Identity Services

Set policy2 min readApplies to the Fowlguard console

SAML 2.0

Single sign-on from your identity provider, Entra ID, Okta, or any SAML 2.0 IdP. You get an SP entity ID and an ACS URL unique to your organization, and exportable SP metadata to hand your IdP.

Let people sign in with your existing identity provider. Once SAML is enabled it decides who may join, and the join rules on the Organization page no longer apply.

A custom identity provider is tied to a domain you have verified, so verify the domain first.

SCIM

Automatic user and group provisioning from your IdP, with mapping into roles and access policy, deprovisioning rules and an activity log.

Provisions and de-provisions people automatically from your directory, so that someone removed there loses access here without anyone doing it by hand.

Directory Services

Connect your own directory - Microsoft Entra, PingOne or AD - to read groups and their membership, so a group can be named as an approver, an owner or a rule audience.

Directory Services runs inside one FgMesh and reaches your directory over that mesh's own addresses. It is not a shared service: a directory added to one FgMesh is invisible to another, and two FgMeshes may hold servers on the same address without either seeing the other's.

It reads. It does not write to your directory, and it does not become the thing that decides who may sign in - that is SAML's job, or the join rules on the Organization page.

Plans

SAML 2.0, SCIM and Directory Services are on the Small, Medium and Large plans. On the Personal plan the tiles show with a padlock.

The values the console shows you

SP Entity ID is unique to your organization, and is also the metadata URL.

ACS URL is your organization's assertion consumer service — where the IdP posts its assertion.

SCIM base URL is where your IdP's SCIM connector points.

The signing certificate

Default uses a certificate Fowlguard generates and rotates. Import takes one you supply, for an organization whose identity provider is pinned to a certificate it already trusts. None signs nothing, which almost no identity provider accepts.

Something missing or unclear? Write to hello@fowlguard.com and we will add it.