Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

Click this link to go to PowerSchool's instructions.

...

  1. On the start page within the PowerSchool SIS Admin portal, choose System Management in the left-hand menu.

  2. System Management will open, and select Security.

  3. Click OIDC Authentication.

    image-20250116-195617.png
  4. Select Add.

  5. In the user dropdown select the user type you want. If all three options are needed repeat steps 5 - 10 for each user dropdown.

    image-20250116-200103.png
  6. Enter https://accounts.google.com for the IDP URL.

  7. Enter the client ID and client secret that was received from Google Cloud during Part 2: Configure the Google Web App.

  8. Enter openid email for the Scopes field.

  9. For Authentication ID / Identifying Claim, enter email.

  10. Check the Enable OIDC Authentication for the personas you need.

  11. Click Submit.

    image-20250116-201636.png

...

  1. On the start page within the PowerSchool SIS Admin portal, choose Data and Reporting in the left-hand menu.

  2. Data and Reporting will open, then select Export.

  3. Under Export click Data Export Manager

    image-20250116-202801.png
  4. In the Select Columns to Export section:

    1. Choose PowerSchool Data Sets as the Category.

    2. Choose one of the following from Export From. **Note - You will need to run this multiple times if you need to export all users.**
      **To get all of your Staff and Teachers you need to run both the Staff Mapping and Teacher Mapping**

      1. SSO Staff Mapping

      2. SSO Teacher Mapping

      3. SSO Parent Mapping

      4. SSO Student Mapping

  5. Select the columns to export, it is helpful to also include email or first and last name so it is easier to identify the user in the CSV file.

    1. For Staff and Teacher, User DCID, SSO User Type, Global Identifier are required.

    2. For Parent, Person ID, SSO User Type, Global Identifier are required.

    3. For Student, Student DCID, SSO User Type, Global Identifier are required.

    4. Click Next.

      image-20250117-143043.png

  6. In the Select/Edit Records section, you can use the Built In Filters to narrow the list of records to export, then click Next.

  7. In the Export Summary and Output Options section:

    1. Change the Export File Name extension from .txt to .csv.

    2. Choose Comma as the Field Delimiter.

    3. Choose UTF-8 as the Character Set.

      image-20250116-204032.png
  8. Click Export.

...

Step 6: Test SSO for Personas

**update URLs shared with teachers and staff. you no longer need pw.html https://nwoesc.ps.nwoca.org/teachers/pw.html

After mapping the users from the identity provider to the PowerSchool SIS, test the SSO connection between your identity provider and the PowerSchool SIS as the service provider. To test a persona, enable OIDC authentication and then verify that you can sign in tothe respective portal. Be sure to test each persona in another browser or using an incognito window before ending your current session.

Enabling OIDC authentication for users without also defining Global Identifiers for users will prevent users from being able to sign in.

  1. In PowerSchool SIS for Administrators, navigate to the OIDC Authentication page.

  2. Select Enable OIDC Authentication for the persona you want to test. It is recommended that you first test teachers, then parents, then students, and finally staff.

  3. Click OK.

  4. Click Submit, but do not close the window.

  5. Based on your Step 3 selection, choose the user you want to test.

  6. Open a new private browser window.

  7. Based on your Step 3 selection, enter the URL of your district's PowerSchool SIS Teacher, Student and Parent, or Admin portal and press ENTER or RETURN. The PowerSchool SIS portal should redirect to the IdP's sign-in page.

  8. Sign in with the user's credentials. For teacher, parent, and student, if the PowerSchool SIS portal launches, the setup has been configured properly. For staff, if the PowerSchool SIS Admin portal launches and you are expelled from your first session, as you are only allowed one session at a time, the setup has been configured properly.

  9. For parent, and student, open the PowerSchool Mobile app. Sign in with the user's credentials.

...