About third-party authentication

2026-07-22Last updated

Third-party authentication uses a trusted, external identity provider to validate user credentials before granting access to one or more IT systems. The authentication process returns identifying information, such as a username, that is used to authorize or deny the requested access.

What is an identity provider?

An identity provider is a trusted external system that manages user accounts. It authenticates users and provides identity information over a distributed network to applications that depend on it.

Benefits of using an identity provider

Using an identity provider has the following benefits:

  • Advanced authentication requirements, such as using smartcards or Multi-Factor Authentication (MFA), can be imposed to increase confidence that a user is who they say they are.
  • User deactivation is aligned with the customers' own internal policies. For example, when an employee leaves the company or is on an extended leave of absence.
  • Separates the authentication process (verifying identity) from the authorization process (granting access rights).
  • Using single sign-on (SSO), one user authentication can grant access to multiple IT systems or even organizations.
    Note:
    Security Center SaaS only uses an external identity provider for user authentication. Authorization is handled internally.

What third-party authentication methods does Security Center SaaS support?

Security Center SaaS supports the following third-party authentication methods:
  • Microsoft Entra ID (using OpenID Connect)
  • OpenID Connect (OIDC) compliant identity providers (such as Okta, OneLogin, Google Workspace, PingFederate, and so on)
Note:
Security Assertion Markup Language (SAML) is not supported.

Single sign-on (SSO)

Single sign-on (SSO) is the use of a single user authentication for multiple IT systems or even organizations. Organizations can integrate their corporate identity provider with Security Center SaaS to simplify the sign-in and authentication process. This gives you greater control over authentication policies such as the identity life cycle, multi-factor authentication (MFA) requirements, password complexity rules, and so on.

SSO integration uses our shared login.genetec.com authentication service, which enables end users to use a single set of credentials to access all Genetec™ cloud-based products and customer service portals. Using the new integration, your users can sign in to the following:
  • Security Center SaaS
  • Genetec™ Airport Badging Solution (ABS)
  • Genetec ClearID™
  • Genetec Clearance™
  • Genetec Cloudrunner™
  • Genetec Operations Center
  • Genetec Portal (genetec.com)
Note:
Corporate SSO is only available in the Security Center SaaS Premium Plan.