Integrating LanSchool Air with Microsoft Entra ID

Integrating LanSchool Air with Microsoft Entra ID

To request this feature be enabled for your LanSchool Air organization, please contact the Customer Success team.

Overview

This article explains how to integrate LanSchool Air with Microsoft Entra ID (formerly Azure Active Directory) for Single Sign-On (SSO) and User Provisioning.

With this integration, instructor accounts can be automatically created and activated in LanSchool Air when created in the organization's Entra ID environment. Only Entra ID users associated to the provisioning application in Entra ID will be provisioned to LanSchool Air.  Email invitations and activations are not required when users are provisioned from Entra ID.

Once instructors are provisioned to LanSchool Air from Entra ID, they will be automatically enabled for Single Sign-On using their Microsoft account. After entering their email address on the LanSchool Air sign-in page, they will be automatically forwarded to Microsoft for authentication.

Prerequisites

  1. Single LSA Org for all users (customers will multiple orgs are not supported at this time)
  2. Site Admin account in LanSchool Air
  3. Admin access to Microsoft Entra ID
LanSchool Air's Entra ID integration only supports integrating with one LanSchool Air organization per Entra ID domain. If your organization has multiple LanSchool Air organizations, only one of them may be integrated with Entra ID at this time.

Creating an Enterprise Application in Microsoft Entra ID

  1. Log into LanSchool Air as Site Admin.
  2. Click on the menu at the top left then click LanSchool Air Settings.



  3. Click on SSO Configuration.



  4. Click Generate New. The system generates a random secrete token. Click Copy.

  5. In a separate browser window or tab, log into Microsoft's Entra ID Portal at https://portal.azure.com/

  6. Click on Entra ID. A page show your organization's name displays.



  7. Click on Enterprise Applications.



  8. Click on +New Application.



  9. Search for LanSchool Air in the Search Application box.



  10. If needed, rename the application and select Create.

  11. Click on Provisioning in the left navigation menu.



  12. On the Provisioning page:
    1. Select Get Started.
    2. Select Automatic from the Provisioning Mode drop-down list.
    3. Paste or enter one of the following URLs into the Tenant URL field:
      1. For Americas: https://api-lsa.lenovosoftware.com/0/lsa/common/scim
      2. For EMEA: https://api-lsa-emea.lenovosoftware.com/0/lsa/common/scim
      3. For APAC: https://api-lsa-apac.lenovosoftware.com/0/lsa/common/scim
    4. Copy the secret token from LanSchool Air (see step 4) and paste it into the Secret Token field.
    5. Click Test Connection.
    6. Click Save and close the Provisioning Page.




Configuring SAML Authentication

  1. While still in Entra ID, click on Single sign-on in the left menu.



  2. Click the SAML tile.



    The LanSchool Air gallery app has default identifier and reply URLs that are for the Americas environment. If your organization is not in Americas you will need to edit the identifier and reply URLs to correspond with the environment your LanSchool Air organization is in. 


  3.  If your LanSchool Air organization is in Americas select Yes, to save the single sign-on setting. Continue to Step 7.



  4.  If your LanSchool Air organization is not in Americas select No, I'll save later and continue to the next step.



    The next step is only if your organization is NOT in Americas. To identify what environment your organization is in, check the URL for LanSchool Air. If your URL begins with lanschoolair-emea or lanschoolair-apac, then your organization is NOT in Americas.

  5. From the Basic SAML Configuration tile, click the Edit icon. 



  6. Configure the settings as follows:
    1. Delete the URL that is already in the Identifier (Entity ID).
    2. Paste one of the following URLs into the Identifier (Entity ID) field and mark as Default:
      1. For Americas: https://api-lsa.lenovosoftware.com/0/lsa/common/saml/sp
      2. For EMEA: https://api-lsa-emea.lenovosoftware.com/0/lsa/common/saml/sp
      3. For APAC: https://api-lsa-apac.lenovosoftware.com/0/lsa/common/saml/sp

    3. Delete the URL that is already in the Reply URL (Assertion Consumer Service URL).
    4. Paste one of the following URLs into the Reply URL (Assertion Consumer Service URL) field:
      1. For Americas: https://api-lsa.lenovosoftware.com/0/lsa/common/saml/acs
      2. For EMEA: https://api-lsa-emea.lenovosoftware.com/0/lsa/common/saml/acs
      3. For APAC: https://api-lsa-apac.lenovosoftware.com/0/lsa/common/saml/acs

    5. Click Save, and then click X in the top right after saving. If a message that asks if you want to test displays, click No, I’ll test later.



  7. From the SAML Signing Certificate section of the Set Up Single Sign-on with SAML page, copy the URL from the App Federation Metadata URL field.



  8. Return to the SSO Configuration page in LanSchool Air.
  9. Paste the URL into the App Federation Metadata URL field and click Update.


Disabling Confirmation Emails

When instructor accounts are created a confirmation email will be sent to instructors with a link directing them to the LanSchool Air login page. If you want instructors to use a SSO portal login page and not be directed to the LanSchool Air login page in the confirmation email, you can choose to not send confirmation emails. 


Enabling User Account Provisioning

  1. Return to Entra ID, and then click Users and Groups from the left menu.



  2. Click +Add User/group.



  3. Click None Selected under Users and groups.
  4. Search for a new user(s) and click Select.
  5. Click Assign.
  6. Click Provisioning in the left pane.
  7. Select Start Provisioning.

