How to set up Azure OIDC Single Sign-On (SSO) for Kahoot!
This guide provides a step-by-step walkthrough for configuring Azure OpenID Connect (OIDC) Single Sign-On (SSO) with your Kahoot! account. By integrating Azure AD, you can streamline user access, ensure secure authentication, and improve account management for your organization.
🔗 If your organization uses SAML instead of OIDC, please refer to our guide on Azure SAML Setup.
- What do I need before starting the Azure OIDC setup?
- How do I access SSO Management in Kahoot!?
- How do I create a new Enterprise application in Azure?
- How do I add Azure Credentials to Kahoot!?
- How do I add the Redirect URL back to Azure?
- What claims are required for OIDC?
- How can I test the Azure OIDC application?
- FAQ
What do I need before starting the Azure OIDC setup?
Before beginning the configuration, ensure you have the following prerequisites in place:
- A Kahoot! Owner or Admin role with SSO & SCIM credentials provided by Kahoot!.
- Admin permissions in your organization's Azure Active Directory to create and configure an enterprise application.
How do I access SSO Management in Kahoot!?
- Log in to your Kahoot! admin account and navigate to SSO & SCIM Management.
- Click Start setup.
- Select Azure & OIDC as your identity provider.
- Keep this tab open. You will need to input your Client ID, Client Secret, and Discovery URL here shortly.
How do I create a new Enterprise application in Azure?
- Log into your Azure portal.
- Create a new Enterprise application.
-
Note on Redirect URL: The Redirect URL will be provided at the end of the Kahoot! Admin SSO & SCIM setup. If Azure requires it immediately, you can leave a placeholder value for now.
How do I add Azure Credentials to Kahoot!?
To successfully link the two platforms, you need to transfer three key pieces of information from Azure to Kahoot!.
1. Client ID
- In Azure, navigate to the Overview section of your new application and copy the Application (client) ID.
- Paste it into the Client ID field under the Kahoot! SSO & SCIM Management page.
2. Client Secret
- In Azure, go to Certificates & Secrets and generate a New Client secret.
- Copy the Secret value and paste it into the Client Secret field in Kahoot!.
3. Discovery URL
- Go to Overview, click on Endpoints in Azure, and copy the OpenID Connect metadata document URL.
- Paste it into the Discovery URL field in Kahoot!.
💡 Ensure you copy the Secret Value, not the Secret ID, as it will be hidden once you navigate away from the Azure page.
How do I add the Redirect URL back to Azure?
- After entering your three credentials in Kahoot!, copy the Redirect URL that Kahoot! provides.
- Go back to your Azure portal, navigate to Authentication, select Add a platform, and choose Web.
- Paste the Kahoot! Redirect URL and save your changes.
What claims are required for OIDC?
Please use the standard claims for OIDC.
☝️ Customizing the claims might lead to a faulty integration setup and prevent users from logging in.
How can I test the Azure OIDC application?
- Remember to completely log out of your current Kahoot! account.
- Copy the invitation link provided in your SSO & SCIM setup and paste it into your browser's address bar.
- You should be securely redirected to log in using Azure SSO.
FAQ
-
How do I connect existing Kahoot! users to the new SSO?
If your organization already had Kahoot! users before enabling SSO, simply send them the invitation link from your SSO & SCIM setup. When they log in via this link for the first time, their existing accounts will be automatically connected to SSO.
-
Can I manage and restrict user provisioning?
Yes. By default, Kahoot! SSO allows all Azure users to self-provision via the SSO link. If you want to restrict access, you must use Azure group or user access settings to limit who can sign in to the Kahoot! Enterprise Application.
-
How do users login to Kahoot! through SSO?
Each organisation will be provided with a custom URL (magic link) by Kahoot!. Users can then click that link to login using Enterprise SSO. When they click on the link, they will be asked to authenticate themselves using their existing company login credentials if they’re not logged in already.
-
What do we need to do to set up the integration with our identity management platform with Kahoot!’s SSO?
Please follow the instructions in the setup guide for your respective identity provider. You will need admin access to your identity provider to configure Kahoot! as an app.
-
What personal information does Kahoot! Require our SSO provider about the user to create an account?
In the first version we need at least a user's email address. Our systems are GDPR compliant to protect user’s privacy. Our systems are GDPR compliant to protect users’ privacy. For more information, please see our Terms & Conditions and Privacy Policy.
-
What happens to the user’s existing account if they had already signed up to Kahoot!?
If we detect that the user already has a Kahoot! account associated with their work email, their existing account will be merged to join the new organization.
During the merging process, the user must first log in via SSO and then provide their old Kahoot! password to verify their account. At this step, a special verification screen will appear:
Once the merge is complete, the user will use the Enterprise SSO magic link to sign in to their Kahoot! account going forward.
-
What happens if a user already has an active subscription?
You will want to ensure that all of your kahoots are saved in your personal folder on your account (some of the upgraded accounts also have a "team folder" where your kahoots may have been saved). If your current account is under another email, ex: a personal email, and you want that to become your SSO work account - you will first need to go to your profile settings and change your email address to your Org email, then you will be able to accept and migrate over.
-
What happens when the users in the user group are higher than the number of licenses we have with Kahoot!?
We will block the users from joining the new org and sign up and ask them to contact their administrator to increase the license count.
-
What happens to users if we want to reduce the number of licenses?
Admin will have to remove those users from the Kahoot! user group in their admin portal before they can reduce the total number of licenses. See our billing and payment terms.
-
How do we offboard users from Kahoot?
Once you have removed the user’s access from your identity provider e.g. Okta, they will no longer be able to access Kahoot! anymore. However, to vacate their used license, you will need to login to Kahoot!’s user management page to remove the user from the interface to free up that license.
💡 Found this helpful? Subscribe to our Youtube channel for more tips and Kahoot! tutorials!
0 comments
Please sign in to leave a comment.