Skip to main content
Blackboard Help

Authentication Framework

The Blackboard Learn authentication framework enables users providing ID and password credentials to validate and initiate a session in Blackboard Learn. The framework also enables integrating Blackboard Learn with one or more external authentication providers.

The Blackboard Learn authentication framework is provided using Building Block technology with full user interface installation, management, and logging. This use of Building Blocks to provide authentication integration removes barriers and issues with system management related to custom authentication.

Authentication providers

Blackboard Learn SaaS includes five providers by default.

  • Learn Internal: This is the default authentication provider. You can make it Inactive, but you cannot delete it.
  • Learn Legacy: This represents the provider configured before SP8 installation and is listed automatically.
  • CAS: This represents an external Central Authentication Service (CAS) provider.
  • LDAP: This represents an external Lightweight Directory Access Protocol (LDAP) provider.
  • SAML: This represents an external Security Assertion Markup Language (SAML) provider.

In the authentication framework, you can map authentication providers to one or more hostnames. The following table provides an example of mapping hosting names.

Hostname Log a User With LDAP education provider CAS medicine provider Learn Internal provider


Provider order

You arrange the providers in order of preference enabling an authentication cascade where each provider is sequentially queried until a user is logged in or fails to be authenticated. Users are only passed through to the next provider in the chain when two conditions exist:

  • The provider does not know the username, for example, known usernames with bad passwords do not fall through.
  • A provider error occurs and error fall-through is enabled.

You want to set provider order to use for failover if one of the providers' sources is broken. For example, if you have three LDAP servers, the authentication framework checks the first server, and if that fails, checks each server until authentication is achieved.

To reorder the providers, use the drag-and-drop function available on the Provider Order page. Press and drag the providers into descending order, from top to bottom.

More on Provider Order

Note: Providers are skipped if they do not match the set of rules that the authentication framework is checking. For example, if a user is logging in using the hostname and the first two providers listed are mapped to and, the first two providers are skipped.

The Legacy provider

Blackboard recommends creating new authentication providers using the Building Block authentication framework and rewriting any custom authentication modules to use the new framework. If this is not viable, you can use the legacy framework to manage authentication.

The Legacy Authentication Provider type bypasses the Building Block authentication framework introduced in Blackboard Learn SP8. Making this provider Active makes all other providers in the authentication framework Inactive.

Webserver (web delegation) authentication has not been created in the new framework along with other partner authentications such as Datatel. If needed, you can manage these using the Legacy Authentication Provider using the and files.

More on Authentication for Blackboard Learn SP 7 and Earlier

More on Legacy Authentication Provider