NCEdCloud SSO — What Single Sign-On is and Why it Matters for NC Schools
What Is NCEdCloud SSO?
NCEdCloud SSO (Single Sign-On) is the authentication system that allows every North Carolina public school user to log in once at ncedcloud.mcnc.org and then access all their educational applications without entering another username or password. NCDPI’s RapidIdentity platform serves as the identity provider.
Clicking an application tile sends a cryptographically signed SAML assertion to the destination app, which trusts it and signs the user in automatically. This applies to approximately 1.5 million students and thousands of staff across 115 NC school districts. The most important thing to know is that NCEdCloud SSO handles authentication for every tile on your dashboard — one login protects and enables access to all of them.
Why SSO Matters in K-12 Education?
Before statewide SSO, students and teachers needed separate credentials for every platform. A teacher might manage five or six different usernames and passwords — PowerSchool, Canvas, Google, Discovery Education, SchoolNet, and more. Students faced the same problem. Lost credentials caused constant help desk calls. SSO resolves this by making NCEdCloud the single credential set that unlocks everything else.
How the SSO Authentication Flow Works
- User enters username and password at ncedcloud.mcnc.org.
- RapidIdentity verifies the credentials against the NC directory.
- Optionally, RapidIdentity requests MFA completion.
- A browser session is established.
- User clicks an application tile.
- NCEdCloud builds a SAML assertion containing identity attributes.
- The assertion is sent to the application’s SAML endpoint.
- The application validates the assertion signature.
- The application maps the identity to a user account.
- The user lands on the application dashboard — signed in, no password entered.
What Attributes Are Sent Through NCEdCloud SSO
The SAML assertion includes identity attributes that the application uses to identify and
| Attribute | Typical Value | Purpose |
| Username / UID | Student or staff identifier | Links to the user’s app account |
| Email address | District email | Display and communications |
| First and last name | Legal name from SIS/HR | Account display |
| Role | Student, teacher, admin | Determines permissions in the app |
| School code | LEA school identifier | Scope’s data to correct the school |
| Grade level | K-12 grade | Routes to the correct curriculum |
When NCEdCloud SSO Does Not Work
Common SSO failure scenarios and what they mean:
| Scenario | Likely Cause | Who Fixes It |
| Tile appears but shows an error on click | Expired certificate or misconfigured endpoint | LEA Administrator |
| App asks for a separate login | App not configured for SSO | LEA Administrator |
| App loads but shows wrong data | Attribute mapping mismatch | LEA Administrator |
| SSO works at school but not at home | IP restriction on the application | LEA Administrator |
| SSO breaks for all users at once | Platform-level issue or expired cert | NCDPI/MCNC |
Frequently Asked Questions
Is my NCEdCloud password sent to my apps when I use SSO?
No. SSO never sends your password to applications. Instead, it sends a cryptographically signed identity assertion. Applications verify the signature using a shared certificate and trust the identity claims without ever seeing your password.
If I change my NCEdCloud password, do I need to update it in Canvas, PowerSchool, and other apps?
No. Application access through SSO does not depend on your password — only on the signed assertion NCEdCloud generates after you log in. Change your NCEdCloud password once, and all apps continue to work through SSO.
Can NCEdCloud SSO work without an internet connection?
No. SSO requires a live network connection to complete the authentication flow between your browser, NCEdCloud’s servers, and the destination application. Offline access to any SSO-connected app is not possible through NCEdCloud.
Why does NCEdCloud SSO sometimes redirect me through multiple pages before landing in an app?
The SAML handshake involves a redirect sequence: your browser → NCEdCloud → application. Each step creates a redirect. This is normal SSO behavior and completes in under a second when network conditions are good. If the sequence stalls, it usually means a cookie was not set correctly — clear cache and retry.
Does NCEdCloud SSO work for all apps my district uses?
NCEdCloud SSO works with applications configured as service providers in the NCEdCloud admin console by your LEA Administrator. Applications that have not been configured appear as separate logins rather than tiles. Contact your LEA IT coordinator if an application you use should have SSO but does not.
Related Reading
NCEdCloud Login — Complete Guide (/ncedcloud-login/)
NCEdCloud RapidIdentity — What Powers NCEdCloud (/ncedcloud-rapididentity/)
NCEdCloud Applications — Full App Directory (/ncedcloud-applications/)
NCEdCloud MFA Setup Guide (/ncedcloud-mfa/)
NCEdCloud SSO Not Working Fix (/ncedcloud-sso-not-working/)







