Zetect

One sign-in for every application

Users authenticate once with Zetect and reach every application they are entitled to, over SAML 2.0 and OIDC.

Single sign-on removes the password sprawl that builds up when every application keeps its own login. Users authenticate once against Zetect, and each application trusts the assertion Zetect issues rather than storing another credential. Because the same identity record and the same policy engine sit behind every sign-in, revoking access in one place actually revokes it everywhere.

How Single Sign-On works

The mechanics behind the capability — what the platform does, and where it does it.

Sign in onceto ZetectPolicy checkedfactors, zone, riskAssertion issuedSAML 2.0 or OIDCApplication opensno second passwordWHAT THE USER EXPERIENCESOne credential to protect, rotate and eventually retireEvery sign-in recorded on the shared audit trailAccess removed centrally takes effect across every connected application

SAML 2.0 and OIDC

Federate any application that speaks either standard, with per-application configuration for assertions, claims and attribute release.

One identity behind every app

Sign-in resolves against the same identity record that governance and privileged access use, so there is no second directory to reconcile.

Per-application policy

Authentication requirements are set per application, so a finance system can demand more than an internal wiki without forcing that standard on everything.

Central revocation

Disabling an identity ends its access everywhere it federates, rather than leaving an orphaned login behind in each application.

What it changes

Who feels the difference once Single Sign-On is in place, and how.

Security

Fewer passwords to attack

Credentials stop being scattered across applications, which removes the reuse and phishing routes that come with them.

IT operations

Faster onboarding

A new joiner reaches their applications as soon as their identity exists, with no per-application account setup.

Service desk

Less help-desk load

One credential means far fewer reset requests, and self-service handles most of what remains.

Audit

Provable access history

Every authentication lands on one timeline, so answering who signed into what is a report rather than a log-gathering exercise.

See Single Sign-On in context

It works because the other capabilities share the same identity fabric. The quickest way to judge that is to watch it run against your own use cases.