Pointrus/Single sign-on

Single sign-on for Pointrus is on the roadmap

Authenticator two-step login works today. OIDC and SAML 2.0 SSO is what we build next, with your help.

Single sign-on for an RMM, done properly

An RMM can run commands on every PC you own, so who can sign in matters more than almost anything else. Single sign-on moves that decision to the place you already manage identity: your directory, your MFA policy and your offboarding process.

Where SSO stands

Pointrus does not have SSO yet. We would rather say that clearly than put a logo wall on this page. Here is what exists and what we plan.

CapabilityStatus
User accounts, roles, authenticator 2FA and audit logAvailable
Single sign-on with OIDC and SAML 2.0Planned
SCIM user provisioningPlanned

The design we are building toward

  • Standards first. OIDC and SAML 2.0, tested with Microsoft Entra ID, Google Workspace and Okta.
  • Your MFA policy applies. Conditional access and phishing-resistant factors at your provider carry through.
  • Roles from groups. Directory groups map to Pointrus roles, so access follows your org chart.
  • Offboarding in one place. SCIM provisioning ends access when a user is disabled.
  • A safety net. One break-glass local administrator, protected by an authenticator code.
  • Every sign-in audited. Sign-ins land in the same audit log as every other action.

What you can use today

Two-step login is live: after the password, the API issues a short-lived challenge and only a valid authenticator code creates a session. Failed attempts are throttled, sessions use secure cookies, and the audit log records sign-ins and actions. See security for details.

Help us build it

Tell us which provider you use, whether you need SAML or OIDC, and how you want roles mapped. The first teams to answer decide what ships first.

SSO questions

Does Pointrus support SSO today?

No. Today Pointrus uses a password and a six-digit authenticator code. SSO with OIDC and SAML 2.0 is planned and is the first thing we are asking early access teams to help shape.

Which identity providers will Pointrus work with?

We are starting with Microsoft Entra ID, Google Workspace and Okta, through standards-based OIDC and SAML 2.0, so other compliant providers should work too. Tell us yours.

Will I still need a local admin account?

We plan to keep one protected break-glass local administrator protected by an authenticator code, so a provider outage never locks you out.

Will Pointrus support SCIM provisioning?

Yes, SCIM is planned after core SSO, so that disabling a user in your directory also ends their Pointrus access.