Skip to main content
Request a Demo
topics

A recent 1EdTech Labs webinar brought together Michael Feldstein (1EdTech), Carrie Vail (D2L), Wade Weichel (Blackboard), and Melissa Loble (Instructure) to talk through the industry-wide retirement of LTI 1.1, the trade-offs vendors make to keep schools safe, and where AI is about to complicate all of it. The discussion offered practical insights into the LTI 1.1 retirement timeline, what D2L Brightspace admins need to know, security best practices and emerging AI governance challenges. 

As part of its move away from LTI 1.1, D2L has announced plans to retire support for the standard in Brightspace. Carrie Vail, Senior Director of Product Management at D2L, said the transition has been underway for several years, supported by migration tools that have helped customers and partners move applications to LTI 1.3, even complicated transitions involving millions of links. 

So why announce a hard deadline now if the tools have existed for years? According to Vail, adoption has lagged despite years of available migration tools and documented customer success stories, underscoring the reality that organizational change often takes time. She noted that many institutions continue to use LTI 1.1 even when migration paths are readily available. 

D2L is rolling the transition out in phases over the next year: 

  • February 2027: New LTI 1.1 integrations can no longer be added via the Brightspace UI 
  • March 2027: Opt-in period opens for institutions that want to disable LTI 1.1 early 
  • October 2027: LTI 1.1 launches disabled for all customers 

Vail described the plan for the months in between.  

“Over the next year, we’re staging the transition into four phases. Right now, customers and partners should be evaluating their systems for that lagging LTI 1.1 use in order to identify which migrations are still necessary. And then over the winter months, make plans for migrations or adoption of replacement tools, so that transition can be fully completed ahead of that October deadline.” 

Vail noted that institutions further along in their migration efforts may be able to shut off LTI 1.1 before its retirement. D2L expects to introduce an opt-in option as early as March to help institutions verify that all LTI 1.1 usage has been eliminated from their Brightspace environment. 

This isn’t a Brightspace-only initiative. In the same webinar, Blackboard’s Wade Weichel and Instructure’s Melissa Loble both confirmed their own LTI 1.1 retirement timelines. Blackboard plans to block new LTI 1.1 registrations after December 31 and retire existing LTI 1.0/1.1 tools after September 30 of the following year, while Instructure is targeting a 2027 transition. 

The rationale for the transition is rooted in security. LTI 1.3 replaces the shared-secret authentication model used in LTI 1.1 with modern standards such as OAuth 2.0, OpenID Connect, and public-key cryptography, providing a stronger foundation for securing integrations. 

What Brightspace Admins Can Do Now 

  • Take inventory of every LTI 1.1 tool connected to your Brightspace environment. 
  • Confirm with each tool provider whether they already support LTI 1.3. 
  • Use D2L’s migration tooling (course import, course copy, or the course migration API) to move links. Institutions such as Minnesota State and Purdue have each migrated more than a million links using these approaches.) 
  • Build your migration plan over the coming months so it is completed well ahead of October 2027. 

Security Considerations for Brightspace Admins 

While the discussion touched on industry-standard practices such as penetration testing, secure development, and compliance certifications, Vail emphasized an area where D2L takes a particularly deliberate approach: administrative control over learning environments. 

“D2L has taken a privacy-by-design approach to help protect student and educator data from the beginning. So, the way that this goes beyond technology infrastructure to our back-end processes is careful separation of customer environments. We require our own support and administrator staff to log in separately to each environment whenever that’s necessary. We also empower our Brightspace administrators to control their environments to meet the unique policies and requirements for their institution. For example, Brightspace admins fully control all of their site’s API credentials.” 

That administrative control over API credentials is intentional. Vail explained that D2L could have allowed broader access to API key creation or third-party app installation, but instead chose to centralize those responsibilities with Brightspace administrators to provide greater oversight into which applications have access to institutional data. 

