Enterprise IAM Platform Features: Security Without Per-User Costs
LoginMaster offers a Tenant-Cloud architecture with dual-signature tokens, configurable 2FA, integrated SSO with Google Workspace and Microsoft Entra ID, tenant-level white-label, and credential protection with Argon2 and split-salt. Every feature is designed to ensure security and control across all identity and access management.
Security and control without compromise
Eight foundational pillars that make LoginMaster an IAM platform designed for security. From the Tenant-Cloud architecture to exclusive user control, every feature ensures real protection of identities and access.
Tenant-Cloud Architecture
The tenant is the customer entity that contains users and credentials. It communicates with the LoginMaster Cloud via dedicated cryptographic keys. Each project has its own key to communicate exclusively with its tenant, ensuring isolation and security at every level of the infrastructure.
Dual-Signature Tokens
The authentication token is signed by both the Tenant and the LoginMaster Cloud, ensuring authenticity on both sides of the communication. The dialog between client and API uses a separate cryptographic certificate, adding an additional layer of verification and protection against token forgery.
Per-Project Configurable 2FA
Two-factor authentication can be disabled, optional, or mandatory on each individual project. The user enables 2FA only if at least one project in their tenant requires it. The system is based on TOTP, compatible with Google Authenticator and similar apps, offering flexibility and tailored security.
SSO with Google Workspace and Microsoft Entra ID
AvailableSingle Sign-On authentication with Google Workspace and Microsoft Entra ID is now available and fully integrated. Your users authenticate with their existing corporate credentials, eliminating the need to manage separate passwords and simplifying access to projects linked to the tenant.
Tenant-Level White-Label
Each tenant can customize logo, colors, and company name to deliver a consistent experience aligned with its own visual identity. Linked projects automatically inherit the tenant's branding, so your users interact with a fully customized authentication interface without knowing that LoginMaster is behind it.
Opaque Cloud: Data Only on the Tenant
Users' personal data resides exclusively on the customer's Tenant. The LoginMaster Cloud never contains readable information: it operates only on encrypted data and references. Not even the provider can access your users' data. With the split-salt system, no single component possesses sufficient information to reconstruct credentials.
Exclusive User Control
No administrator can reset passwords, change emails, or disable a user's 2FA. Only the user themselves can perform these operations through secure procedures designed to prevent identity theft. This security model protects users even in the event of administrative account compromise.
Multi-Project Management
IoT Q2 2026Customer personnel have a single account on the tenant and can access various projects upon confirmation by the project admin or tenant admin. Support for two subject types (user and device) and API keys as a server-to-server communication method. Prepared for AWS IoT integration: manage your IoT device credentials from the same panel without duplicating identity management (available by Q2 2026).
Conditional Access Policies and Adaptive MFA
LoginMaster enforces authentication contextually: each tenant defines policies that adapt access and MFA requirements based on role, device, context, and risk level. A Zero Trust approach that strengthens NIS2 compliance without burdening the experience of low-risk users.
Role-based adaptive MFA
Set 2FA as mandatory for the most sensitive roles and projects and optional for the others. Authentication requirements adapt to the user's privilege level, applying stronger verification where the risk is higher.
Device and subject-type controls
Distinguish between user and device subjects and govern server-to-server access with dedicated API keys. Each access type follows separate policies, so machine-to-machine integrations don't share the rules designed for people.
Access context and perimeter
Define the registration-authorized email domains, the enabled SSO providers, session duration, and failed-attempt thresholds before temporary lockout. Access is granted only within the context allowed by the tenant policy.
Risk evaluation and Zero Trust
Conditional policies concentrate the strictest controls where they matter: critical projects, administrative roles, and sensitive operations require reinforced authentication, while low-risk access stays frictionless. A Zero Trust model aligned with NIS2 and ISO 27001.
Conditional access policies build on LoginMaster's multi-layer security architecture. Explore the platform's cryptographic security and discover the solutions for regulated sectors.
Passwordless Authentication and FIDO2/WebAuthn Passkeys
Reducing reliance on passwords is now a standard requirement in IAM evaluations. LoginMaster already delivers a passwordless experience through federated SSO and a phishing-resistant architecture, with an evolution path toward FIDO2/WebAuthn passkeys.
Passwordless SSO
AvailableWith Single Sign-On to Google Workspace and Microsoft Entra ID, users sign in with the corporate credentials they already use every day -- no dedicated password to create or remember. Fewer passwords means fewer resets, fewer helpdesk requests, and a reduced attack surface.
