Enterprise Features¶
PRO / ENTERPRISE Features
Some advanced features require a PRO license; the Corporate Tenant Registry requires an ENTERPRISE license.
CertifyClouds PRO and Enterprise include advanced features for organizations with SSO, multi-user, B2C tenant monitoring, multi-tenant requirements, and governed AI-client access to read-only security data.
Overview¶
Enterprise features include:
- SSO/OIDC: Single Sign-On integration with Azure AD, Okta, and other OIDC providers
- B2C Tenant Registry: Monitor credential expiry in Azure AD B2C tenants
- Corporate Tenant Registry: Discover and rotate credentials across multiple Entra ID tenants of the same organisation (ENTERPRISE)
- Multi-User Support: Multiple users with role-based access control
- MCP Connector: ENTERPRISE Phase 1 read-only tools for approved AI clients
Feature Summary¶
-
MCP Connector (ENTERPRISE Phase 1)
Connect approved AI clients to read-only CertifyClouds security, expiry, dependency, compliance, and audit data.
-
Integrate with Azure AD, Okta, or any OIDC provider for Single Sign-On.
-
Monitor credential expiry across your Azure AD B2C tenants.
-
Corporate Tenant Registry (ENTERPRISE)
Discover and rotate credentials across multiple Entra ID tenants of the same organisation.
-
Manage multiple users with roles and permissions.
Comparison: STARTER vs PRO / ENTERPRISE¶
| Advanced Feature | STARTER | PRO | ENTERPRISE |
|---|---|---|---|
| Local username/password auth | |||
| SSO/OIDC integration | |||
| B2C Tenant Registry | |||
| Corporate Tenant Registry | |||
| MCP Connector (read-only Phase 1) | |||
| Multiple users | |||
| Role-based access control |
Prerequisites¶
Before configuring enterprise features:
- PRO or Enterprise license: Advanced features require Pro or Enterprise
- Admin account: Must be logged in as administrator
- Identity provider access: Admin access to Azure AD, Okta, etc. for SSO setup
- Public HTTPS path for MCP: Required only when using the MCP Connector with remote AI clients
Getting Started¶
1. Configure SSO (Optional)¶
If your organization uses centralized identity:
- Set up SSO with your identity provider
- Test SSO login
- Optionally disable local password authentication
2. Add B2C Tenants (Optional)¶
If you have Azure AD B2C tenants to monitor:
- Register B2C tenants in CertifyClouds
- Run initial discovery
- Configure expiry alerts
3. Manage Users¶
Set up your team:
- Create user accounts
- Assign appropriate roles
- Configure SSO auto-provisioning (if using SSO)
4. Configure the MCP Connector (Optional, ENTERPRISE)¶
If your organization wants approved AI clients to query CertifyClouds:
- Review the MCP Connector prerequisites
- Create the Entra MCP API and one client App Registration per approved hosted AI surface
- Configure the trusted issuer and run the setup diagnostic
Security Considerations¶
Authentication Options¶
| Option | Description | Security Level |
|---|---|---|
| Local only | Username/password stored locally | Basic |
| SSO only | Disable local auth, SSO required | Enhanced |
| SSO + Local | Both options available | Flexible |
Recommendations¶
For production environments:
- Enable SSO for centralized identity management
- Disable local auth after SSO is working
- Use MFA via your identity provider
- Review audit logs for authentication events
Service Credentials CertifyClouds Uses¶
To act as itself in your Microsoft Entra tenant, CertifyClouds uses two distinct credentials, which are easy to confuse:
| Credential | Used for | Notes |
|---|---|---|
| B2C discovery service-principal secret | Reading App Registrations in each registered B2C tenant | Per-tenant discovery service principal |
| SSO application secret | CertifyClouds' own SSO sign-in application | Rotated by the platform Managed Identity |
Both are monitored for expiry and can be rotated automatically or on demand from Settings; see Secret Rotation. These are separate from the customer App Registration credentials that the Rotation feature manages.
Support¶
For enterprise feature support:
- Email: support@certifyclouds.com
- Response time: PRO tier receives priority support with a 2 UK business day target. Enterprise response targets are defined in the signed support agreement.