Key Takeaways:
-
Start planning your LTI 1.3 migration now. Identify older integrations, assign responsibility for updates, and allow time to test connections and course links before provider deadlines.
-
Make security an ongoing team effort. Regular monitoring, training, access reviews, and updated procurement practices help protect learning environments. Explain how added “security friction” supports those protections.
-
Adopt AI with clear boundaries. Understand what information AI can access, what actions it can take, and where human oversight is needed. Transparency and thoughtful permissions support more confident adoption.
Students and educators need to feel safe when entering a digital learning environment. Protecting those environments means keeping connections between digital tools secure and up to date, reviewing who has access to those tools, and helping people understand the decisions that keep their information safe.
That work takes time. Updating an integration or changing a familiar process can involve technology teams, providers, administrators, and educators. Starting early gives everyone more room to make those changes while keeping learning on track.
That was a central message of 1EdTech’s recent Labs Live discussion, “LMS Security: This Is What Shared Responsibility Looks Like.” Representatives from Blackboard, D2L, and Instructure came together to discuss their transition to more secure learning tool connections and the broader work needed to protect learners and educators.
Across the conversation, one point was clear: whatever platform an institution uses, security depends on people working together.
Start planning for LTI 1.3 now
Learning Tools Interoperability® (LTI®) is the 1EdTech standard that connects learning tools to a learning management system. Moving to LTI 1.3 strengthens the security of those connections.
During the discussion, all three providers described plans to move away from older LTI versions, with major milestones in 2027:
- Blackboard: New LTI 1.0 and 1.1 tool registrations will no longer be permitted beginning January 1, 2027. Existing integrations can continue operating until their retirement on September 30, 2027.
- D2L: Brightspace is taking a phased approach. Its published plan ends new LTI 1.1 configurations through the user interface in February 2027 and stops existing LTI 1.1 launches by October 2027.
- Instructure: During the webinar, Instructure described plans to complete remaining internal migrations in 2026 and support customer and partner transitions during 2027. Its published guidance states that full retirement of legacy LTI support will not happen before December 2027, with additional details to follow.
Institutions and providers should identify integrations that still use older LTI versions, including internally developed tools, and determine who is responsible for updating them. Confirm with each provider or internal team whether existing course links will update automatically or need to be recreated as part of the migration.
Also, remember that just because a tool has an LTI 1.3 version available, it does not mean every existing connection has been migrated. Allow time to test the transition and communicate any changes educators will need to make.
1EdTech offers several resources to help with these migrations:
- 1EdTech’s LTI Audit Toolkit will help you audit your current integrations.
- The Standards Portal provides open access to specifications.
- The Build Portal gives members tools to test their implementations.
Build security into everyday work
All three providers agreed that more secure connections are part of a broader, ongoing commitment to security. That work includes secure product development, regular testing and monitoring, incident response planning, staff training, and careful control over access to customer environments.
They also agreed that stronger protections can create “security friction,” extra steps or limits in familiar processes, such as additional permission checks, administrator approval of new applications, or restrictions on customization. Explaining the purpose of these changes helps educators and administrators understand how that friction protects the learning environment.
Finally, procurement teams have an important role to play. The providers recommended reviewing RFPs each purchasing cycle to reflect current security practices and focus on what users need to accomplish. Outdated technical requirements can limit providers’ ability to meet those needs securely.
Bring the same care to AI
AI adds urgency to these conversations, while also making careful, thoughtful decisions even more important.
Panelists emphasized the need for transparency about how, where, and why AI is being used. Institutions should be able to ask what information an AI tool can access, what actions it can take, and where human review is required.
As AI agents gain the ability to act on someone’s behalf, permissions deserve particular attention. The appeal of automation should prompt careful discussion about how much authority a tool needs and how that authority will be controlled.
Taking time to understand those choices helps institutions adopt AI with greater confidence.
Educators and technology providers are encouraged to join an ongoing discussion on a trusted portable learning context with 1EdTech. You can learn more about it here, and take a few minutes to fill out the surveys to help us understand the community’s needs around AI.
The next steps are practical: inventory older integrations, coordinate migration plans, review access and procurement requirements, and bring more people into the security conversation.
Change takes time. Working together helps us make that time count.
Watch the webinar and explore resources from 1EdTech and the participating LMS providers.
About the Author
Jacques Menasche is the Manager of Technical Programs & Strategic Initiatives at 1EdTech Consortium, where he bridges high-level strategy and complex technical architecture across core initiatives like LTI, AI, and 1EdTech Labs. With a career spanning 15 years in education technology, he brings deep expertise in K-12 district systems and vendor ecosystem architecture, specializing in turning complex interoperability standards into seamless tools for learning.
After earning his B.S. in Computer Science from Florida Atlantic University, Jacques built his career at the intersection of technical strategy and education. Outside of work, he can usually be found walking his two dogs, hunting down a great dark roast coffee, or relaxing with a strategic board game or a good book.