A stolen password works from any laptop. Sign-in should ask which device is asking — Iru Workforce Identity signs people into SAML and OIDC apps with a device-bound passkey, provisions their accounts from HR data over SCIM, and lets policy demand a healthy, managed device.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers Iru Workforce Identity — the identity provider, licensed per monthly active user. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
One sign-in service that every work app trusts, so staff log in once and accounts are created and removed centrally.
What consolidation actually replaces, dimension by dimension.
| Dimension | A password per app, accounts by ticket | Iru Workforce Identity |
|---|---|---|
| Signing in | A separate password for each app, often reused | One passkey approval in the Iru Access app |
| When someone leaves | Accounts closed app by app, if anyone remembers | SCIM removal triggered by the HR record |
| Which device is used | Any laptop with the password gets in | Policy demands a set platform and a healthy device |
| Group membership | Edited by hand inside every tool | Filled from user attributes in the directory |
| Where identity data sits | Scattered across each app’s own store | One Iru tenant on AWS, US or EU, never India |
| What it is NOT | — | LDAP, RADIUS, machine identity or a rupee price |
The cheapest test is the 14-day trial: federate from your current directory, put one app behind a device-health rule, and see who gets turned away.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
Users and groups live in a directory Iru runs for you, and membership can follow attributes, so a change of team or role moves a person into the right access without a ticket.
Joiners, movers and leavers begin as HR changes; SCIM provisioning then creates, edits or deletes the matching accounts in each connected application on its own.
A policy can insist on a named platform and a healthy device before access is granted, taking that posture from Iru Endpoint wherever it manages the machine in use.
Applications trust Iru over SAML or OIDC; the user approves in the Iru Access app with a passkey bound to the device. Tenants are hosted on AWS, in the US or in the EU.
A directory, HR-driven SCIM and device-aware policy — passkey sign-in to SAML and OIDC apps from a US or EU tenant.
Iru Workforce Identity signs people into their apps and checks the device they are using before it lets them in.
Applications hand authentication to Iru over SAML or OIDC, so one approval opens every connected SaaS tool for the day.
The Iru Access app holds a passkey tied to the device; one approval is both the sign-in and the second factor, with no code.
Iru can accept sign-ins federated from Google Workspace or Microsoft Entra ID, so apps can move over before passwords change.
Users and groups are held in Iru’s own directory rather than borrowed from another vendor, ready to be the source of truth.
Rules on attributes such as department or location fill groups automatically, so access follows the record, not memory.
HR changes drive the account lifecycle, and SCIM pushes creations, updates and removals out to the connected applications.
A policy can admit only the operating systems you name, such as managed Macs and iPhones, and turn away anything else.
Sign-in can depend on device health reported by Iru Endpoint, so a laptop that has drifted out of policy loses app access.
Each tenant is fixed to AWS us-east-2 or eu-central-1, two isolated regions; there is no Indian region to pick instead.
Iru’s own overview of Workforce Identity from its official channel, recorded for the October 2025 launch; it is the only identity-specific video Iru has published.
Iru’s own introduction to Workforce Identity from the October 2025 launch, and the only identity video on its channel.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
A password works from any laptop on earth. Iru’s access policies can require a named platform and a healthy device before an app opens, and when Iru Endpoint already manages the Mac, Windows PC or iPhone, that posture comes from the same vendor and console. A phished password on an unmanaged laptop fails.
People approve sign-ins in the Iru Access app with a passkey bound to their device, a single step that also satisfies multifactor. A passkey is tied to the real site, so a look-alike login page has nothing to harvest, and password resets stop for anyone who has moved.
Iru keeps its own directory with groups filled by attribute, takes joiners, movers and leavers from HR data, and uses SCIM to create and remove accounts in connected apps. It can also accept sign-ins federated from Google Workspace or Entra ID, so apps can move one at a time.
The product shipped in October 2025. Iru documents no LDAP, RADIUS or header-based route for older apps and no machine authentication, so VPNs and legacy intranets need another directory. Tenants live in the US or EU only, the price is a quote, and support runs 24/5 rather than around the clock.
List every application as SAML, OIDC or neither; any that need LDAP or RADIUS will stay on another directory.
Pick US or EU before the tenant exists, because it stays pinned, and record legal sign-off that India is unavailable.
Enrol a pilot group in Iru Access, federate from your current directory, and put a device-health rule on two apps.
Let HR records drive joiners and leavers, turn on SCIM for the main apps, and test one leaver’s removal end to end.
Shift the rest of the SAML and OIDC apps, retire old passwords, and sign the annual contract on measured MAU.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“Macs that fail a health check can still reach email but not the finance tools. Writing that rule took one afternoon.”
“Staff now approve sign-ins with a passkey in Iru Access. Our last phishing drill did not capture a single password.”
“HR marks someone as leaving and SCIM strips their Slack and GitHub accounts within the hour. Offboarding tickets vanished.”
“We federated in from Google Workspace first, so nobody changed a password on day one while apps moved across.”
“Our VPN wants RADIUS and an old intranet wants LDAP. Iru does neither, so both still sit on the previous directory.”