Phishing-resistant foundation
AvailableThe zero-knowledge architecture ensures passwords are never recoverable or accessible: no administrator can reset them on the user's behalf. This eliminates server-side credential theft and forms the foundation for modern, phishing-resistant authentication.
FIDO2/WebAuthn passkeys
On the roadmapPasskeys replace the password with a cryptographic key pair: the private key stays on the device and is unlocked with biometrics (fingerprint, face) or a PIN, with no shared secrets to intercept. Native support for the FIDO2/WebAuthn standards is on the platform roadmap, in line with the direction of the IAM market.
Frictionless user experience
Removing the password speeds up registration and login, reduces drop-off, and frees the helpdesk from reset tickets. Security increases precisely as the experience gets simpler: users sign in with a single gesture, with no compromise on identity protection.
Passwordless access integrates with Single Sign-On with Google and Microsoft and builds on the zero-knowledge security architecture.
Automated Provisioning and Access Lifecycle
Automate the entire user lifecycle -- joiner, mover, and leaver -- without manual data entry. LoginMaster handles provisioning and deprovisioning through its REST API, SDKs, and webhooks, with support for the SCIM 2.0 standard on the platform roadmap.
Provisioning via API and SDK
AvailableCreate, update, and link users to projects through the REST API and the TypeScript and .NET SDKs. Automate onboarding (joiner) by integrating LoginMaster with your HR system or identity provider, eliminating manual account entry and the errors it causes.
Lifecycle events via webhook
AvailableReceive real-time webhooks on authentication and access events to keep your systems aligned when a user changes role or project (mover). Every context change can trigger downstream automation with no polling or scheduled synchronization.
Deprovisioning and offboarding
AvailableWhen a person leaves the organization (leaver), revoke project access, API keys, and active sessions in a single operation. Immediate deprovisioning closes the risk window of orphaned accounts, a key requirement for NIS2 and ISO 27001 compliance.
SCIM 2.0 standard
On the roadmapThe SCIM 2.0 standard enables automatic synchronization of users and groups with providers such as Okta and Microsoft Entra ID. Native SCIM support is on the platform roadmap; today the same outcome is achievable through the REST API, SDKs, and webhooks.
Provisioning builds on the REST API and TypeScript/.NET SDKs and on the exclusive user-control model.
API and SDK Integration for Developers
LoginMaster offers native SDKs for TypeScript and .NET, along with complete REST APIs to integrate identity management into your applications. Detailed technical documentation and code examples allow developers to implement secure authentication in hours, not weeks. Support for webhooks, advanced logging, and SIEM integration to monitor every authentication event in real time.
Regulatory Compliance by Design
LoginMaster is designed to ensure structural compliance with the most stringent European regulations. The Tenant-Cloud architecture, where personal data resides exclusively on the customer's tenant and the Cloud operates only on encrypted data, natively meets GDPR, NIS2, and ISO 27001 requirements. This is not about additional configurations or add-ons: privacy and security are built into the platform's architecture itself.
Pricing Without Per-User Limits
Unlike traditional IAM solutions that charge per user, LoginMaster pricing is based solely on tenants and projects. Scale your user base without worrying about escalating costs. Whether you have 100 or 100,000 users, your investment remains predictable and sustainable.
Why choose LoginMaster?
LoginMaster is the IAM platform built on a Tenant-Cloud architecture where every component communicates via dedicated cryptographic keys. Dual-signature tokens, credentials protected with Argon2 and split-salt, and exclusive user control over their own sensitive operations.
Discover the Security ArchitectureDual-signature tokens Tenant + Cloud
Authenticity guaranteed on both sides of the communication
Opaque Cloud: personal data only on the Tenant
The Cloud contains no readable information. Not even the provider can access users' data
SSO with Google Workspace and Microsoft Entra ID
Simplified access with existing corporate credentials, now available
Dedicated LoginMaster technical support
Dedicated team available for assistance and consulting
Frequently Asked Questions About Features
LoginMaster's architecture is based on two fundamental components: the Tenant and the Cloud. The tenant is the customer entity that contains users and credentials. It communicates with the LoginMaster Cloud via dedicated cryptographic keys. Each project has its own key to communicate exclusively with its tenant. This separation ensures that each customer's data is isolated and protected by independent cryptographic keys.
