Single Sign-On (SSO)

Single Sign-On Login Changes

San Diego Unified is updating how some applications handle sign in. The main change is that more applications will begin using Microsoft Single Sign-On.

What is SSO?

Single Sign-On lets you sign in once and use that sign-in across multiple district applications. This helps improve security and can reduce the number of times you are asked to sign in as more applications move to Microsoft SSO.

What is MFA?

Multifactor Authentication, or MFA, is an additional security step used to help verify it is really you signing in. After entering your password, you may be asked to verify your identity using the district MFA process. For more information, visit the Multifactor Authentication (MFA) page.

Microsoft SSO Login Flow

Microsoft SSO will become the main sign-in experience for more district applications. This is the primary login flow you may begin seeing more often.

SSO Flow: Microsoft, ADFS, MFA

Security reminder: Check the URL before signing in

Before entering your email, Employee/Student ID, password, or MFA code, always check the website address. District sign-in pages should match the expected URLs shown in the examples.

Examples include login.microsoftonline.com, adfs19.sandi.net, dwa.sandi.net, and api-a833b38b.duosecurity.com.

How the Microsoft SSO flow works

Step 1

Microsoft Login

Enter your district email to start the sign-in process.

Step 2

ADFS Login

Enter your password. Your email will usually carry over.
On this screen, you may use your district email or your Employee/Student ID.

Step 3

MFA

Verify your identity using MFA.

Important: ADFS is currently our Single Sign-On system for most district applications. We are transitioning more applications to Microsoft SSO.

During this transition, some applications may show more than one sign-in flow. For example, an application may first use Microsoft SSO, then still require the application’s current ADFS and MFA sign-in.

Why are we making this change?

This change is being made to increase overall login security and create a more consistent sign-in experience. As more applications move to Microsoft SSO, you should be asked to sign in less often.

Some applications, such as PeopleSoft, may continue to require their own sign-in and MFA in addition to Microsoft SSO.

Other login flows you may see

Some applications may continue to use their current sign-in flow during or after the transition.

PeopleSoft Login

Some applications, such as PeopleSoft, may still require a separate application sign-in and MFA.

SSO Flow: Peoplesoft, MFA

ADFS Login

Some applications may continue to start directly at the ADFS login screen and then require MFA.

SSO Flow: ADFS, MFA

Onsite and offsite access: The login process will work the same whether you are onsite or offsite.

Using a district-managed device may reduce how often you are asked to sign in, especially when you are onsite. Personal devices, offsite access, or higher-risk sign-in situations may require additional security checks.

Questions and Answers

What is Single Sign-On?

Single Sign-On, or SSO, allows you to use one district sign-in process to access multiple applications. It helps keep accounts secure and can reduce repeated sign-ins.

Why am I being asked for my email first?

The Microsoft login screen uses your district email to start the sign-in process and route you to the correct district login system.

Can I use my Employee ID or Student ID?

On the Microsoft login screen, enter your district email. On the ADFS password screen, you may use your district email or your Employee/Student ID.

Why did my email carry over to the ADFS screen?

This is expected. After you enter your district email on the Microsoft screen, that information may carry over to the ADFS password screen.

Why am I seeing more than one login?

During the transition, some applications may use Microsoft SSO first and then still require the application’s current ADFS and MFA sign-in. This should become more consistent as more applications move to Microsoft SSO.

Will this work the same at home and at work?

Yes. The login process will work onsite and offsite. You may see additional security checks when using a personal device, connecting from offsite, or signing in from a higher-risk situation.

Why does a district device ask me to sign in less often?

District-managed devices can provide additional trust signals during sign-in. This may reduce repeated sign-in prompts, especially when you are onsite.

Will PeopleSoft still require a separate sign-in?

Some applications, including PeopleSoft, may continue to require their own sign-in and MFA in addition to Microsoft SSO.

Need help?

If you have trouble signing in, contact the IT Service Desk at 619-209-4357 (HELP), Monday through Friday, 7:00 a.m. to 5:00 p.m.