“We took the EU region. Legal had asked for India, which Iru cannot offer, and approved it only with written conditions.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the workforce identity market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Quoted per monthly active user; launched October 2025.
The grid nobody publishes — how much device posture a sign-in policy can use vs how many protocols and apps the identity provider reaches.
Platform and health rules; SAML, OIDC and SCIM only.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against Okta Single Sign-On, Microsoft Entra ID, Jamf Connect, Scalefusion OneIdP and Hexnode IdP — on protocols, passkeys, device trust, price, India storage, support and exit.
| Dimension | Iru Workforce Identity | Okta Single Sign-On | Microsoft Entra ID | Jamf Connect | Scalefusion OneIdP | Hexnode IdP |
|---|---|---|---|---|---|---|
| What it is | Device-aware cloud IdP | Independent cloud IdP | Microsoft’s cloud IdP | Mac login, not an IdP | UEM-linked IdP | UEM-linked IdP, 2026 |
| Deployment and hosting | SaaS on AWS, US or EU | SaaS on AWS | SaaS, geo set at signup | App on each Mac | SaaS with UEM agent | SaaS beside Hexnode UEM |
| Protocols and legacy apps | SAML, OIDC only | SAML, OIDC, LDAP, RADIUS | Modern + App Proxy | Login window, not apps | SAML, OIDC on Pro | SSO plus LDAP |
| Pricing model | Per monthly active user | Per user, by suite | Per user, or in M365 | Per user or device | Per device, two tiers | Pro and Enterprise tiers |
| Published entry price | Not published | $6/user/month | Free; P1 $7/user/mo | Inside Jamf for Mac | $4/device/month | Quote; 14-day trial |
| Included vs add-on | Posture needs Endpoint | Lifecycle from $14 | Conditional access in P1 | Needs an IdP and MDM | SSO only on Access Pro | Conditional: Enterprise |
| Passwordless and MFA | Device-bound passkeys | FastPass, FIDO2 | Passkeys, Hello, FIDO2 | Your IdP’s MFA | OTP and authenticator | MFA, FIDO2 unconfirmed |
| Device trust in policy | Platform + device health | Device Access costs more | Intune compliance | ZTNA checks health | Network and geofence too | Blocks non-compliant |
| Directory and lifecycle | Directory + HR-led SCIM | Universal Directory | Directory + HR inbound | Uses the IdP directory | Own or federated | Lifecycle on Pro |
| Integrations and federation | Google, Entra upstream | 7,000+ OIN apps | Gallery + Microsoft 365 | Okta, Entra, Google | Google, Entra, Okta | Upstream IdP on Ent. |
| India data storage | US or EU only | India tenants, 2026 | Asia/Pacific geo | Lives in your IdP | India-built; ask region | No India region found |
| Support and uptime | 24/5, 99.9% SLA | 24/5 online support | 99.99% SLA on P1/P2 | Not published | Trial, no setup fee | No targets published |
| Lock-in and exit | Standards, young vendor | Rented directory | Tied to Microsoft 365 | Light to remove | Needs Scalefusion UEM | Needs Hexnode UEM |
| Best fit | Iru-managed fleets | Vendor-neutral estates | Microsoft 365 shops | Mac fleets with an IdP | Scalefusion UEM users | Hexnode UEM users |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
Iru Workforce Identity is one of 26 IAM, SSO & MFA products TechBag carries. The IAM, SSO & MFA guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (people who sign in each month; IT staff-hour cost). Estimates model IT time spent on password resets, creating and removing app accounts by hand and fixing access after role changes, at an assumed 1.5 hours per person a year, with 70% of it removed by SSO, SCIM and passkeys. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Quote only. Iru publishes no price for Workforce Identity: it is licensed per monthly active user (MAU) on an annual contract billed yearly, as its own Billing line beside the per-device Endpoint licences. Every plan includes 24/5 support and free onboarding and migration, and a 14-day trial comes first. Iru quotes in USD and has no Indian partner; TechBag counts your monthly active users first, then works the quote through with GST.
Best for SaaS apps on SAML or OIDC
Best for a broader rollout
Best when device health should gate sign-in
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
How many apps speak SAML or OIDC, and which still need LDAP, RADIUS or header sign-in that Iru does not document?
Does Iru Endpoint manage the devices whose health you want in policy, or will unmanaged laptops sign in too?
Will your DPO and auditors accept a US or EU tenant, given that Iru offers no Indian region to choose?
Will Iru become the directory, or federate in from Google Workspace or Entra ID while the apps move?
Which HR system holds the truth for joiners and leavers, and can it drive SCIM provisioning into the apps?
How many people sign in each month, contractors included? Monthly active users are the licence unit.
Is 24/5 support, Sunday 22:30 to Saturday 01:00 UTC, enough for a sign-in outage on an Indian weekend?
Where will machine and workload credentials live, since Iru documents no machine authentication?
Sort your apps by protocol first, or let a TechBag advisor run a passkey pilot on two apps behind a device-health rule and size the MAU quote.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.