Software services
Identity & single sign-on
SSO, federation and access control implemented properly: SAML 2.0, OAuth 2.0 and OpenID Connect against Microsoft Entra ID, Okta and other enterprise identity providers. The aim is authentication your customers' security teams approve without a second round of questions.
Outcomes
- Enterprise deals unblocked at the security review stage
- New tenants onboarded in hours, not sprints
- Identity risk reduced to documented, tested behaviour
The challenge
What usually brings clients to us
An enterprise customer is ready to buy, then the security questionnaire arrives: SSO with their identity provider, provisioning, session policy, audit logs. The deal now depends on an identity workstream your team has not shipped before.
Identity is where small mistakes become security incidents: a token validated against the wrong audience, an open redirect, a refresh flow that never expires. None of it shows in a demo. It shows in a penetration test or a security review, usually late in the sales cycle.
What you receive
- Working SSO between your application and the identity providers in scope
- A written protocol and configuration decision for each integration
- Per-tenant onboarding steps your team can repeat without us
- Automated tests covering token validation and failure paths
- Documentation ready for enterprise security questionnaires
Approach
How we deliver it
The right protocol for the relationship
SAML 2.0 where the enterprise requires it, OpenID Connect where you have the choice, OAuth 2.0 for delegated API access, with the trade-off explained in writing.
Integrate with the provider they already run
Entra ID, Okta and other standards-based providers configured per tenant, so each new enterprise customer is an onboarding task rather than an engineering project.
The details reviewers test
Token validation, key rotation, session lifetime, logout, just-in-time provisioning and the error paths real users hit.
An audit trail you can hand over
Sign-in, failure and administrative events logged in a form your support team and your customers' security teams can both use.
Client work
Where we have delivered this
Anonymised engagements delivered by the Codentures team. See all client work.
- Enterprise identity
Zero-downtime legacy authentication migration
An enterprise with 3,000 users
Legacy authentication migrated to modern identity with SAML SSO across six integrations, run as a phased cutover with zero downtime.
- 3,000 users migrated
- Zero minutes of downtime
- HealthcareEU
GDPR-compliant patient management portal
An EU private healthcare provider
A patient management portal with full audit logging, role-based access control and EU data handling throughout.
- Full audit trail
- Role-based access control
Fit
Who this suits
SaaS and platform companies selling into enterprises, where SSO and a clean security review stand between a signed contract and a stalled one.
We design and implement identity. Where you need formal penetration testing or certification, we build to pass it and work alongside the specialist who issues it.
Typical technologies
- Microsoft Entra ID
- Azure AD B2C
- Okta
- SAML 2.0
- OAuth 2.0
- OpenID Connect
- ASP.NET Core Identity
- IdentityServer
- .NET / C#
Send us the system and the symptom
A scoping conversation takes an hour. You will leave it knowing how big the problem is, where the risk sits, and what the sensible first step costs.