Connect your IAM / SSO / MFA
Identity is where most controls either hold or fail — MFA coverage, privileged access, joiner-mover-leaver hygiene. TruSecure's identity connector pulls IAM/SSO/MFA state directly, so access-control evidence comes from the directory that enforces it.
What the connector pulls
| Source system | What TruSecure pulls | Feeds governance |
|---|---|---|
| MFA enforcement | Method coverage, exclusions, conditional-access rules | Control Library · NIS2 Art. 21(2)(b) access control |
| Privileged access | Admin roles, PAM sessions, standing vs just-in-time | Audit Trail · privileged-activity evidence |
| Lifecycle events | Joiners, movers, leavers, orphaned accounts | Evidence Automation · JML controls |
| SSO federation | App integrations, password policies, session settings | Control Library · authentication measures |
Evidence produced from IAM / SSO / MFA data
One control test pulled from live IAM / SSO / MFA state — not a manual export, not a screenshot, but a verified query result with provenance:
- Control tested
- Privileged accounts require MFA and quarterly review
- Identity source
- Microsoft Entra ID · tenant: contoso.eu
- Test
- re-perform · role assignments vs MFA policy
- Sample
- 31 privileged accounts · 31 MFA-enforced, 4 unreviewed >90 days
- Result
- pass with exceptions · 4 reviews overdue, owners notified
- Evidence
- Graph API query · timestamped 2026-08-22T06:48:19Z
- Export
- sealed · sha256:7b3c...1e9f
Setup and scope model
- Read-only, scoped permission
Connector requires read-only directory access — role assignments, MFA state, sign-in summaries. No write permissions, no ability to grant, revoke, or reset anything.
- Data filtered by entity
Directory objects scoped to the entity context. Groups with several domains keep each entity's identity evidence separate.
- Continuous sync
Access reviews refresh on every control test. An unreviewed admin account is flagged the day it crosses 90 days, not at audit time.
Commercial packaging
IAM / SSO / MFA connectors are part of the paid TruSecure Fabric subscription. The connector itself, the continuous sync, the evidence provenance tracking, and the mapping to NIS2, DORA, ISO 27001, SOC 2 and other frameworks are all included — no per-connector fees, no usage tiers. Pricing is scoped in the conversation, not a price list.
How integration works
A demo with your actual IAM / SSO / MFA environment shown in preview mode — your data pulling into governance, feeding controls and evidence. Then a Resilience Sprint that configures the connector for production, scopes the entity context, and validates the first evidence pull. No self-serve checkout, no per-connector pricing.
TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.