Talk to us
by IruTechBag Intel Page

Iru Workforce Identity

A stolen password works from any laptop. Sign-in should ask which device is asking — Iru Workforce Identity signs people into SAML and OIDC apps with a device-bound passkey, provisions their accounts from HR data over SCIM, and lets policy demand a healthy, managed device.

Passkey sign-in through Iru AccessDevice-health conditions in policyQuoted per monthly active user

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Pricing
Billed per monthly active user on an annual contract; Iru prints no rate card
Quote
Sign-in
Device-bound passkeys in the Iru Access app, approved in one multifactor step
Passkeys
Maturity
A young identity provider; Iru gives no customer count for this product alone
Since Oct 2025
India
Tenants are pinned to AWS us-east-2 or eu-central-1; neither is in India
US or EU

Quick answer

Iru Workforce Identity, from Iru (formerly Kandji), is a cloud identity provider launched in October 2025: SAML and OIDC single sign-on, a directory, SCIM provisioning driven by HR data, and access policies that check the device, with sign-in by device-bound passkeys. It is quoted per monthly active user, runs only in AWS US or EU regions with no India option, and documents no LDAP or RADIUS for older apps. Read more ↓ Show less ↑
Part 01 · Orient

The Iru platform family

This page covers Iru Workforce Identity — the identity provider, licensed per monthly active user. The rest:

Quick facts

30-second orientation
Product
A cloud identity provider: SSO, a directory, SCIM lifecycle and device-aware access policies
Maker
Iru, Inc., US-based (Miami and San Diego); co-founder Adam Pettit is CEO
Status
Launched in October 2025, at the rebrand; roughly a year in market by October 2026
Price
Not published; licensed per monthly active user (MAU) on annual contracts billed yearly
Trial
14 days free; onboarding and migration come at no charge with every Iru plan
Sign-in
SAML and OIDC to apps; users approve with a device-bound passkey in the Iru Access app
Hosting
AWS us-east-2 (US) or eu-central-1 (EU); each tenant is pinned to one region
Gaps
No LDAP, RADIUS, header-based or machine authentication in Iru’s documentation
India
No Indian region, office, partner or rupee price; support hours are 24/5
In India via
TechBag — app inventory by protocol, a passkey pilot, the USD quote worked through with GST
Part 02 · Learn

Understand workforce identity before you buy it

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is a workforce identity provider?

One sign-in service that every work app trusts, so staff log in once and accounts are created and removed centrally.

A password per app and accounts by ticket vs Iru Workforce Identity — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionA password per app, accounts by ticketIru Workforce Identity
Signing inA separate password for each app, often reusedOne passkey approval in the Iru Access app
When someone leavesAccounts closed app by app, if anyone remembersSCIM removal triggered by the HR record
Which device is usedAny laptop with the password gets inPolicy demands a set platform and a healthy device
Group membershipEdited by hand inside every toolFilled from user attributes in the directory
Where identity data sitsScattered across each app’s own storeOne Iru tenant on AWS, US or EU, never India
What it is NOT—LDAP, RADIUS, machine identity or a rupee price

The cheapest test is the 14-day trial: federate from your current directory, put one app behind a device-health rule, and see who gets turned away.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
Where people and groups are kept

Directory

The Iru-hosted directory

Users and groups live in a directory Iru runs for you, and membership can follow attributes, so a change of team or role moves a person into the right access without a ticket.

02
How accounts are made and removed

Lifecycle

HR-driven lifecycle with SCIM

Joiners, movers and leavers begin as HR changes; SCIM provisioning then creates, edits or deletes the matching accounts in each connected application on its own.

03
Who may sign in, from which device

Policy

Access policies with device trust

A policy can insist on a named platform and a healthy device before access is granted, taking that posture from Iru Endpoint wherever it manages the machine in use.

04
How people prove who they are

Sign-in

SAML/OIDC SSO with Iru Access passkeys

Applications trust Iru over SAML or OIDC; the user approves in the Iru Access app with a passkey bound to the device. Tenants are hosted on AWS, in the US or in the EU.

A directory, HR-driven SCIM and device-aware policy — passkey sign-in to SAML and OIDC apps from a US or EU tenant.

Part 03 · Evaluate

Nine capabilities. Sign in, govern, enforce.

