Skip to content

Sign-in methods and SSO

Eduvem offers more than one way in, configurable per institution. Native sign-in (username and password) is always available; the SSO mechanisms are optional.

  • The participant signs in with email, CPF, or username (depending on how they were registered) and password - the platform automatically recognizes which of the three was typed.
  • The sign-in screen has protection against excessive attempts (rate limiting) - repeated errors in a row temporarily block new attempts.
  • Recovery is self-service through Forgot password.

To sign in with the organization’s account, with no separate password:

  • SSO with Microsoft (SAML): the most common path - see the dedicated guide at SSO with Microsoft.
  • Keycloak / OIDC: institutions that already operate a compatible identity provider can connect it; the participant’s registration is found or created automatically on first access.

Each mechanism is configured per institution, and access is always isolated: sessions are valid only for your Eduvem.

For institutions with SAML SSO, the SSO configuration tab has an option “Also sign participants out of the Identity Provider on logout”, disabled by default. When enabled, signing out of Eduvem also ends the participant’s session at the Identity Provider (SAML single logout) - useful when the device is shared. When disabled (the default), logging out ends only the session on the platform; the session at the Identity Provider may remain active until the browser closes or it expires on its own.

The Eduvem platform administration accounts (the Eduvem team, not your institution’s administrators) have an additional hygiene rule: passwords older than 12 months require a change at the next sign-in. It is automatic and not configurable. Your institution’s administrators and participants are not affected by this rule.