Feature

Single sign-on

One sign-in for every application your team uses, assigned by role rather than person, with every sign-in recorded.

  • SAML 2.0, OIDC and OAuth 2.0
  • Browser extension for apps with no SSO
  • Assigned by role, group or department
  • Every sign-in in the audit log

What it does

Publish an application once

Register the app in Besecure, choose how it signs people in, and assign it. That work is not repeated for each person who needs access.

One launcher for your people

Employees open everything they have been granted from a single screen — no password per application, and no bookmark folder that goes stale.

Applications that speak no protocol still work

Where an application supports no federation at all, the Besecure browser extension signs people in. The same launcher, the same access rules, the same audit trail.

Access follows the organisation

Grant by role, group or department rather than per person, so a new starter inherits the right access on their first day instead of raising four tickets.

Setting it up

What the rollout looks like

Register the application

Add it in Besecure and choose the protocol it supports, or the browser extension if it supports none.

Exchange the details

Give the application your Besecure sign-in URL and signing certificate, and enter its reply URL in Besecure.

Assign it

Attach the application to the roles, groups or departments that should have it.

Test, then roll out

Verify with a single account before releasing it to everyone.

Questions about single sign-on

What about applications that support no single sign-on?

They are reached through the Besecure browser extension, an approach the identity industry calls Secure Web Authentication. People open them from the same launcher, access is granted by the same roles and groups, and every sign-in lands in the same audit log.

Does Besecure replace our directory?

No. It connects to the directory you already run and treats it as the source of truth for who works here.

What do employees actually see?

One sign-in, then a launcher listing only the applications they have been granted. Anything they cannot reach does not appear on it.

One sign-in for every app your team uses.

Set up your organisation, connect your directory and give your people a single secure launchpad.