Secure Use of Canvas LMS

Audience

Faculty • Staff • Adjuncts • Instructional Designers

Summary

This guide explains how to use Canvas securely, protect student data, manage course content safely, and avoid common LMS‑related security risks.

When You Should Use This Guide

  • You create or manage Canvas courses

  • You upload assignments, grades, or student information

  • You use third‑party LTI tools

  • You share course materials with colleagues or students

Security Context

Canvas contains FERPA‑protected student data, including grades, submissions, analytics, and communications. Proper configuration prevents unauthorized access and data exposure.

Step-by-Step Instructions

1. Use Secure Login Practices

  • Always log in through the Bellevue College's Canvas page

  • Ensure MFA is enabled on your BC NetID account

  • Avoid saving passwords in browsers

2. Manage Course Access Carefully

  • Faculty should verify enrollment lists regularly, Interactive eLearning staff can assist if there are enrollment errors.

  • Faculty should restrict TA/Designer permissions appropriately, Interactive eLearning staff can assist.

3. Faculty Must Protect Student Data

  • Use Canvas Gradebook and SpeedGrader

  • At all costs, avoid downloading gradebooks 

  • If you download rosters or gradebooks, delete local copies after use

  • Do not upload files containing Social Security numbers, credit card numbers, personal contact or personal medical information

4. Use Approved LTI Tools Only

  • Third‑party tools must be reviewed and vetted by IT for integration, security and accessibility issues

  • Avoid installing unapproved plug‑ins

  • Check permissions requested by external tools

5. Secure File Sharing

  • Use Canvas Files for course materials

  • Avoid sharing FERPA data through Canvas Announcements

  • Use OneDrive/SharePoint for departmental collaboration

6. End‑of‑Term Cleanup

  • Remove outdated files

  • Unpublish sensitive content

  • Verify grades are submitted through official channels

Common Mistakes to Avoid

  • Posting grades in announcements

  • Sharing course links publicly

  • Using personal email for Canvas communication

  • Uploading rosters with sensitive data

Examples 

  • Faculty accidentally sharing a gradebook file in course Files

  • Students accessing outdated course content

  • Unapproved LTI tool requesting access to student submissions

Troubleshooting

  • Students can’t access content: Check module publish settings

  • Gradebook errors: Re‑sync with SIS if applicable

  • External tool issues: Contact IT for review

How to Request Assistance

 Submit a Ticket

You can submit a ticket anytime through our Service Catalog

 425-564-HELP (4357)

We are available by phone during standard service hours

 Email 

Send an email to servicedesk@bellevuecollege.edu anytime and we will get back to you

 B 233

Come by the Service Desk in the B building on Main Campus, room 233, for in-person assistance