Skip to main content
Whether someone signs in directly with Iru or through a provider you already run, they end up in the same place: an app dashboard of the applications they are allowed to use.

How users sign in

By default, Iru Identity is your identity provider: users sign in to Iru directly, and Iru signs them in to their apps. You can also let them sign in through a provider you already run, in specific situations. Both paths lead to the same app dashboard.

Directly with Iru (default)

The user proves who they are to Iru itself, typically with a passkey (a quick fingerprint, face, or screen-lock gesture) or the Iru Access app. No password required. This is how most users sign in.

Through a provider you already run

The user signs in with an existing provider, such as Google Workspace or Microsoft Entra ID, and Iru continues once the provider confirms them. This federated sign-in is for when you use Iru as an authentication layer into the Iru platform, or to ease a migration onto Iru Identity.
The user always proves who they are with their authenticator (a passkey or Iru Access). Iru then evaluates the relevant authentication policy before granting access. A policy can require a trusted device, so the exact prompts a user sees can depend on the app they are reaching and the rules you have set.
Federated sign-in is configured through an identity provider connection. To set one up, see Federated Authentication.

The app dashboard

Once signed in, each user lands on their own app dashboard. It greets them by name and shows the applications your organization has assigned to them.

Your Applications

Every application the user has access to appears as a tile. Selecting a tile signs them straight in to that app, with no separate password for the app itself.

Favorites

Users can star the apps they use most so they surface at the top of their app dashboard for quick access.
The app dashboard only ever shows the apps a user is actually assigned, so what each user sees reflects the access you have granted them. To control who sees which apps, see Assigning access.
Selecting an app tile starts a single sign-on into that app. If an app’s policy requires something the user has not satisfied yet (such as enrolling a passkey), they are prompted at that point.
For what end users see when they sign in and open apps, see Accessing your apps. For passkey and Iru Access setup, see Manage authenticators. On macOS, if a passkey does not appear in the browser prompt, see the tip in Accessing your apps.

Where to go next

End-user experience

A fuller tour of what end users see and manage in Iru, including their authenticators.

Federated Authentication

Let users sign in through Google Workspace, Microsoft Entra ID, or another provider you already run.

Authenticators

The passkeys and credentials users use to prove who they are.

Authentication policies

What Iru checks between sign-in and access.

Accessing your apps

What end users see when they sign in and open apps from the app dashboard

Manage authenticators

End-user guide for passkeys, Iru Access, and backup devices