Validate the requesting Business Application through AIS
Authentication and SSO Service
One trusted authentication journey for every user
Connect Business Applications to enterprise, national, and approved external identity methods without rebuilding authentication logic inside every application.
The business challenge
Why this capability belongs in a shared service
Direct identity integrations give every application its own redirects, sessions, security controls, and provider dependencies.
The result is slower onboarding, inconsistent journeys, and authentication complexity inside teams whose responsibility is business delivery.
Architectural responsibility
One clear role within the Enterprise Platform
Establish and manage the authentication session
Present only approved authentication options
Connect to Active Directory, National PKI, NRS, approved providers and enforce MFA where applicable.
Return only to callbacks registered during onboarding
Enable one-time server-to-server collection of the verified result
High-level journey
How the responsibility flows
- 01
Application trust
The Business Application obtains the required trust through Application Identification.
- 02
SSO session
The application requests a protected, short-lived authentication session server-to-server.
- 03
Browser journey
The browser enters SSO using the session reference without carrying application credentials.
- 04
Identity choice
The user selects an approved enterprise, national, or external method. The SSO will enforce MFA when required.
- 05
Registered return
The browser returns only to the callback established during onboarding.
- 06
Verified collection
The trusted application retrieves the result once through a controlled server call.
Key capabilities
Designed for practical enterprise adoption
- Active Directory authentication
- National PKI
- National Registry System
- Username and password with MFA
- OTP over SMS, email, or mobile notification
- Firebase mobile approval
- Approved external providers such as Google OAuth
- English and Arabic journeys
- Standard success, cancellation, and failure handling
Security and governance
Trust at every boundary
- Registered callbacks cannot be supplied dynamically by the browser
- AIS access tokens and application credentials remain server-to-server
- Browser values are short-lived and transaction-bound
- Results expire and can be collected only once
- Only approved identity attributes are released
- Correlation logs exclude passwords, tokens, and unnecessary personal information
Business benefits
Value created through reuse and clear ownership
Flagship demonstration
See the service inside a connected platform journey
An internal employee begins from the enterprise portal while connected to the organization's network. Integrated Windows authentication verifies the employee seamlessly, allowing access to authorized Business Applications without displaying a login screen. An external user begins from the public website, selects an identity option appropriate to the application and context, and completes mandatory MFA. In both journeys, the Authentication Service returns the verified result securely to the registered Business Application.
Start the conversation
Make secure authentication reusable across every application
Connect existing applications, Active Directory, national identity, MFA channels, and future providers through one governed SSO architecture.