IDENTITY & ACCESS MANAGEMENT

TS Identity
One Identity Platform, Full Control

Complete on-premises identity management — OAuth2/OIDC/SAML SSO, advanced MFA with passwordless DLogin, SCIM 2.0 directory sync from Active Directory and Azure AD, and adaptive access policies. Your identity data never leaves your datacenter.

Why Choose TS Identity?

The only IAM platform designed from the ground up for on-premises sovereignty

🏢

True On-Premises

Unlike cloud IAM vendors, TS Identity runs entirely in your datacenter. ArangoDB stores all identity data locally. Zero dependency on external services for authentication — even if internet is down.

📷

Passwordless DLogin

Users scan a QR code with their mobile app to authenticate — no password required. DLogin eliminates password phishing entirely while keeping the login experience seamless.

🔁

SCIM 2.0 Directory Sync

Real-time sync from Active Directory and Azure AD using SCIM 2.0 (RFC 7643/7644). Users and groups provisioned automatically. Departures deprovisioned immediately.

🛠

Adaptive Policies

SignIn Policies and MFA Policies with conditions based on IP range, device trust, user group, time of day, and risk level. Step-up authentication for sensitive operations.

Comprehensive IAM Capabilities

Every identity feature your enterprise needs, running entirely on your infrastructure

Multi-Factor Authentication

TOTP (Google Authenticator, Authy), SMS OTP, Email OTP, WebAuthn/FIDO2 hardware keys (YubiKey, Touch ID, Face ID), Push notifications, and QR-code DLogin. All MFA methods managed from one console.

Single Sign-On (SSO)

OAuth 2.0, OpenID Connect, SAML 2.0, and WS-Federation. Configure SSO for internal apps and external SaaS. Pre-built integrations for Microsoft 365, Salesforce, GitHub, Jira, and more.

RBAC with 100+ Permissions

8 built-in roles (Super Admin, Administrator, User Manager, Group Manager, Auditor, Security Admin, Storage Admin, Basic User) with 100+ granular permissions. Create custom roles with precise permission sets.

User Lifecycle Management

Automated provisioning from directory sync. Self-service profile updates and MFA enrollment. Access certification workflows. Immediate deprovisioning on account disable or deletion.

Session Trust Levels

Authentication sessions carry trust levels (HIGH, MEDIUM, LOW) based on MFA method and device trust. Applications can require minimum trust levels, triggering step-up authentication as needed.

Audit Dashboard

Real-time ClickHouse-powered audit analytics. Visualize login patterns, MFA usage, failed authentication attempts, geo-distribution, and suspicious activity with interactive dashboards.

Integrates With Your Existing Directory

TS Identity connects to your existing user directories and applications without replacing them

📁

Directory Sources

Active Directory (LDAP/LDAPS), Azure Active Directory (SCIM via Microsoft Graph), Google Workspace, any LDAP-compatible directory. Real-time sync with conflict resolution and audit trail.

🔑

Identity Providers

Act as an OAuth2/OIDC/SAML IdP for all your applications. Configure per-application SSO profiles with custom attribute mapping, scope policies, and token lifetimes.

🔗

Application Integrations

Microsoft 365, Slack, Zoom, Salesforce, HubSpot, GitHub, GitLab, Jira, Confluence, AWS IAM, Azure, GCP — configure SSO for any SAML 2.0 or OIDC-compatible application.

Use Cases

How enterprises deploy TS Identity

👤

Employee Identity Management

Central directory for all employees with automated provisioning from HR systems via AD/Azure sync. Role assignment based on department and job function.

🔐

MFA Rollout

Enforce MFA across all applications with a single policy. Users enroll once and get MFA for every app — no per-application MFA configuration needed.

📋

Compliance & Audit

Meet SOC 2, ISO 27001, and HIPAA access control requirements with immutable audit logs, access certification, and session recordings.

👥

Contractor & Partner Access

Create time-limited accounts with restricted access policies. DLogin eliminates credential sharing risks. Automatic deprovisioning on account expiry.

Technical Specifications

Built on open standards, designed for on-premises sovereignty

SCIM 2.0 | 100+ Permissions | On-Premises
Authentication
  • OAuth 2.0
  • OpenID Connect (OIDC)
  • SAML 2.0, WS-Federation
  • LDAP/LDAPS
MFA
  • TOTP (RFC 6238)
  • FIDO2/WebAuthn
  • SMS OTP, Email OTP
  • DLogin (QR-based)
Provisioning
  • SCIM 2.0 (RFC 7643/7644)
  • Active Directory
  • Azure AD (Microsoft Graph)
Deployment
  • Docker Swarm
  • ArangoDB (on-premises)
  • gRPC + REST APIs
  • Offline installer
Compliance

SOC 2 Type II  •  ISO 27001  •  GDPR (data sovereignty)  •  HIPAA  •  SCIM 2.0 (RFC 7643/7644)

Take Control of Your Identity Infrastructure

Stop trusting cloud IAM vendors with your most sensitive data. Run TS Identity on your own infrastructure.