Skip to main content
← All integrationsIdentity & SSO

SAML 2.0 single sign-on for DeepTech LMS

Connect any SAML 2.0 identity provider — Okta, Azure AD, Ping, JumpCloud, Auth0 — and let your IT team own identity. We don't see passwords.

DeepTech LMS speaks SAML 2.0 as a Service Provider. Bring any compliant IdP (Okta, Microsoft Entra / Azure AD, Ping, JumpCloud, Auth0, Google Workspace, ADFS). Roles, groups, and de-provisioning flow from the IdP.

Trademark note: SAML 2.0 is a trademark of its respective owner. This page describes DeepTech's support for SAML 2.0; it does not claim partnership or certification unless explicitly stated on our security or compliance pages.

What's supported

Capabilities are described as they exist in DeepTech today. We'll confirm anything we don't list here on a discovery call.

SP-initiated and IdP-initiated flows

Both flows are supported. Launch from your IdP catalogue, or have users land on DeepTech and route to the IdP for sign-in.

Just-in-time provisioning

First sign-in creates the account using the SAML assertion attributes. No nightly batch import required.

Group-based roles

Map IdP groups → DeepTech roles (faculty, student, admin, auditor) on the assertion. Move a user between groups in the IdP and their LMS access follows.

Multi-tenant claims

For multi-campus universities, the tenant the user belongs to is taken from a SAML attribute so one IdP federates many tenants.

Signed and encrypted assertions

Optional assertion encryption + signed responses; rotation of signing certificates supported without downtime.

Frequently asked questions

Do you support Okta, Azure AD, Google Workspace, and ADFS?

Yes — all four are SAML 2.0 IdPs and have been wired into DeepTech LMS. The same metadata-XML exchange works for any other SAML 2.0 IdP.

What metadata do we exchange?

You upload (or paste) our SP metadata into your IdP and we ingest yours into the LMS. The exchange is one-time per environment; certificate rotation is a metadata refresh.

Where does identity data live?

Only the attributes the assertion carries (name, email, group, tenant) — no passwords, no MFA tokens. De-provisioning is by group removal on the IdP side and is honoured on the next assertion.

Need a different integration?

DeepTech exposes a documented REST API plus webhooks, so most institutional systems can be wired in. Send our engineering team your stack and we'll scope it.