How to Configure the Tenant to Authenticate SSO via LTI 1.1
LTI Authentication allows third-party application users to access the Frost platform using LTI 1.1. A Superadmin user has the authority to enable the tenant to authenticate SSO via LTI while an admin user can successfully configure it. Once the LTI Authentication is enabled and configured, a user should be able to access the application based on the assigned roles and platforms.
To configure the tenant to authenticate SSO via LTI:
Step 1: Enabling LTI SSO Authentication
- From the Tenant Configuration page, navigate to the Registration & Authentication section.
- To enable LTI Authentication, toggle the switch from Off to On.
Note: Only Superadmin can view and enable the LTI Authentication feature. A Super Admin is a user that has complete access to the system. The super admin user access is with LearningMate only. To make any super admin level configurations for the tenant, kindly raise a Zendesk Request or contact the Account SPOC.
- In the Domain Name field, enter the domains to be authorized for login.
Note: These domains will be given the authorization to log in using LTI authentication. This will allow users coming from third-party applications to log in to the tenant.
- Click Save to update the tenant configuration.
Step 2: Creating LTI Configuration
- Navigate to the Admin platform, click the LTI drop-down and select LTI Config. (1.1).
- Click Create LTI Configuration to open the Add LTI Configuration form.
- Fill in the necessary details such as:
- Organization Level – select the level of the organization
- Level 1
- Level 2
- Organization Name – select an organization from the dropdown based on the level selected.
- Configuration Type - select SSO
- Organization Level – select the level of the organization
- Based on the data selected above, the following fields are generated automatically:
- Organization Type
- LMS Consumer Key
- Shared Secret
- Launch Url
- Click Save to add the LTI Configuration to the system.
- Share the LMS Consumer Key, Shared Secret, and Launch URL generated by the Tenant with the third-party application.
Note: On successful configuration, the third-party application users can access Frost via LTI Authentication.