Passwordless SSO for modern and legacy applications

Replace passwords and traditional MFA with passkeys or mobile authentication. Give employees one secure sign-in experience across SSO-enabled, legacy, and custom web applications.

Hideez Workforce Identity on a phone and a workstation
A password plus a rejected one-time code is the most common way a workday stalls. Passwordless sign-in removes the password and the code together, and keeps the phishing resistance your auditor is looking for.
5,000,000+Passwordless logins delivered
100+Integrations and custom use cases
9 yearsSecuring the workforce
Swipe to see more →
Why teams choose it

One sign-in that reaches everything

One identity across every app

One identity across every app

Microsoft 365, modern web apps, and legacy applications that don’t support SAML — all accessible through the same sign-in experience.

Phishing-resistant by design

Phishing-resistant by design

The private key stays protected on the user’s device and is never transmitted, leaving no password or code for attackers to steal through phishing.

Keeps the directory you already run

Keeps the directory you already run

Hideez federates with Active Directory and Microsoft Entra ID, so your users, groups and policies carry over untouched.

Yours to host

Yours to host

Run it in our cloud, in a private isolated cloud, or fully on-premise on your own login domain.

What single sign-on actually does
SSO explained

What single sign-on actually does

Single sign-on means one verified identity opens every application a person is entitled to use. They authenticate once, and each application trusts that result instead of asking for its own password. The service that performs the check is the identity provider; everything that trusts it is a service provider.

Most SSO deployments still start that one sign-in with a password and a one-time code, which is where the friction and the phishing risk live. Hideez uses the same SAML and OpenID Connect federation flows, but initiates authentication with a passwordless credential stored on the user’s phone or hardware security key.

  • Federation with Active Directory and Microsoft Entra ID
  • SAML 2.0 and OpenID Connect for modern applications
  • Applications without SSO support covered through Hideez AuthShield
  • One audit log across all of it
How people sign in

Different services, unified sign-in

Device-native biometrics
FIDO2 security keys

Passkeys use public-key cryptography instead of passwords. The private key stays protected on the user’s phone, tablet, computer, or security key and is unlocked with biometrics or a device PIN.

The cryptographic credential is stored on an external FIDO-certified security key (Hideez Key, Yubikey, etc.) rather than on the user’s phone or computer. The private key remains protected inside the device and is used to authenticate the user without exposing any reusable secret.

Dynamic QR codes

The lock screen shows a QR code. The employee scans it in the app and approves the request.

Federate with the identity you already have
Works with your directory

Federate with the identity you already have

Hideez can act as the identity provider for your applications or work alongside Microsoft Entra ID and Active Directory to add passwordless authentication to your existing environment. Users and groups are synchronized from your directory, so there is no separate user database to manage.

For organizations that need to keep authentication within their own infrastructure, Hideez can be deployed on-premises or in a private isolated cloud, with a custom login domain under your own DNS.

  • Synchronize users and groups from Active Directory or Entra ID
  • Connect applications through SAML or OpenID Connect
  • Use a custom login domain under your own DNS
  • Deploy in the cloud, a private isolated cloud, or fully on-premises
Sign-in audit

Every sign-in, every application, one log

Hideez Server records each authentication against the person, the application they opened and the method they used. The same log covers modern apps behind SSO and older ones reached through AuthShield.

Audit / Application Sign-ins
Start Date End Date Employee Application Method
8/4/2026 9:14 AM Active Emma Wilson Microsoft 365 Passkey
8/4/2026 9:02 AM 8/4/2026 9:11 AM James Carter Microsoft 365 Push approval
8/4/2026 8:47 AM 8/4/2026 8:58 AM Michael Brown Quality portal (AuthShield) Hideez Key
8/3/2026 5:26 PM 8/3/2026 6:02 PM Olivia Davis Internal CRM Passkey
8/3/2026 1:05 PM 8/3/2026 5:58 PM Sophia Miller Remote desktop Hideez Key
8/3/2026 7:12 AM 8/3/2026 12:44 PM James Carter Quality portal (AuthShield) Push approval
  • One person stays one identity across every application
  • Method recorded per sign-in, so passwordless coverage is measurable
  • Modern apps behind SSO and older ones behind AuthShield in the same log
  • Export-ready trail for HIPAA, PCI DSS, NIS2 and DORA
SEE HIDEEZ SERVER →
How it compares

Beyond passwords and traditional MFA

Password + OTP MFA Cloud-only IdP ADFS on-prem
Sign-in with no password and no code to type Limited
Phishing-resistant FIDO2 credentials Limited
Covers applications with no SAML or OIDC support
Runs fully on-premise or in a private cloud
Windows desktop login included Limited
See it live

Start with one application

A 30-day proof of concept, phone-only, on a single application you pick. Add the rest once the sign-in feels right.

Case study

How a government agency replaced hardware keys with mobile authentication

Since adopting Hideez, authentication has become both secure and user-friendly. We have almost entirely eliminated passwords in favor of Hideez authentication

State Agency for Restoration of Ukraine
How a government agency replaced hardware keys with mobile authentication
FAQ

Questions IT teams ask

What is single sign-on, and how is it different from a password manager?

Single sign-on removes the second password entirely: the application trusts an identity provider that already verified the person. A password manager still stores and types a password into each application, so every one of those passwords continues to exist and can still be phished or reused.

Is passwordless actually more secure than a password plus a one-time code?

Yes, and the reason is specific. A one-time code can be read out over the phone, typed into a fake login page, or approved by a tired user. A FIDO2 credential is bound to the exact site that issued it and never leaves the device, so there is nothing to hand over. Many teams assume more steps means more security. What matters is whether any step can be intercepted.

Do we have to replace Microsoft Entra ID or Active Directory?

No. Hideez can act as your identity provider, and it can also federate with Entra ID or Active Directory and add passwordless sign-in on top of them. Users, groups and policies replicate from the directory you already run.

Which applications can Hideez cover?

Anything that speaks SAML 2.0 or OpenID Connect, which covers Microsoft 365 and most modern web applications. Applications with no modern SSO support are covered through Hideez AuthShield, which sits in front of them and signs users in without changes to the application itself.

Can we host it ourselves?

Yes. The same platform runs in our cloud, in a private isolated cloud, or fully on-premise inside your perimeter, on a login domain of your own. Organisations under data-residency rules generally choose one of the latter two.

What happens when someone loses their phone?

Revoke the credential from the admin console and issue a new one. Teams that cannot tolerate any downtime give critical users a Hideez Key as a second credential, so the two work interchangeably.

Does this work on macOS and Linux?

Signing in to work accounts and web applications works from any operating system, including macOS, Linux and ChromeOS. Locking and unlocking the device itself is Windows 10 and 11 only.

How long does a rollout take?

A single-application proof of concept usually runs the same week, phone-only. Full rollouts are paced by how many applications you connect rather than by the authentication itself.

What does this do to our password-reset tickets?

When there is no password for an application, there is no reset for it either. Industry benchmarks put a single reset at roughly $70 once helpdesk time is counted, which is where most of the payback comes from. Confirm the numbers against your own ticket volume with our team.

More questions? Contact sales
Get started

See passwordless SSO on your own stack

Book a demo or get a quote. Free 30-day proof of concept, phone-only to start.