Integration

SenseCrypt as an external IdP for Microsoft Entra ID

SenseCrypt works as an external identity provider (IdP) for Microsoft Entra ID. Entra ID stays your identity platform. SenseCrypt handles each sign in by face login. Entra ID federates to SenseCrypt through open standards. This is standards-based federation. It is not a proprietary connector.

On this page
  1. What this integration does
  2. Choose OIDC or SAML 2.0
  3. How you set it up
  4. What you get
  5. Frequently asked questions

What this integration does

Entra ID keeps the tenant, the directory and the policies you have already tuned. Your applications stay pointed at Entra ID. The one thing that moves is the proof of identity: Entra hands the user to SenseCrypt, the user looks at the camera on a device bound to them, and a signed token or assertion comes back.

There is no gallery application to install and no connector to run. Entra ID already trusts external identity providers over open standards, and this integration is exactly that and nothing more.

Entra ID stays the identity platform

Your Microsoft and line-of-business applications keep their existing Entra ID configuration, and Entra ID still issues the session they consume.

SenseCrypt is the sign in step

Entra redirects the user to SenseCrypt, the face ceremony runs on the enrolled device, and Entra completes the sign in from the signed result it receives.

Standards, not a connector

The trust is an OIDC or SAML 2.0 federation you configure yourself. Nothing proprietary is installed on either side, so there is no vendor agent to patch later.

Start with one group

Federation can be scoped, so a pilot group moves to face login while the rest of the directory carries on unchanged. Undoing it means removing a policy, not migrating users back.

Choose OIDC or SAML 2.0

One federation is enough. OIDC is the lighter build: Entra reads a discovery document, PKCE binds the authorization code to the client that started the flow, and pushed authorization requests keep request parameters out of the browser.

SAML 2.0 is the right call when your Entra estate already federates that way and you want this connection to look like the others your team supports. The device ceremony is the same in both. Only the envelope changes.

OIDC: discovery does the setup

The SenseCrypt discovery document publishes the authorization and token endpoints and the signing keys, so Entra configures most of the connection from a single URL and keeps working across key rotation.

SAML 2.0: exchange metadata

SenseCrypt publishes IdP metadata carrying the sign in URL and the signing certificate. Entra exports its service provider metadata back. Each side imports the other.

What comes back is signed

SenseCrypt signs every token and every assertion. Entra validates that signature against the published key before it trusts anything in the payload.

Nothing biometric crosses the wire

Capture and matching run on the user's own device. What moves is a single-use face token, and the server keeps no face image and no face template.

How you set it up

Two consoles, no installs. Most of the elapsed time goes into attribute mapping, because the claims SenseCrypt emits have to land on the right Entra ID user attributes before anything downstream behaves.

Test with a throwaway account and a real phone before you point a policy at anyone who has work to do. Enrollment is the step people underestimate.

  • Register Entra ID as a relying party in the SenseCrypt console.
  • Copy the SenseCrypt discovery URL, or download the SAML 2.0 metadata file.
  • Add SenseCrypt in Entra ID as an external identity provider.
  • Map the SenseCrypt claims onto Entra ID user attributes.
  • Scope a policy so the pilot group is routed to SenseCrypt.
  • Turn on SCIM 2.0 if you want users and groups kept in sync.
  • Enroll a test user and run one face login end to end.

What you get

You remove the shared secret instead of protecting it better. No password to phish, no one-time code for a caller to talk out of a user, no approval prompt to tap out of habit. What proves the person is a face check on a device that was bound to them.

Everything else in the platform arrives with it, because SenseCrypt is a full identity provider and not a bolt-on second factor.

Phishing loses its payload

The user types nothing at sign in, and the face token is dead once spent. A cloned sign in page ends up holding nothing worth replaying.

Read the biometric claims precisely

Liveness holds iBeta ISO 30107-3 certification at Level 1 and Level 2, which covers presentation attacks at the camera such as a printed photo or a mask. Face recognition entered the NIST evaluation in 2021, then FRVT and later split into FRTE and FATE, maintained through our latest submissions. We call that evaluation, not certification.

The platform underneath

Role-based access control, multi-tenant isolation and audit logs are included. SenseCrypt computes and emits roles and permissions in the token; your applications enforce them.

What it costs

One dollar per user per month with a 20-seat minimum. KMS signing-key custody is twenty dollars per key per month, and each tenant or custom domain past the first three is ten dollars per month. Customer identities bill as monthly active users. The 30-day trial takes no card.

Frequently asked questions

Does SenseCrypt use a prebuilt Entra ID connector?

No. SenseCrypt connects to Microsoft Entra ID through open standards only. You use OIDC or SAML 2.0 with metadata and a discovery URL.

Does SenseCrypt store biometric data on the server?

Not the face itself. Face matching runs on-device, and SenseCrypt keeps no face image and no face template. SenseCrypt uses patent-pending face tokenization, so what it holds is a sealed, single-use face token.

Does SenseCrypt replace Microsoft Entra ID?

No. Entra ID stays your identity platform. SenseCrypt works as the external identity provider (IdP) for face login.

Can SenseCrypt provision users with Entra ID?

Yes. SenseCrypt supports SCIM 2.0. You can sync users and groups with Entra ID.

Related

Retire the password, keep the person

Stand up a passwordless identity provider for your workforce and customers. Free for 30 days, no credit card needed.