Additional SSO Options (OIDC with SCIM)
NWEA needs to build additional integrations for authentication and user provisioning into NWEA MAP Growth. Currently the only two options for SSO are Clever and Classlink. However a system with as sensitive of data as NWEA, there needs to be configuration for a fully fledged IdP such as Okta. Ideally this configuration would be via OIDC and also support user provisioning via SCIM. Currently all user account creation is managed manually, which can leave behind stale user accounts that pose security risks. Further, there is no native way within NWEA's user management portal to enforce MFA. If NWEA were to support a fully-fledged IdP, automate user provisioning and deprovisioning can be fully automated, as well as enforcement of MFA via the IdP's security policies.