انتقل إلى المحتوى

داينمو. محرك الأعمال الأول

متوفر بالإنجليزية

Security

Sign-in, SSO and two-factor authentication

Passwords and two-factor authentication, Microsoft Entra ID / Google / OpenID Connect single sign-on, enforced SSO, SCIM and service accounts.

Passwords and two-factor authentication

Password sign-in can require a second factor (an authenticator app or an e-mail code), set by your administrator for everyone or for chosen roles. After a number of wrong passwords (set by your administrator in System Settings) sign-in is paused for a short time. Forgotten passwords are reset with a one-time link sent by e-mail; the link expires and works once.

Single sign-on

Dynamo supports:

  • Microsoft Entra ID (Azure AD), using your own Entra tenant;
  • Google Workspace accounts;
  • any OpenID Connect provider;
  • SAML-only providers through an OpenID Connect bridge (most identity platforms offer one).

People sign in with the provider's button; the e-mail address links them to their Dynamo user.

Enforced SSO

Your administrator can require SSO for your company's e-mail domains. Password sign-in is then refused for those users, except for named break-glass administrators kept for emergencies, so an outage at the identity provider never locks the organization out.

SCIM provisioning

With SCIM, your identity provider creates, updates and disables Dynamo users and keeps group membership (mapped to role profiles) in sync. A person removed in the identity provider is disabled in Dynamo; their records and history stay.

Service accounts and API keys

Integrations use service accounts: API identities with their own keys and roles. They cannot sign in with a password, do not take a seat, and their keys can be rotated or revoked at any time. Each integration should have its own service account with only the roles it needs.

Your sessions

Signing out ends the session in that browser. Administrators can end a user's sessions by disabling the user or resetting their password.