Sign in

Find your organisation

Every organisation has its own Inlinea address. Type the first word of yours, or the whole address, and we will take you there.

Take the tourBook a demo

Identity

Your directory decides who. Inlinea decides what.

People sign in with the identity provider you already run. Groups come from your directory and drive every Access Rule. Administrators get the roles and scope their job needs, and automation gets API users with their own tokens.

SSO and Directory SyncYour identity providerMicrosoft Entra ID, Okta, Google, any OIDCInlineaUsers, groups, Access RulesInlinea AgentManaged devicesZERAAny browserWhoPolicyEvery way in
The identity provider signs people in; Directory Sync brings groups; Inlinea applies the same policy to the agent and to ZERA.

Single sign-on

Sign in the way your organisation already does

  • Your identity providerMicrosoft Entra ID, Google, Okta, Keycloak, Authentik, Zitadel, JumpCloud, PocketID and any OpenID Connect provider.
  • Separate sign-insThe Workspace and the Control Center keep separate sign-ins, each in your branding, and the agent signs a device in through the browser.
  • Sign-in protectionTyped credential attempts are limited and abusive addresses are blocked, with named reasons and an unblock action.
  • Sign out everywhereOne action ends a person's identity sessions, devices, Secure Sessions and browser sessions.

Directory Sync

Groups from your directory, kept in step

Connect Microsoft Entra ID with the sign-in application you already registered. Users and groups arrive keyed to their sign-in subjects, so the person who signs in is the person the rule names.

  1. 1ConnectReuse the Entra ID application behind single sign-on; grant it directory read permissions.
  2. 2Choose scopePick the groups to sync. Members arrive with their groups, and a person's reach follows their membership.
  3. 3Block, never deleteA user removed or disabled in Entra ID is blocked in Inlinea at the next sync. Nothing is deleted, so audit history stays intact.
  4. 4See the sourceEvery user shows which identity provider owns it, and the sync's state is visible in the Control Center.

Administration

The right scope for every administrator

  • Custom rolesBuild roles from a catalogue of permissions per module: owner, administrator, auditor, or exactly what a help desk needs.
  • Delegated scopeGive a regional or departmental administrator the groups, devices and resources of their scope and nothing beyond it.
  • API usersService identities with their own access tokens for automation, listed with people in Users and governed by the same roles.
  • AuditedEvery administrative action lands in the Audit Log with who, what and when.

Identity providers

What connects, and how

ProviderSingle sign-onDirectory Sync
Microsoft Entra IDOpenID ConnectUsers and groups, keyed to sign-in subjects
OktaOpenID ConnectSCIM
Google WorkspaceOpenID ConnectSCIM
Keycloak, Authentik, Zitadel, JumpCloud, PocketIDOpenID ConnectGroups through claims
Any OpenID Connect providerOpenID ConnectGroups through claims

Questions buyers ask

Do we have to move our users into Inlinea?
No. People stay in your identity provider and sign in with it. Inlinea keeps the groups it needs for policy, synced from your directory or read from claims.
What happens to a person who leaves?
Disable them in your identity provider. With Directory Sync they are blocked in Inlinea at the next sync; Live Sessions can also sign them out everywhere immediately.
Can a department administer its own users without seeing everyone?
Yes. Delegated administration scopes a role to chosen groups, devices and resources.
Is there an API?
Yes. A REST API with API users and access tokens covers users, groups, devices, resources, rules and settings.

Open the application. Never the network.