Iru Workforce Identity signs people into their apps and checks the device they are using before it lets them in.

Sign in
SSO

SAML and OIDC apps

Applications hand authentication to Iru over SAML or OIDC, so one approval opens every connected SaaS tool for the day.

Sign in
Passkeys

Approve on the device

The Iru Access app holds a passkey tied to the device; one approval is both the sign-in and the second factor, with no code.

Sign in
Federation

Start beside your IdP

Iru can accept sign-ins federated from Google Workspace or Microsoft Entra ID, so apps can move over before passwords change.

Govern
Directory

A directory you control

Users and groups are held in Iru’s own directory rather than borrowed from another vendor, ready to be the source of truth.

Govern
Groups

Membership by attribute

Rules on attributes such as department or location fill groups automatically, so access follows the record, not memory.

Govern
SCIM

Leavers removed by HR

HR changes drive the account lifecycle, and SCIM pushes creations, updates and removals out to the connected applications.

Enforce
Platform

Required platforms

A policy can admit only the operating systems you name, such as managed Macs and iPhones, and turn away anything else.

Enforce
Health

Device health as a gate

Sign-in can depend on device health reported by Iru Endpoint, so a laptop that has drifted out of policy loses app access.

Enforce
Region

A tenant pinned in place

Each tenant is fixed to AWS us-east-2 or eu-central-1, two isolated regions; there is no Indian region to pick instead.

See it, don’t just read it

Watch Iru Workforce Identity in action

Iru’s own overview of Workforce Identity from its official channel, recorded for the October 2025 launch; it is the only identity-specific video Iru has published.

Iru (official)·Product overview, 2025

Iru Workforce Identity

Iru’s own introduction to Workforce Identity from the October 2025 launch, and the only identity video on its channel.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why Iru Workforce Identity

Passwords travel; devices do not. Iru checks the device before the app opens.

Here’s what genuinely sets it apart — and exactly where it stops.

01

Sign-in that asks which device is knocking

A password works from any laptop on earth. Iru’s access policies can require a named platform and a healthy device before an app opens, and when Iru Endpoint already manages the Mac, Windows PC or iPhone, that posture comes from the same vendor and console. A phished password on an unmanaged laptop fails.

02

Passkeys in place of passwords and push codes

People approve sign-ins in the Iru Access app with a passkey bound to their device, a single step that also satisfies multifactor. A passkey is tied to the real site, so a look-alike login page has nothing to harvest, and password resets stop for anyone who has moved.

03

Accounts that follow the HR record

Iru keeps its own directory with groups filled by attribute, takes joiners, movers and leavers from HR data, and uses SCIM to create and remove accounts in connected apps. It can also accept sign-ins federated from Google Workspace or Entra ID, so apps can move one at a time.

04

Where it stops

The product shipped in October 2025. Iru documents no LDAP, RADIUS or header-based route for older apps and no machine authentication, so VPNs and legacy intranets need another directory. Tenants live in the US or EU only, the price is a quote, and support runs 24/5 rather than around the clock.

The idea
Sign-in that checks the device first
The residency
AWS US or EU; no India region
The price
Quoted per monthly active user
Proof, not promises

The numbers behind the platform

2 regions
on AWS where a tenant can live, us-east-2 or eu-central-1, fixed when it is created
— Vendor docs
14 days
of free trial for Workforce Identity before an annual contract is signed
— Vendor
99.9%
availability Iru commits to across its platform in its service level agreement
— Vendor SLA
2.5%
of the monthly fee credited back for every 60 minutes of downtime under that SLA
— Vendor SLA
2025
the year Workforce Identity launched, in October, on the day the Iru brand arrived
— Vendor
6000+
teams using Iru across all its products, per its About page; no identity-only count
— Vendor (2026)

What your Iru Workforce Identity rollout looks like

Week 1Model

Sort apps by protocol

List every application as SAML, OIDC or neither; any that need LDAP or RADIUS will stay on another directory.

Week 2Decide

Choose the tenant region

Pick US or EU before the tenant exists, because it stays pinned, and record legal sign-off that India is unavailable.

Week 3Pilot

Pilot passkeys and policy

Enrol a pilot group in Iru Access, federate from your current directory, and put a device-health rule on two apps.

