Authentication and SSO Service

One trusted authentication journey for every user

Connect Business Applications to enterprise, national, and approved external identity methods without rebuilding authentication logic inside every application.

The business challenge

Why this capability belongs in a shared service

Direct identity integrations give every application its own redirects, sessions, security controls, and provider dependencies.

The result is slower onboarding, inconsistent journeys, and authentication complexity inside teams whose responsibility is business delivery.

Architectural responsibility

One clear role within the Enterprise Platform

01

Validate the requesting Business Application through AIS

02

Establish and manage the authentication session

03

Present only approved authentication options

04

Connect to Active Directory, National PKI, NRS, approved providers and enforce MFA where applicable.

05

Return only to callbacks registered during onboarding

06

Enable one-time server-to-server collection of the verified result

High-level journey

How the responsibility flows

  1. 01

    Application trust

    The Business Application obtains the required trust through Application Identification.

  2. 02

    SSO session

    The application requests a protected, short-lived authentication session server-to-server.

  3. 03

    Browser journey

    The browser enters SSO using the session reference without carrying application credentials.

  4. 04

    Identity choice

    The user selects an approved enterprise, national, or external method. The SSO will enforce MFA when required.

  5. 05

    Registered return

    The browser returns only to the callback established during onboarding.

  6. 06

    Verified collection

    The trusted application retrieves the result once through a controlled server call.

Key capabilities

Designed for practical enterprise adoption

  • Active Directory authentication
  • National PKI
  • National Registry System
  • Username and password with MFA
  • OTP over SMS, email, or mobile notification
  • Firebase mobile approval
  • Approved external providers such as Google OAuth
  • English and Arabic journeys
  • Standard success, cancellation, and failure handling

Security and governance

Trust at every boundary

  • Registered callbacks cannot be supplied dynamically by the browser
  • AIS access tokens and application credentials remain server-to-server
  • Browser values are short-lived and transaction-bound
  • Results expire and can be collected only once
  • Only approved identity attributes are released
  • Correlation logs exclude passwords, tokens, and unnecessary personal information

Business benefits

Value created through reuse and clear ownership

Faster Business Application onboarding
Consistent authentication and MFA
Reduced provider dependency
Central callback governance
Improved user experience
Lower authentication risk inside Business Applications

Flagship demonstration

See the service inside a connected platform journey

An internal employee begins from the enterprise portal while connected to the organization's network. Integrated Windows authentication verifies the employee seamlessly, allowing access to authorized Business Applications without displaying a login screen. An external user begins from the public website, selects an identity option appropriate to the application and context, and completes mandatory MFA. In both journeys, the Authentication Service returns the verified result securely to the registered Business Application.

View Demonstration Center

Start the conversation

Make secure authentication reusable across every application

Connect existing applications, Active Directory, national identity, MFA channels, and future providers through one governed SSO architecture.