Identity

Identity recovery that sits beside the service desk

AD, LDAP, and Entra patterns plus self-service password reset—governed per tenant, not as a separate IdP project.

  • User management
  • Active Directory & LDAP sync
  • Microsoft Entra ID
  • OIDC SSO
Orqit Identity – Directory Sync, SSO & Password Reset preview
Overview

Orqit Identity keeps directory alignment and password recovery inside the same operations platform as tickets, assets, and endpoints.

Audience

Who this is for

  • Identity administrators
  • IT support leaders
  • Security teams governing recovery flows
Challenges

Problems we address

  • Password ticket volume L1 queues drown in reset and unlock requests.
  • Directory drift ITSM users diverge from AD/Entra reality.
  • Fragmented login Another password for yet another ops tool.
Context

How Orqit approaches this

Admins connect directories, shape sync scope, and expose SSPR APIs for portal and lock-screen agents—so unlock volume drops without standing up a second console for IT.

Capabilities

Platform capabilities

Directory sync, OIDC SSO, and SSPR that cut unlock tickets.

User management

Administer users and roles inside the Orqit tenant.

Active Directory & LDAP sync

Read sync plus lifecycle write patterns (create/enable/disable/delete) where configured.

Microsoft Entra ID

Graph-based directory sync and OIDC SSO preset for Entra.

OIDC SSO

Sign-in with Entra, Okta, Google, or Keycloak-style OIDC providers.

Self-service password reset

Branded hub for reset and account unlock with OTP verification.

SSPR API for agents

HTTP APIs so approved endpoint agents can participate in recovery flows.

Workflow

How it works in practice

  1. 1

    Connect directory

    Configure AD, LDAP, or Entra and sync users into Orqit.

  2. 2

    Enable SSO

    Turn on OIDC so staff authenticate with your IdP.

  3. 3

    Publish SSPR

    Employees reset or unlock without opening a ticket—policy still governs verification.

Outcomes

Results teams care about

Ticket deflection

Password and unlock demand drops when SSPR is adopted.

Governed recovery

OTP and tenant controls replace ad-hoc admin resets.

One ops identity

Same users power ITSM, assets, and Operations Center access.

Details

In depth

Identity highlights

  • OIDC SSO for staff login
  • AD / LDAP / Entra directory sync
  • SSPR for password reset and unlock
  • Windows lock-screen SSPR via SSPR API for endpoint agents

See also LDAP Sync and Entra integration.

FAQ

Common questions

Does Orqit support SAML SSO?

Not currently. Orqit supports OIDC SSO (including Microsoft Entra ID, Okta, Google, and Keycloak-compatible providers). SAML is on the roadmap—do not plan a SAML-only requirement against Orqit today.

Does Orqit support SCIM provisioning?

Not currently. Use AD, LDAP, or Entra directory sync for user alignment.

Can users reset passwords from the Windows lock screen?

Orqit exposes SSPR APIs for endpoint agents. Lock-screen UX depends on the agent package deployed in your estate—confirm agent support for your Windows build.

Can Orqit write passwords back to Active Directory or LDAP?

Yes—SSPR and directory lifecycle integrations are designed for directory password and account operations when providers are configured with appropriate privileges.

Next step

Ready to modernize IT operations?

Launch a pilot workspace or book a walkthrough — with estimated seat savings versus legacy suites, plus 24/7 support.