This article explains Single-Sign-On (SSO) in Class including:
Overview
Class offers SSO integration for a number of identity providers that support OpenID Connect. This gives users a seamless login experience for the Class application.
Class follows the Australian Taxation Office (ATO) Operational Framework for Digital Service Providers (DSPs). Under this framework, multi-factor authentication (MFA) on your identity provider is compulsory.
For more information around the complete requirements, please refer to the following ATO article: Operational Framework.
Class will review all requests to activate SSO and require a signed agreement to be complete to document conformance to the ATO's Digital Service Providers (DSP) requirements.
Approval Process
- An Access Controller of the Business send a request to partners@class.com.au, including "SSO" in the subject line.
- Document your use case and which identity provider you use for Single-Sign-On.
- Confirm the Business will conform to the ATO requirements for Digital Service Providers (DSP).
- The Class Information Security Team will review your use case. If accepted, a contract will be issued that sets out the conditions for implementing SSO in line with ATO DSP requirements.
- Return the signed contract back to the Class Information Security Team.
- Once approved Class will activate SSO for the Business.
Login Using SSO
Once approved, Class will will repoint Class users logins, to make use of your identity provider. You will receive a unique URL for your users, which will enforce them to use your Identity Provider to log in to the Class application.
Users configured for Single Sign-On (SSO) cannot accept another standard Class user invite under the same Business. Instead, access is granted once the user is set up in the organisation's identity provider. The user then logs in for the first time using their unique SSO URL.
All data access rights and restrictions inside Class continue to be granted and controlled by the Class application, once a user has successfully logged in through your identity provider.
What's Next?
Learn more about Class' User Permissions.