Trustholm supports enterprise identity patterns for portal users: OpenID Connect and SAML 2.0 single sign-on, multi-factor authentication, role-based access control, and JWT session management with tenant binding on API calls.
Single sign-on: Configure OIDC or SAML with Entra ID, Google Workspace, Okta-style providers, or compatible IdPs. Callback routes handle federation; group claims can map to roles where configured.
Multi-factor authentication: MFA setup and verify flows ship for local and federated users per tenant policy. Security Center surfaces MFA status for administrators reviewing posture.
Role-based access control: Permissions gate UI routes and API endpoints. Packaged modules (Agent Management, Monitoring, PowerShell IDE) respect global and per-tenant enablement via module feature gates-disabled modules hide navigation and return clear errors on deep links.
JWT tenant binding: Authenticated API calls include tenant claims. Resolved tenant from headers or subdomain must match TenantId for tenant-scoped users-prevents cross-tenant data access via header manipulation.
Super Admin step-up: Platform operators use elevated roles for cross-tenant commercial and support tasks under audited access patterns. This is not a customer IdP concern but appears in vendor responsibility matrices.
Customer responsibilities: IdP provisioning and deprovisioning, conditional access policies, break-glass accounts, and periodic access reviews remain yours. Trustholm provides technical enforcement points-not governance attestation.
Module gates and least privilege: Disable packaged modules globally when not licensed to reduce attack surface. Map SSO groups to roles with least privilege for script publish versus execute separation. Review Super Admin vendor access separately in vendor risk assessments.
Session and token hygiene: Document JWT session timeout expectations and signing key rotation windows in your change control. Federation outages should have documented break-glass procedure-customer-operated, not vendor-implied SLA.
Access review integration
Quarterly export users and roles; reconcile against IdP group membership; remove stale contractors within 24 hours of offboarding ticket closure. Map module entitlements to SKU billing lines so disabled modules align with least privilege.
Super Admin vendor access should appear on enterprise vendor risk register with review cadence. Federation failure tabletop: document manual lockdown steps and communication tree-Trustholm provides authentication enforcement points, not 24/7 SOC for your IdP outages.
Federation test plan
Semi-annual IdP failover exercise: verify login denial when IdP unavailable matches runbook; verify MFA enforcement still visible in Security Center export screenshots post-exercise.
Contractor and break-glass accounts: Document separate provisioning for contractors with time-bound IdP group membership. Break-glass local accounts-if any-require enhanced audit review and quarterly attestation. Trustholm enforces roles at API boundary; your IdP owns timely deprovisioning when contracts end.
Machine versus human credential reviews: Schedule distinct access review cadences for agent polling keys and portal SSO users. Questionnaires often conflate them-split narratives in SSP data flow diagrams.
This page describes product capabilities for your control matrix. Trustholm does not hold SOC 2, ISO 27001, IRAP, Essential Eight, CMMC, Cyber Essentials, NIS2, or framework certification badges.