Month 2Prove

Wire HR and SCIM

Let HR records drive joiners and leavers, turn on SCIM for the main apps, and test one leaver’s removal end to end.

Month 3Commit

Move the remaining apps

Shift the rest of the SAML and OIDC apps, retire old passwords, and sign the annual contract on measured MAU.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4
38+ reviews*
78% would recommend
Passkey sign-in4.3
Device-aware policy4.2
Directory and SCIM3.9
Reach to older apps3.2
Value for money3.8
5★
36%
4★
40%
3★
16%
2★
6%
1★
2%

Quick poll — what’s driving your evaluation?

Talk to an advisor
SaaS
“Macs that fail a health check can still reach email but not the finance tools. Writing that rule took one afternoon.”
IT Lead
SaaS
Fintech
“Staff now approve sign-ins with a passkey in Iru Access. Our last phishing drill did not capture a single password.”
Security Engineer
Fintech
Technology
“HR marks someone as leaving and SCIM strips their Slack and GitHub accounts within the hour. Offboarding tickets vanished.”
People Operations Manager
Technology
Media
“We federated in from Google Workspace first, so nobody changed a password on day one while apps moved across.”
Systems Administrator
Media
Manufacturing
“Our VPN wants RADIUS and an old intranet wants LDAP. Iru does neither, so both still sit on the previous directory.”
Network Engineer
Manufacturing
Financial Services
“We took the EU region. Legal had asked for India, which Iru cannot offer, and approved it only with written conditions.”
Head of IT
Financial Services
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the workforce identity market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag Workforce Identity Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
Iru Workforce IdentityThis page

Quoted per monthly active user; launched October 2025.

Grid 02 · The architecture

Device Trust × IdP Breadth

The grid nobody publishes — how much device posture a sign-in policy can use vs how many protocols and apps the identity provider reaches.

Broad, device-light IdPsBroad and device-awareLogin add-onsDevice-first identity
Iru Workforce IdentityThis page

Platform and health rules; SAML, OIDC and SCIM only.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

Iru Workforce Identity vs the identity field

Against Okta Single Sign-On, Microsoft Entra ID, Jamf Connect, Scalefusion OneIdP and Hexnode IdP — on protocols, passkeys, device trust, price, India storage, support and exit.

DimensionIru Workforce IdentityOkta Single Sign-OnMicrosoft Entra IDJamf ConnectScalefusion OneIdPHexnode IdP
What it isDevice-aware cloud IdPIndependent cloud IdPMicrosoft’s cloud IdPMac login, not an IdPUEM-linked IdPUEM-linked IdP, 2026
Deployment and hostingSaaS on AWS, US or EUSaaS on AWSSaaS, geo set at signupApp on each MacSaaS with UEM agentSaaS beside Hexnode UEM
Protocols and legacy appsSAML, OIDC onlySAML, OIDC, LDAP, RADIUSModern + App ProxyLogin window, not appsSAML, OIDC on ProSSO plus LDAP
Pricing modelPer monthly active userPer user, by suitePer user, or in M365Per user or devicePer device, two tiersPro and Enterprise tiers
Published entry priceNot published$6/user/monthFree; P1 $7/user/moInside Jamf for Mac$4/device/monthQuote; 14-day trial
Included vs add-onPosture needs EndpointLifecycle from $14Conditional access in P1Needs an IdP and MDMSSO only on Access ProConditional: Enterprise
Passwordless and MFADevice-bound passkeysFastPass, FIDO2Passkeys, Hello, FIDO2Your IdP’s MFAOTP and authenticatorMFA, FIDO2 unconfirmed
Device trust in policyPlatform + device healthDevice Access costs moreIntune complianceZTNA checks healthNetwork and geofence tooBlocks non-compliant
Directory and lifecycleDirectory + HR-led SCIMUniversal DirectoryDirectory + HR inboundUses the IdP directoryOwn or federatedLifecycle on Pro
Integrations and federationGoogle, Entra upstream7,000+ OIN appsGallery + Microsoft 365Okta, Entra, GoogleGoogle, Entra, OktaUpstream IdP on Ent.
India data storageUS or EU onlyIndia tenants, 2026Asia/Pacific geoLives in your IdPIndia-built; ask regionNo India region found
Support and uptime24/5, 99.9% SLA24/5 online support99.99% SLA on P1/P2Not publishedTrial, no setup feeNo targets published
Lock-in and exitStandards, young vendorRented directoryTied to Microsoft 365Light to removeNeeds Scalefusion UEMNeeds Hexnode UEM
Best fitIru-managed fleetsVendor-neutral estatesMicrosoft 365 shopsMac fleets with an IdPScalefusion UEM usersHexnode UEM users
● Strong◐ Partial / add-on○ Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose Iru Workforce Identity if…

