One identity.
Every OrenG system.
Sign in once with Microsoft 365 — or a local account with MFA — and move between OrenG platforms on a single audited session.
Sessions are audited · security policies apply
M365 federation
Entra ID, single-tenant
id_tokens verified locally — issuer, audience, signature and nonce — before a single claim is read.
MFA & passkeys
Local accounts, hardened
TOTP, WebAuthn passkeys and recovery codes. Token rotation treats reuse as theft.
Tamper-evident audit
Every event, chained
HMAC checkpoint chain over the audit stream — recompute and verify it on demand.