Launching your Canvas instance was a huge milestone which required significant time, departmental coordination, policy alignment, and technical integration. If you were part of your original implementation team, you likely remember the amount of effort you and your team placed into ensuring every setting and level of access was specifically tailored to your institution’s needs.
Over time, the focus of your instance moved from deployment to long term governance. If your institution is like many others, personnel changed, academic policies updated, and new integrations were built and introduced to your instance. Without routine evaluation, settings can drift leading to new variations of user access the original implementation team didn’t account for. By routinely reviewing your settings, you have the opportunity to ensure your system remains fully optimized for academic success.
In this post, we’ll highlight authentication and course data best practices to ensure the health of your Canvas instance is the best it can be.
Strengthening Access: Authentication and Multi-Factor Authentication (MFA)
Utilizing trusted institutional Single Sign-On (SSO) systems ensures that users are tied directly to your primary identity management system. When you federate authentication through protocols like SAML or OpenID Connect, you reduce the overhead of managing separate credentials within Canvas and ensure that account access terminates automatically when a user leaves the institution. Further, our implementation team recommends pre-provisioning users rather than enabling Just in Time Provisioning in order for administrators to have the greatest control over user logins.
Beyond SSO, we recommend using multi-factor authentication (MFA) to provide a beneficial layer of verification for all accounts (or at least administrator accounts). Canvas native authentication requires administrators to use MFA authentication. If your primary identity provider does not enforce MFA globally, you can leverage MFA within Canvas to add this requirement for all users in addition to admins.
Suggested resource:
How do I configure third-party authentication providers for a Canvas account?.
Governing API Token Access
Personal access tokens allow users to interact directly with the Canvas API. This can be a great tool for admins to create integrations, send data to Canvas, create custom reporting, or automate tasks within and out of Canvas. Unmonitored token generation can introduce unexpected variables into user access and data management. In addition, personal access tokens can provide an opportunity for learners to connect tools that violate academic integrity policies.
By default, any user in your Canvas instance can generate an API key. We recommend that you limit personal access token creation to Admins. The Limit personal access token creation to Admins checkbox can be enabled to allow admin with the Users-Manage Access Token permission to generate access tokens.
As a reminder, a personal access token inherits every single permission that the user's account holds. If it’s been a while since reviewing user roles and permissions, take some time to check that the current settings match what your institutional policies dictate.
Suggested resources:
How do I set details for an account?
What user roles and permissions are available in Canvas?
Quiz IP Filtering
Instructors spend a lot of time building quizzes, and they want to know those tests are being taken fairly. Canvas has a helpful feature that simplifies this by using quiz IP filters. By enabling Quiz IP Filtering on a Classic or New Quiz, instructors can restrict access to a quiz to a specific campus location like a testing lab.
Setting IP Filtering up is straightforward, but formatting matters in Classic Quizzes. Checking these numbers ahead of time prevents accidental lockouts and keeps exam day running smoothly for everyone. Within New Quizzes, instructors can input the IP address range themselves, or choose from an existing group in a dropdown menu.
Suggested resources:
What options can I set in a quiz? (Classic Quizzes)
How do I manage settings for a quiz in New Quizzes?
Content Security Policy (CSP)
The Content Security Policy within your instance’s administrator settings allow you to control which 3rd-party tools can run JavaScript in your environment. You can manually add up to 50 domains to your allowed list (Canvas, Instructure, and LTI tool domains are automatically added and do not count towards your limit).
Suggested resource:
How do I manage the Content Security Policy for an account?
A Final Word
Optimizing your Canvas instance is an ongoing commitment. The settings your team established during initial implementation and onboarding do require regular maintenance and evaluation to protect your users and academic workflows.
Rest assured, your Instructure team is here to support! If you want to ensure that your settings align with best practices, it’s been a while since you’ve reviewed your settings, or you’ve had significant admin turnover, our Canvas Continuity Check service provides a detailed evaluation of your instance. We can review your goals, access to controls, and verify your data workflows. Additional consulting is available beyond the Continuity Check to dive even deeper into the findings of the report. Reach out to your Customer Success team today to learn more!