  • ✓Iru Endpoint already manages your Macs, PCs and phones, and you want sign-in to depend on those devices being healthy
  • ✓Your apps speak SAML or OIDC and you would rather people approve with a passkey than type a password
  • ✓US or EU hosting is acceptable for identity data, and a product launched in October 2025 is a risk you can carry

Compare alternatives if…

  • ✓Older apps need LDAP, RADIUS or header-based sign-in — Okta and Entra ID both offer routes for them
  • ✓Identity data must be stored in India — Okta has run in-country Indian tenants since January 2026
  • ✓You want a price before a sales call — Okta, Entra ID and Scalefusion OneIdP publish theirs

Do not expect…

  • ✓A rate card, an Indian region or a rupee invoice from Iru itself
  • ✓Machine or workload identity, or a directory that answers LDAP queries
  • ✓A Gartner placement or a long track record for this product

Iru Workforce Identity is one of 26 IAM, SSO & MFA products TechBag carries. The IAM, SSO & MFA guide narrows them to a shortlist and shows the reasoning. →

Do the math

What do passwords and hand-made accounts cost you?

Drag the sliders (people who sign in each month; IT staff-hour cost). Estimates model IT time spent on password resets, creating and removing app accounts by hand and fixing access after role changes, at an assumed 1.5 hours per person a year, with 70% of it removed by SSO, SCIM and passkeys. Both figures are assumptions. Illustrative.

300
2510,000
₹800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual access-admin cost
₹3,60,000
Estimated annual savings
₹2,52,000
≈ ₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Quote only. Iru publishes no price for Workforce Identity: it is licensed per monthly active user (MAU) on an annual contract billed yearly, as its own Billing line beside the per-device Endpoint licences. Every plan includes 24/5 support and free onboarding and migration, and a 14-day trial comes first. Iru quotes in USD and has no Indian partner; TechBag counts your monthly active users first, then works the quote through with GST.

Iru Workforce Identity

Best for SaaS apps on SAML or OIDC

  • Quoted per monthly active user, annual
  • SSO, directory, SCIM and passkeys
  • 14-day free trial

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

Workforce Identity + Iru Endpoint

Best when device health should gate sign-in

  • Endpoint licensed per device by platform
  • Policies read live device posture
  • Two Billing lines, one vendor

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
Protocols

How many apps speak SAML or OIDC, and which still need LDAP, RADIUS or header sign-in that Iru does not document?

2
Device fleet

Does Iru Endpoint manage the devices whose health you want in policy, or will unmanaged laptops sign in too?

3
Region

Will your DPO and auditors accept a US or EU tenant, given that Iru offers no Indian region to choose?

4
Upstream directory

Will Iru become the directory, or federate in from Google Workspace or Entra ID while the apps move?

5
HR source

Which HR system holds the truth for joiners and leavers, and can it drive SCIM provisioning into the apps?

6
MAU sizing

How many people sign in each month, contractors included? Monthly active users are the licence unit.

7
Support hours

Is 24/5 support, Sunday 22:30 to Saturday 01:00 UTC, enough for a sign-in outage on an Indian weekend?

8
Service accounts

Where will machine and workload credentials live, since Iru documents no machine authentication?

FAQ

Questions buyers ask

It is Iru’s cloud identity provider, launched in October 2025. It signs users into applications over SAML and OIDC, keeps a directory with attribute-driven groups, provisions accounts over SCIM from HR data, and applies access policies that can require a set platform and a healthy device. People approve with a passkey.

Ready to evaluate Iru Workforce Identity?

Sort your apps by protocol first, or let a TechBag advisor run a passkey pilot on two apps behind a device-health rule and size the MAU quote.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.