Enterprise single sign-on
Connect ThreatPrevent to your workforce identity provider using OpenID Connect. Employees can use their company identity for the customer portal and browser extension.
Portal
Owners, administrators and users sign in through the organisation identity provider.
Browser extension
The extension opens the system browser for authentication and receives a short-lived one-time exchange code.
API access
API keys and OAuth 2.0 remain separate controls for applications calling ThreatPrevent APIs.
Before you start
- ThreatPrevent organisation owner or administrator access
- Identity-provider administrator access
- Control of the organisation's email domain and DNS records
- At least two organisation owners or administrators available for recovery testing
- Users created or invited in ThreatPrevent; just-in-time provisioning is not currently enabled
Configuration path
Register the application
Create the identity-provider application and add ThreatPrevent's exact callback URI.
Add the provider
Enter its issuer, client ID and client secret in Organisation SSO.
Test and activate
Verify OIDC discovery before activating the provider.
Verify the domain
Publish the DNS TXT challenge shown by ThreatPrevent.
Test users
Complete portal and extension sign-in tests before enforcement.
Schedule enforcement
Use the mandatory seven-day grace period to finish rollout.
Follow the application-registration guide.
Test the complete flowValidate portal, extension and recovery access.