Removing Entra ID Integration

  1. Log into LanSchool Air as Site Admin.
  2. Select the menu at the top left and go to LanSchool Air Settings.



  3. Select SSO Configuration.



  4. Select Remove Connection at the bottom.



  5. Type 'Confirm' and select Remove Connection.


  6. All user accounts that were provisioned in LanSchool Air from Entra ID will be deleted.

Entra ID FAQ

How do users sign into LanSchool Air?

Assigned users will log into LanSchool Air with Single Sign-On using their Entra ID credentials.  To confirm a user was assigned, in LanSchool Air go to Settings>People. The user will appear with Entra ID listed under Source.

Users with "LanSchool Air" listed as the source will continue to login with their LanSchool Air password and not Entra ID SSO.

How often does Entra IDprovision users?

Users will be added/removed every 40 minutes (by default).  To immediately provision users, select Stop Provisioning and then select Start Provisioning.

What happens if a user is deleted in Entra ID?

If a user is deleted in Entra ID, the user will appear as "disabled" in LanSchool Air for 30 days and then deleted.

What happens if a user is unassigned from the app in Entra ID?

If a user is unassigned from the app in Entra ID, the user will be disabled in LanSchool Air.

What if there are local user accounts in LanSchool Air?

If you already have local users in LanSchool Air, with Source listed as "LanSchool Air" under Settings>People, you will first have to delete the local accounts before assigning the user to the app in Entra ID.

Deleting the local account(s) will remove all manually created classes and the user will have to recreate them once signed in using their Entra ID credentials.

It is recommended to keep one or two local Site Admin accounts in your LanSchool Air organization to prevent being locked out of LanSchool Air in case something happens to Entra ID.


    • Related Articles

    • Managing Instructors and Site Admin Accounts

      Overview When your LanSchool Air organization is first created, it contains a single user account. This account is assigned the Site Admin role. One of the primary tasks of the Site Admin is to invite other users to use LanSchool Air. These users can ...
    • LanSchool Air Release Notes

      LanSchool Air Release Notes Updates to LanSchool Air are applied automatically and rolled out globally over a period of 1 to 2 weeks, so the latest updates noted in the release notes might not be available in your region for a few more days. ...
    • LanSchool Air Setup Guide

      Who Should Use this Guide? LanSchool Air site administrators responsible for installing LanSchool Air on student devices, configuring admin settings, and inviting instructors. What Does This Guide Cover? This guide provides instructions for: ...
    • LanSchool Air User Guide

      Who Should Use this Guide? Teachers who have received an invitation from a site admin to create a LanSchool Air account Site admins who are setting up an account for a teacher What Does this Guide Cover? This guide provides instructions for: ...
    • Deploying LanSchool Air Using Intune

      Overview The LanSchool Air for Windows agent supports using our LanSchool Air installer. Please note that our support team can only provide limited assistance with configuring your organization's Microsoft Endpoint Manager. The LanSchool Air Intune ...
    • Popular Articles

    • Viewing Student Client Status

      Overview If a student device is appearing as offline, check the status of LanSchool Air client installed on the student's device to make sure it's provisioned and connected. This will provide direction on where to begin troubleshooting. Viewing ...
    • Using Web Limiting

      Overview To block troublesome or distracting websites or limit students to a select few websites pertinent to the class, use the Web Limiting feature in LanSchool Air. There is currently no limit on the number of URLs that can be added to the block ...
    • Mass Deploying LanSchool Air for Chromebook Student

      This guide walks site administrators through the process of deploying the LanSchool Air app to students using Chromebooks and getting LanSchool Air ready for instructors to use. For information on installing the LanSchool Air app to Windows or Mac ...
    • Controlling Student Browser Tabs

      Overview Controlling browser tabs is currently supported for students using Chromebooks. Students on Windows or macOS devices will only display the most recently viewed website. In List View and Student Details, you have added controls over tabs on a ...
    • Using Blank Screen

      Overview LanSchool Air's customizable Blank Screen feature enables you to push a Blank Screen to your students' computers. When you enable Blank Screen, students are not able to view or listen to anything on their device until the Blank Screen is ...
    • Recent Articles

    • End of Life Lenovo V2 VR Integration with LanSchool Air

      As of March 31, 2024 Lenovo V2 VR integration with LanSchool Air has reached End of Life. Please see Lenovo VR Classroom for more information about VR learning solutions.
    • Viewing Web History

      Overview LanSchool Air preserves a 45 day record of student web history. This record can help instructors keep track of what sites students are using and if they are remaining on task. Web history can be viewed by Instructors and co-teachers in the ...
    • Disabling Edge Split Screen

      Overview LanSchool Air is unable to limit the web in Microsoft Edge when the student uses the Edge Split Screen feature. The LanSchool Air extension does not register the second screen and will not block the website. It is recommended to disable Edge ...
    • Resolving Installer Download Issues for LanSchool Air

      Overview This article serves as a supplementary guide to the articles Installing LanSchool Air for Windows Student and Installing LanSchool Air for Mac Student. If you encounter challenges during the download process on the student machine, ...
    • Accessing Chat History

      Overview Chat history preserves a 45 day record of interactions between students and instructors. This record can be valuable for administrative purposes, tracking student progress or addressing any concerns. Chat history allows LanSchool Air admins ...