Skip to main content
INTEGRATION

Connect your IAM / SSO / MFA

Identity is where most controls either hold or fail — MFA coverage, privileged access, joiner-mover-leaver hygiene. TruSecure's identity connector pulls IAM/SSO/MFA state directly, so access-control evidence comes from the directory that enforces it.

What the connector pulls

IAM / SSO / MFA data pulled into TruSecure
Source systemWhat TruSecure pullsFeeds governance
MFA enforcementMethod coverage, exclusions, conditional-access rulesControl Library · NIS2 Art. 21(2)(b) access control
Privileged accessAdmin roles, PAM sessions, standing vs just-in-timeAudit Trail · privileged-activity evidence
Lifecycle eventsJoiners, movers, leavers, orphaned accountsEvidence Automation · JML controls
SSO federationApp integrations, password policies, session settingsControl Library · authentication measures

Evidence produced from IAM / SSO / MFA data

One control test pulled from live IAM / SSO / MFA state — not a manual export, not a screenshot, but a verified query result with provenance:

Control test · IDM-2026-072 privileged accountsSample data
Control tested
Privileged accounts require MFA and quarterly review
Identity source
Microsoft Entra ID · tenant: contoso.eu
Test
re-perform · role assignments vs MFA policy
Sample
31 privileged accounts · 31 MFA-enforced, 4 unreviewed >90 days
Result
pass with exceptions · 4 reviews overdue, owners notified
Evidence
Graph API query · timestamped 2026-08-22T06:48:19Z
Export
sealed · sha256:7b3c...1e9f

Setup and scope model

  1. Read-only, scoped permission

    Connector requires read-only directory access — role assignments, MFA state, sign-in summaries. No write permissions, no ability to grant, revoke, or reset anything.

  2. Data filtered by entity

    Directory objects scoped to the entity context. Groups with several domains keep each entity's identity evidence separate.

  3. Continuous sync

    Access reviews refresh on every control test. An unreviewed admin account is flagged the day it crosses 90 days, not at audit time.

Commercial packaging

IAM / SSO / MFA connectors are part of the paid TruSecure Fabric subscription. The connector itself, the continuous sync, the evidence provenance tracking, and the mapping to NIS2, DORA, ISO 27001, SOC 2 and other frameworks are all included — no per-connector fees, no usage tiers. Pricing is scoped in the conversation, not a price list.

How integration works

A demo with your actual IAM / SSO / MFA environment shown in preview mode — your data pulling into governance, feeding controls and evidence. Then a Resilience Sprint that configures the connector for production, scopes the entity context, and validates the first evidence pull. No self-serve checkout, no per-connector pricing.

TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.