Identity Access Management (IAM) is a set of policies and procedures that help organizations automate which users can access which data. In the case of the LMS, IAM tools can safeguard not only course content but also user data.
Touvti has various natively integrated tools that help Admins implement an IAM program. This article outlines these different tools and links to broader articles that outline how to use them.
This article outlines the following concepts:
General Security Configurations
From the moment Admins begin to use Tovuti, they can configure a variety of general security settings to reinforce how users and other admins log in to and interact with the LMS.
Go to Configuration > click Security
Configure is a user can upload their own avatar. Some Admin teams may want to restrict this ability to When restricted, Admins can upload images to an avatar bank from which users can select.
Set if there is a limit to the number of failed login attempts. When enabled, users are required to wait a designated amount of time before being allowed to login again.
Admins can also set requirements for password strength. This requires users to create unique passwords for the LMS.
Two-Factor Authentication
Also within the Security configurations, Admins can enable and set up Two-Factor authentication tools.
A “factor” refers to the method used to log in to a user’s account; including passwords, physical objects, or a personal trait such as a fingerprint. Inputting multiple factors when logging in conclusively verifies the identity of the user.
With Tovuti, Administrators can utilize two-factor authentication through a mobile authentication app and Yubikey.
Admins can select the best app or tool according to their preference and use case.
Security at the Login Level
Tovuti offers additional features at the login level that ensures users are who they say they are when entering the LMS.
Single Sign-On (SSO)
Integrating Single Sign-On to the LMS not only adds extra security for learners, but also makes the sign in process quick and easy.
Through SSO, Admins can also configure Profile Field and User Group Mapping. These configurations enable automatic syncing of profile information from the SSO platform to the LMS, ensuring users are immediately added to correct groups and therefore have access to corresponding content.
This level of automation is an essential part of a robust IAM program.
Tovuti supports the following SSO systems that are supported by SAML or OAuth2.0.
- SAML
- OneLogin
- AuthO
- Centrify Identity Service
- Microsoft Azure Active Directory (view setup guide)
- Microsoft Active Directory Federation Services (ADFS) (view setup guide)
- Okta Identity Management (view setup guide)
- Idaptive Next-Gen Access
- Amazon Cognito
- SecureAuth Identity Platform
- VMware Workspace One
- EmpowerID
- Optimal IdM
- CloudCodes
- LastPass Enterprise
- Ping Identity PingOne
- Salesforce Identity
- + Generic support for SSO systems that use SAML 2.0
- OAuth2
- AWS Cognito (view setup guide)
- Google Apps
- Windows Account
- Other OAuth2 supported Identity Providers
Self Registration
Self Registration is an IAM best practice because it supports password self-management, consistency and standardization, and security compliance through logs.
Equally, self registration also enhances user experience and decreases administrative overhead.
Administrators can customize the registration process and requirements through Login Pages.
Logs and Reporting
All user activity is logged in the Admin Portal. Admins can track major user actions such as course purchasing in the User Manager Timeline.
Admins can also track progress through LMS content in Activity Reports. By tracking these LMS events, Admins can verify and audit user activity in the event of a breach.
User Experiences
IAM protocols also include standardization of certain user experiences to ensure all users have access to the LMS services.
Accessibility
Tovuti has implemented many accessibility standards to make sure that users of all skill and ability level can access learning content. These options include but ar not limited to:
- Keyboard Navigation
- Color Contrast
- Text-to-Speech
- Closed-captioned Videos
- Image Accessibility
E-Signatures
For some learning content, Admins may want to collect authorization or agreement from users. This can be used for Employee Handbooks, Terms of Use Agreements, and many other required documents.
Admins can accomplish this through including and E-Signatures within Lessons.
This authorization is essential in industries that require certification or accreditation and may be suggest to audits.