LoginMaster's authentication token is signed by both the Tenant and the Cloud, ensuring authenticity on both sides of the communication. This dual-signature mechanism ensures that the token cannot be forged even if one side is compromised. Additionally, the communication between client and API uses a separate cryptographic certificate, adding an extra layer of protection independent from the token's signature.
No, 2FA on LoginMaster is configurable for each individual project. It can be set as disabled, optional, or mandatory depending on the project's security requirements. The user enables 2FA only if at least one project in their tenant requires it. The system is based on TOTP and is compatible with Google Authenticator and similar applications, offering a balance between security and practicality.
LoginMaster supports Single Sign-On authentication with Google Workspace and Microsoft Entra ID. These two providers cover the vast majority of corporate environments and allow your users to access tenant projects with the corporate credentials they already use daily, without having to manage separate passwords.
No. On LoginMaster, no administrator can reset passwords, change emails, or disable a user's 2FA. Only the user themselves can perform these operations through secure procedures. This principle of exclusive user control prevents identity theft and protects users even if an administrative account is compromised.
Customer personnel have a single account on the tenant and can access various projects upon confirmation by the project admin or tenant admin. Each project supports user and device subject types, with API keys for server-to-server communication. By Q2 2026, AWS IoT integration will be available to manage IoT device credentials from the same panel. The admin controls who can access which project.
Users' personal data resides exclusively on the customer's Tenant. The LoginMaster Cloud never contains readable information: it operates only on encrypted data and references. Not even the provider can access the data. Credentials are protected with advanced hashing and a cryptographic separation mechanism that distributes components across multiple entities, so no single component possesses the information to reconstruct them.
LoginMaster's white-label feature allows each tenant to customize logo, colors, and company name in the authentication interface. Linked projects automatically inherit the tenant's branding, so your users will see a login experience consistent with your organization's visual identity, without knowing that the underlying platform is LoginMaster.
Yes. Each tenant configures conditional access policies that adapt authentication requirements to context: user role, project sensitivity, subject type (user or device), enabled SSO providers, authorized registration email domains, session duration, and the failed login attempt threshold before lockout. 2FA can be made mandatory for specific roles and projects, applying stricter controls where the risk is higher while keeping access smooth in low-risk scenarios.
Adaptive MFA modulates the second-factor challenge based on the access risk level, instead of applying the same rule to all users. With LoginMaster you define at the tenant policy level when TOTP 2FA is mandatory -- for example for administrative roles or critical projects -- and when it remains optional. This Zero Trust approach strengthens security on sensitive access without burdening the experience of low-risk users, in line with NIS2 and ISO 27001 requirements.
Yes. With federated Single Sign-On to Google Workspace and Microsoft Entra ID, your users sign in without a dedicated password to create, manage, or forget: they use the corporate credentials they already have. On top of that sits a zero-knowledge architecture where passwords are never recoverable or accessible to anyone, a phishing-resistant foundation onto which the evolution toward FIDO2/WebAuthn passkeys is built.
Passkeys are passwordless credentials based on the FIDO2/WebAuthn standards: a cryptographic key pair where the private key stays on the user's device and is unlocked with biometrics (fingerprint, face) or a PIN, with no shared secrets to steal or intercept. They are phishing-resistant by design. Today LoginMaster delivers a passwordless experience through federated SSO and a zero-knowledge credential model; native FIDO2/WebAuthn passkey support is on the platform roadmap.
Today LoginMaster enables automated user provisioning and deprovisioning through its REST API and TypeScript/.NET SDKs: you can create, update, link to projects, and deactivate accounts by integrating the platform with your HR system or identity provider, and receive real-time webhooks on access events. Support for the SCIM 2.0 standard for automatic synchronization with providers such as Okta and Microsoft Entra ID is on the platform roadmap.
The entire joiner-mover-leaver cycle can be automated. On entry (joiner) you create the account and project links via API; during tenure (mover) you update roles and access and receive webhooks when context changes; on exit (leaver) you revoke project access, API keys, and sessions in a single operation. The exclusive user-control model ensures that sensitive data such as passwords and 2FA always stays under the person's control, while the administrator governs project membership and permissions.
Ready to protect your organization?
Discover how LoginMaster can transform identity management in your company. Request a personalized demo with one of our experts and start protecting your users with LoginMaster's Tenant-Cloud architecture.