Vail framed security as an ongoing operational commitment rather than a standalone initiative, noting that the constantly shifting nature of cyber threats requires organizations to stay alert and proactive every day. 

  • If you’re a Brightspace admin, recognize that API credential creation and third-party app installation sit with you by design. 
  • Keep your inventory of connected LTI tools and API integrations up to date. 
  • Review D2L’s security documentation and certifications if your institution requires compliance reporting or vendor review. 

Building a Culture of Security Awareness 

When the conversation turned to what the sector needs to tackle collectively, Vail pointed to training. 

“One of the biggest problems that I see, and I keep coming back to, is more on the people side of things. Technical staffing and resourcing within the educational community is a really high ratio of users, end users, to IT staff. And when you think about security as layered protection, it starts with those end users. And they have a lot of people that they have to support that vary greatly in their digital literacy.” 

Vail also highlighted a gap between the security training routinely received by technology professionals and what’s available to many educators, students, and parents who regularly interact with sensitive data. Her point wasn’t simply that users need more training. It was that institutions should treat security awareness as a shared responsibility, extending beyond IT teams to everyone who handles student data: 

  • Don’t assume phishing awareness is only an IT department’s responsibility. Extend training to staff, faculty, and administrators who handle student data. 
  • Enable two-factor authentication on administrator, institutional, and personal accounts wherever possible. 
  • If your institution lacks a formal security-awareness program for non-IT staff, consider raising the issue internally. 

Preparing for AI-Connected Learning Environments 

The final portion of the webinar focused on AI and what happens when learners and educators begin connecting AI-powered tools directly into learning environments. Vail characterized these as industry-wide governance questions that will require collaboration among technology providers, institutions, and standards organizations rather than any single vendor acting alone. 

“When a learner has access to multiple tools, can we work together as a community to agree on the context that’s needed for AI to provide them the best resource? What is that minimum personal information that’s necessary to give them a great learning experience? And how do we allow the end user to provide consent in that process?” 

Vail also raised questions about accountability and auditability when AI agents begin taking actions on behalf of users, emphasizing the need to distinguish between human and agent interactions. 

Michael Feldstein connected those concerns to 1EdTech’s emerging Trusted Portable Learning Context initiative and the broader evolution of interoperability standards. 

Questions to Ask Before Adopting AI Tools 

  • Before connecting any AI tool to Brightspace, understand what student data it can access and why. 
  • Ask vendors how they distinguish human actions from agent actions and whether those actions are auditable. 
  • Monitor developments around 1EdTech’s Trusted Portable Learning Context initiative and related standards work. 

The retirement of LTI 1.1 is an industry-wide shift, but for Brightspace administrators the immediate priority is clear: identify any remaining LTI 1.1 tools and establish a migration plan well before October 2027. More broadly, the webinar highlighted a common theme across security and AI governance efforts alike: technology matters, but strong outcomes depend just as much on informed processes, administrative oversight, and ongoing user education. 

Checklist for Brightspace Admins 

  • Take inventory of every LTI 1.1 tool connected to your Brightspace site. 
  • Confirm LTI 1.3 support with each tool provider and begin migration planning. 
  • Consider the March 2027 opt-in period if you want to disable LTI 1.1 ahead of the final retirement date. 
  • Reconfirm who controls API credentials and third-party app installation at your institution. 
  • Extend security training beyond IT staff. 
  • Enable two-factor authentication wherever available. 
  • Review AI tools carefully and understand what data they access and how actions are tracked. 

Want to hear more? Watch the full webinar now.  

Further Reading 

  • D2L Security: Full overview of D2L’s privacy-by-design approach and certifications. 

Written by:

Table of Contents

  1. What Brightspace Admins Can Do Now 
  2. Security Considerations for Brightspace Admins 
  3. Building a Culture of Security Awareness 
  4. Preparing for AI-Connected Learning Environments 
  5. Questions to Ask Before Adopting AI Tools 
  6. Checklist for Brightspace Admins 
  7. Further Reading 

Recommended Reading