OAuth
Seamless login with existing identity providers
Short answer
OIDC and SSO connect intraOnline to your identity provider and allow signing in without a separate intraOnline password.
Definition
intraOnline supports single sign-on through OpenID Connect using the authorization code flow with a client secret.
Configuration needs the issuer URL, client ID, client secret and redirect URL.
Optionally the groups claim can be used to assign groups automatically at SSO login.
Without central SSO
Accounts are maintained twice, sign-in is error-prone and security policies are hard to enforce.
With OIDC/OAuth in intraOnline
Sign-in runs through the existing IdP, identity data stays consistent and groups can be synchronised automatically.
How it works
Most modern standards
Supports OAuth 2.1 and OpenID Connect for secure authentication.
Take on roles
Synchronize groups or roles from your identity provider.
Hardening
Centrally define security policies such as MFA or allowlists.
In practice: signing in through Entra
An organization sets up Entra as its OIDC provider, enters the client data and enables the groups claim. At SSO login the user data is taken from the ID token and group assignments are updated according to the mapping. Changes in Entra take effect at the next sign-in. Groups assigned manually in intraOnline stay untouched.
Benefits
- Less account and password upkeep day to day
- Consistent user data through the central IdP
- Optional automatic group assignment at login
- A better security level through standardised IdP policies
Frequently asked questions
Related topics
Implement OAuth in your organization
In a live demo, we show how OAuth fits your structure and which rollout steps bring the fastest value.
Request access