Single Sign-On (SSO) and Directory Services

Tags sso mfa saml

Learn about single sign-on (SSO) and directory services at NCU, including how one university account signs you in to many systems and how access is decided.

In this article

  1. One Account, One Sign-In
  2. How Single Sign-On Works
  3. What to Expect
  4. How Directory Services Work
  5. Why Central Accounts Matter

One Account, One Sign-In

Every person affiliated with NCU has one university account. Single sign-on lets that account sign you in to Microsoft 365, Canvas, Skyline, and many third-party applications using the same university sign-in page — so you sign in once instead of keeping a separate password for each system.

How Single Sign-On Works

1
You open an application and are sent to the university sign-in page.
2
The university confirms who you are using your NCU username, password, and multi-factor authentication. This is authentication.
3
The application decides what you can do based on your role at NCU. This is authorization.
4
Other SSO applications open without signing in again while your session is active.
  Your session stays open until you sign out, close the browser, or it expires.
On a shared or public computer, sign out and close the browser completely when you are finished.

What to Expect

  Not Every App Uses SSO
  Access Depends on Role
  Vendors Are Reviewed
Some applications have their own separate sign-in and password.
Signing in to one SSO application does not grant access to all of them. Access follows your role as a student, faculty, or staff member.
The Office of Innovation & Technology works with vendors to connect their products to university sign-in wherever possible.

How Directory Services Work

The university's central directory holds every NCU account and controls what each one can reach. Access is granted mainly through group membership: each group is tied to a specific service or system, and accounts are added to the groups that match their role. Access can be broad, like Microsoft 365 for all employees, or narrow, like read and write access to one department's file share.

  Microsoft Entra ID
  Active Directory
Handles university sign-in, multi-factor authentication, and SSO for Microsoft 365, Canvas, Skyline, and connected third-party applications.
Manages access to on-campus resources such as university computers, printers, and department file shares.

Why Central Accounts Matter

  Provisioning
  Lifecycle
  Monitoring
  Logging
Determines who receives a university account.
Activates accounts when needed and deactivates them when they are not.
Flags unusual or potentially harmful account activity.
Keeps a history of account and device activity for security investigations.
Print Article

Related Articles (1)

North Central utilizes multi-factor Authentication (MFA) for all users, including faculty, staff, adjuncts, and students. Learn how to set up MFA using the Microsoft Authenticator.

Related Services / Offerings (2)

This article provides a broad overview of Multi-factor Authentication (MFA) and how it is used to secure university systems and information. This is meant for all North Central students, staff, and faculty.
Use this service to report a single sign-on (SSO) issue, request SSO for an application, change an existing SSO connection, or ask a question about university sign-in and directory access. To learn how SSO and directory services work at NCU, see Single Sign-On (SSO) and Directory Services at NCU.