r/k12sysadmin Future Sysadmin 4d ago

FACTS/RenWeb SSO Support

Does FACTS finally have SSO support yet, and is anyone using it? With the recent push for MFA every 24 hours, staff is getting annoyed. We would like to relinquish back control over the login process, as well as simplify login; for staff and preferably students.

We're what I like to call an "Everything" shop in terms of IDP. We have AD, Entra, Google, and Duo (On-Prem AD is the source of truth that pushes out to everything else).

I'd ask our SIS admin to email RenWeb, but don't feel like putting him in the 6th circle of hell - that is RenWeb support.

13 Upvotes

8 comments sorted by

2

u/Kendalf Director of Technology 3d ago

I've not seen anything about SSO support in FACTS. The MFA is actually required every 8 hours, and yes it is extremely annoying. However, FACTS rolled out the use of passkeys about a week ago, and that has made the login process easier for those who turn it on.

2

u/QueJay Some titles are just words. How many hats are too many hats? 3d ago

We rolled out SSO this summer through FACTS.

To get it going now you'll need to contact your account manager to try and get into the 'beta' testing phase of it now. We are a Microsoft school so ours is setup as an Entra Enterprise App with SAML connection.

I will note it does not remove the authentication requirement, simply moves it over to your IDP. We have to authenticate each day still for SIS access, it just happens with Microsoft credentials and not direct FACTS credentials. So our daily login process is:

Landing Page Enter District Code -> A new page is there showing 5 options: Staff SSO/ Staff Direct Login / Student SSO / Student Direct Login / Parent Direct Login. My understanding is that once we get everyone confirmed fully over to SSO they'll remove the two non-parent direct login options but who knows.

Even if you have a previously authorized session on that device, if that authorization is over likely 8 hours old FACTS requires a fresh authorization token for the SSO so you get an MFA ping.

It definitely isn't a perfect setup but is easier management wise for students.

2

u/MaxBroome Future Sysadmin 3d ago

Super helpful, thanks. I’ll talk with the boss to see if we can get the ball rolling on this.

We had freshman BYOD device orientation and everything on our side was flawless, but getting them set up in FACTS was a mess. Hoping to alleviate that for next year!

0

u/Temporary_Werewolf17 3d ago

We did that same but now have some staff that are unable to log in to the financial side. Have you seen this behavior?

1

u/QueJay Some titles are just words. How many hats are too many hats? 1d ago

So I purposefully game-planned with Holly and Tiffany to not convert our Dual-access people during this initial phase and we were going to get them together on a call with a FACTS engineer available to make sure the conversion didn't mess up like that. Our school year just started last week so I've been finalizing all the other faculty/staff conversions before we get to them.

So I haven't seen that, but I am also 0% surprised that is an issue and you or your admin should reach out to them.

1

u/Temporary_Werewolf17 1d ago

I was not clear. Our dual access people still have to authenticate each login. We use facts for billing for lunch. We have several that can not login to see and pay what they owe.

1

u/grewholph 2d ago

We rolled out Microsoft sso. We are having a few growing pains. But overall a positive experience.

1

u/thedevarious IT Director 14h ago

It looks like there's some potential SSO by proxy below, I'd need to investigate with the one school we have that uses Facts SIS.

However I would push back on your staff about MFA. Big time.

"While I understand the frustration with having to type in a random string of numbers once to twice a day minimum, we need to look at the security implications. This system houses some of the most sensitive data about our most important users -- our students. This has to be safeguarded top to bottom without exception. If there was even one security incident involving this tool, all of us would face the unemployment line."