SSO integration FAQs

Goal

Quick answers to the most common questions institutions ask when setting up single sign-on with BoodleBox. For step-by-step setup, see How to set up SSO with your identity provider or How to set up SAML SSO with rostering.

Planning and setup

Which integration path should we use — IMP, LMS, or SAML?

If you use Microsoft Entra, Google Workspace, or OneLogin, use the IMP path — it's the simplest. If you want users launching from your LMS (Canvas, Brightspace, Blackboard, etc.), use the LMS path; you can do both. Use SAML when your identity provider isn't one of the three native options. All three paths run through the same Edlink integration link.

Can SAML be our only integration?

No. SAML is authentication/enrichment only — it cannot provision (roster) users. Always set up a rostering source first (SFTP/CSV), then add SAML through the configuration process.

What is Edlink and why is it involved?

Edlink is the integration subprocessor for BoodleBox.

How long does setup take?

SSO configuration can take 2–3 weeks end to end, depending on the integration pathway selected.

Can we use claims-based authentication to avoid maintaining an SFTP roster?

No — Edlink does not support claims-based provisioning via SAML attributes. Rostering requires an SFTP/CSV file, LMS roster, or directory groups.

Permissions and security

Why does the Microsoft Entra consent screen request so many permissions for a login tool?

The Edlink application registers a broad permission set because it supports many integration types. For BoodleBox SSO, only four scopes are required: offline_access, openid, email, and profile.

Can we revoke the extra permissions (e.g. grades, classes) after setup?

Yes. As long as the four required scopes remain enabled, the integration stays operational. Revoking the others after initial setup has no effect — BoodleBox does not read grade data through SSO.

Accounts and users

Some users already have BoodleBox accounts. What happens to them?

SSO automatically associates with an existing account as long as the email registered with BoodleBox matches the email in your IMP/LMS. If the emails differ, a duplicate account is created — have the user contact success@boodle.ai.

Is SSO available on free or individual plans?

No. SSO is only available for users associated with a paid institutional team.

What happens when someone leaves the institution?

If you provision from the integration, their team access is removed at the next sync once they drop off the roster. If you don't provision from the integration, remove the user from your BoodleBox dashboard and they'll be removed from the team at that time. Their underlying BoodleBox account persists; full deletion requires a formal request to success@boodle.ai.

Will users get an email when we grant access?

Yes — a welcome email is automatically triggered when access is granted. Plan internal comms accordingly; for a phased rollout, coordinate with your Customer Success representative.

Signing in and sync

A user was just added but can't log in.

Roster sources sync every 24 hours. Wait for the next cycle or trigger a manual sync from the Edlink dashboard.

Users get errors right after we finished setup.

Login attempts during the 24-hour propagation window can return "account not found" or similar. This is expected — try again the next day.

What does a 400 error mean?

Almost always: the user isn't provisioned and needs to be added to the integration group or to the BoodleBox workspace by the team admin. See Troubleshooting SSO and sign-in errors.

Still stuck?

See also

How to set up SSO with your identity provider · How to set up SAML SSO with rostering · LMS integration FAQs.

Contact us

Didn’t find what you need?

Send us a note and the team will get back to you — typical response within 8 business hours.

PNG, JPG, GIF, WEBP or PDF. Up to 310 MB each.