Skip to main content
Security, MFA & SSO
Authentication
- SSO: SAML 2.0 single sign-on integrates with Azure AD / Entra ID. Staff sign in with district credentials; local accounts remain available for evaluators.
- MFA: Time-based one-time passcodes, email codes, and backup codes are available for every account. Production policy enforces MFA for administrators.
- Evaluator note: the four demo logins are intentionally not gated by an MFA challenge, so you are never blocked on a device you do not have.
Protection and audit
- HTTPS with modern ciphers (TLS 1.2 and 1.3); encryption in transit and at rest.
- Role-based permissions by site; one person can hold different roles on different sites.
- Authentication and content events are recorded in the network audit trail.