one.iu.edu serves as a central portal for Indiana University students, faculty, and staff, providing access to campus systems and third-party integrations. This overview explains how third-party services connect through one.iu.edu and what users need to manage those connections securely.
Below is a structured summary of authentication flows, supported third-party categories, and data handling expectations for one.iu.edu third party relationships.
| Integration Type | Supported Third Parties | Authentication Method | Data Shared |
|---|---|---|---|
| Learning Tools | Canvas, Zoom, Respondus | Shibboleth + MFA | Name, email, IU ID, course enrollment |
| Productivity Apps | Microsoft 365, Google Workspace | OAuth 2.0 + SSO | Email, calendar, files (with consent) |
| Research Platforms | GitHub, Tableau, SPSS Cloud | API Keys + SSO | Directory attributes, project metadata |
| Student Services | Banner, PeopleAdmin, Workday | SAML + MFA | Student ID, major, financial aid status |
Learning Tool Integrations
Third-party learning tools accessed via one.iu.edu must comply with IU security policies and FERPA requirements. Instructors can connect tools such as Zoom and Respondus directly through the portal, enabling seamless single sign-on for students.
Each tool integration uses Shibboleth authentication with multi-factor authentication to verify identity. Detailed configuration guides help IT administrators control which domains and data elements are released to these applications.
Productivity App Connectivity
Many productivity apps are approved for use with one.iu.edu and leverage OAuth 2.0 for delegated access. Users can link their IU account to Microsoft 365 or Google Workspace without sharing their credentials directly with the third party.
Scoped permissions ensure that only necessary data, such as email and calendar events, is accessible. Administrators can review and revoke connected app permissions from the IU account security dashboard.
Research and Development Platforms
Researchers often rely on third-party platforms like GitHub and Tableau, which integrate with one.iu.edu using secure API tokens and SSO. These integrations enable reproducible analysis while maintaining centralized identity management.
Institutional controls allow selective exposure of directory data, protecting sensitive attributes unless explicitly required for the research workflow. Logging and audit trails help monitor access to shared resources.
Student Services Systems
Core student services systems, such as Banner and Workday, connect through one.iu.edu using SAML-based authentication with multi-factor verification. This setup supports secure access to sensitive information like grades and financial aid details.
Role-based access policies ensure that students and staff see only the data necessary for their responsibilities. Regular reviews of connected services strengthen compliance and reduce long-term risk.
Security and Management Recommendations
- Review connected third-party apps at least quarterly via the IU account portal.
- Enable multi-factor authentication for all one.iu.edu linked services.
- Limit data sharing to only the attributes required for the intended workflow.
- Prefer applications that support institutional sign-on and audit logging.
- Follow IT security guidance when integrating custom or internal tools.
FAQ
Reader questions
How does one.iu.edu authenticate third-party applications?
Third-party applications are authenticated using Shibboleth, SAML, or OAuth 2.0, combined with multi-factor authentication, depending on the integration type and required permissions.
What personal data is shared with third-party services through one.iu.edu?
The data shared typically includes name, email address, IU ID, and role information, and may include course or directory data when explicitly authorized for the service.
Can students manage which third-party apps access their IU account?
Yes, students can review and revoke connected app permissions through the IU account security dashboard, controlling ongoing third-party access.
What should users do if a third-party app requests excessive permissions?
Users should deny or revoke access and contact the IT help center, because overly broad permission requests may indicate misconfigured or risky integrations.