ORDSwatch

Hosted edition

Sign-in, MFA and single sign-on

How sign-in works

Enter your username; ORDSwatch works out which organization you belong to and how you sign in, then asks for the next step — a password, a Duo approval, your directory password, or a redirect to your company's identity provider. If you belong to more than one organization you pick one first.

Duo multi-factor authentication

On the Professional and Enterprise plans, an admin can set a teammate's sign-in method to Duo when inviting them. At every sign-in they approve a Duo push (or enter a passcode) after their password.

Single sign-on (Enterprise)

On the Enterprise plan an admin can connect your organization's own directory or identity provider under Settings → Authentication:

  • LDAP / Active Directory — users sign in with their directory password. You provide the directory URL, a bind account, the search base and user filter, and the groups that map to the admin, operator and viewer roles.
  • SAML 2.0 — Azure AD / Entra ID, Okta, Oracle IDCS, ADFS, PingFederate, Keycloak. You provide the IdP sign-in URL and signing certificate; the settings page shows the callback URL to register with your IdP.
  • OpenID Connect — Azure AD / Entra ID, Okta, Google Workspace, Auth0, Keycloak, Oracle IDCS. You provide the issuer, client ID and client secret.

Passwords and client secrets are stored encrypted and are never shown again after saving. Changes apply from the next sign-in.

Invite people first. A single-sign-on user must already be a member of your organization — invite them as usual and choose LDAP, SAML or OIDC as their sign-in method. Their first sign-in through the directory or IdP then lands in your organization.