Single Sign-On (SSO) allows Providers to log in to CampDoc/SchoolDoc using the same credentials they already use to access your organization’s other systems.
With SSO enabled, Providers don’t need to remember or manage a separate CampDoc/SchoolDoc password, making sign-in easier while allowing your organization to continue managing access through your existing identity provider.
In this article:
- Before Requiring SSO
- Requiring SSO for Providers
- Warning
- Prerequisites
- Configuring Single Sign-On (SSO)
- Updating Password Length and Expiration Rules
- FAQ's
Before Requiring SSO
Before requiring SSO for all Providers, make sure your SSO setup has been configured and tested successfully. Requiring SSO means Providers will need to sign in through your organization's identity provider to access CampDoc/SchoolDoc.
Requiring SSO for Providers
If your organization requires SSO, Providers will use their organization credentials to sign in instead of a separate CampDoc/SchoolDoc password.
This means your organization can manage Provider access through the same system you already use for your staff.
Warning
Enforcing SSO for Organizations strengthens data security while placing user access management firmly in your hands. Requiring IdP credentials ensures that provider login permissions are tied directly to your internal organization directory. Simply review your domain configuration prior to enforcement to keep onboarding seamless and secure.
Prerequisites
- Provider Permissions: You must have a Provider account with Edit access to Security Settings.
- Your organization’s SSO information: If you’re setting up SSO, you’ll need information from your organization’s identity provider (IdP). An identity provider is the service your organization uses to securely manage staff logins, such as Microsoft Entra ID, Okta, or Google Workspace.
- Identity Provider Metadata: Your IT team can provide the XML metadata file or service endpoint URL you’ll need during setup.
Configuring Single Sign-On (SSO)
Connecting your organization’s identity provider allows staff and providers to sign in using their existing institutional credentials (e.g., hospital or university logins) without managing separate passwords.
- Log in to your Provider Portal.
- In the left menu, click Settings.
- In the submenu, click Security.
-
Locate the Single Sign-On (SSO) section, and toggle Enable SAML SSO to On.
- Map the Email Attribute (Claim Mapping): Specify the exact field name your identity provider uses for email addresses (such as 'email' or 'emailaddress'). This tells the system where to look so it can correctly match incoming login data to the right user account.
- Upload Metadata XML
- (Optional) Select Enforce SAML SSO for Provider Accounts to require that all providers log in using your institutional domain.
- Click Save Changes, then click Test Connection to verify your setup.
-
Log out and log back in to test your SSO connection yourself.
Updating Password Length and Expiration Rules
To align with modern health data security standards, you can customize password length and enforcement cadences across your organization.
- Navigate to Settings > Security.
- Under Password Security Requirements, adjust your parameters:
- Minimum Password Length: Set password length requirements to up to 12 characters.
- Password Expiration Cadence: Toggle password expiration On and select your preferred timeframe (e.g., [INSERT EXPIRATION TIMEFRAME, e.g., 90 days]).
- Click Save Changes.
FAQ's
I tried to create my account with SSO, but I got a "No Access" page. What should I do?
Click the link in your invitation email again and try SSO one more time. If you see the "No Access" page again, open a new browser window or an incognito (private) window and try again.
If your organization does not require SSO, you can also create your account with an email address and password.
I tried to log in with SSO and got a "No Access" page. Now I can't try SSO again. What should I do?
Open a new browser window or an incognito (private) window. Then log in with SSO again using your organization's login information.
My CampDoc/SchoolDoc email address is different from my organization login email. How do I log in with SSO?
The steps depend on whether your organization requires SSO.
If your organization requires SSO, contact your organization and ask them to invite your organization email address to CampDoc/SchoolDoc.
If SSO is optional, follow these steps:
- Log in to CampDoc/SchoolDoc with your current email address and password.
- Click your name in the upper-right corner.
- In the Email Address field, enter your organization email address.
- Click Save.
- Click Link Account. You can also log out and click Log in with Organization.
Note: You will need to enter your CampDoc/SchoolDoc password to link your account.
I unlinked my SSO login. Now I need a password to link it again. What should I do?
If you have set a CampDoc/SchoolDoc password before, enter that password to link your account again.
If you have never set a password, follow these steps:
- On the Link Account page, click Forgot Password.
- Open the password reset email and click the link.
- Enter your new password, confirm it, and save it. You will be logged out.
- Log back in. If you log in with SSO, you will be asked to link your account with your new password. If you log in with your email and password, go to User Settings > Security to link your account. You will be asked to enter your password again.