Sign-in methods and SSO
Eduvem offers more than one way in, configurable per institution. Native sign-in (username and password) is always available; the SSO mechanisms are optional.
Native sign-in
Section titled “Native sign-in”- The participant signs in with email, CPF, or username (depending on how they were registered) and password - the platform automatically recognizes which of the three was typed.
- The sign-in screen has protection against excessive attempts (rate limiting) - repeated errors in a row temporarily block new attempts.
- Recovery is self-service through Forgot password.
Corporate SSO
Section titled “Corporate SSO”To sign in with the organization’s account, with no separate password:
- SSO with Microsoft (SAML): the most common path - see the dedicated guide at SSO with Microsoft.
- Keycloak / OIDC: institutions that already operate a compatible identity provider can connect it; the participant’s registration is found or created automatically on first access.
Each mechanism is configured per institution, and access is always isolated: sessions are valid only for your Eduvem.
For institutions with SAML SSO, the SSO configuration tab has an option “Also sign participants out of the Identity Provider on logout”, disabled by default. When enabled, signing out of Eduvem also ends the participant’s session at the Identity Provider (SAML single logout) - useful when the device is shared. When disabled (the default), logging out ends only the session on the platform; the session at the Identity Provider may remain active until the browser closes or it expires on its own.
Extra protection for platform accounts
Section titled “Extra protection for platform accounts”The Eduvem platform administration accounts (the Eduvem team, not your institution’s administrators) have an additional hygiene rule: passwords older than 12 months require a change at the next sign-in. It is automatic and not configurable. Your institution’s administrators and participants are not affected by this rule.