standards-compliant provider. If yours speaks either protocol, it works.
Can SSO be enforced, not just offered?
Yes — SSO-only mode disables all other login paths for your organisation, which is how most security teams choose to run it.
How do frontline workers without corporate email log in?
Mixed-mode is supported per company: SSO for the corporate population, managed alternatives for populations your IdP doesn’t cover — with the same session logging either way.
Does MFA come from your platform or ours?
Yours. Authentication policy — MFA, conditional access, session length — lives at your IdP, applied to this platform like any other app in your catalogue.
What identity attributes do you consume?
The minimum for account mapping and role scoping: identifier, name, and the group/role claims you choose to send. The attribute map is explicit and yours to review.
See it on your own content.
Bring one course. We’ll show you the retention curve your current training leaves behind — and what scheduled review does to it.
- 30 minutes, on your calendar — pick a slot here
- Run on your own content wherever possible, not a canned deck
- You see the dashboards, the learner surface and the evidence exports
- No commitment — and pilot data stays yours either way