Flexible, Secure, and Purpose-Built User Access Management
ETCETERA® offers robust authentication services that ensure secure access to its platform through highly configurable user validation methods. Designed to meet the evolving needs of organizations, the platform supports both native and external directory-based authentication, including Active Directory (AD) and Microsoft Entra ID (formerly Azure AD), with flexible implementation options for mixed environments.
Whether used to authenticate internal staff or external users (like customers, vendors, patients or constituents accessing portals), ETCETERA®’s authentication services streamline user provisioning, enforce secure policies, and offer fine-grained control over login methods – all while maintaining a cohesive and secure user experience.
Supported Authentication Models
- ETCETERA® Native Authentication
- User credentials (username/password) are stored and validated within ETCETERA®‘s internal database.
- Ideal for smaller organizations or external users who don’t exist in an enterprise directory.
- AD / Entra ID Authentication
- Supports secure validation against Microsoft Active Directory or Microsoft Entra ID.
- Enables seamless Single Sign-On (SSO) using existing enterprise credentials.
- Reduces admin overhead by leveraging domain-managed identity services.
- Mixed Authentication
- Enables simultaneous use of ETCETERA®-native and AD/Entra ID-based authentication.
- Useful for scenarios involving both internal (domain-authenticated) users and external (non-domain) users like vendors or clients.
Key Configuration Options
- Authentication Mode Setup
- Admins can select from:
- ETCETERA® Authentication Only
- AD/Entra ID Authentication Only
- Mixed Mode (AD/Entra ID + ETCETERA®)
- Configurable during deployment or after implementation through system settings.
- Admins can select from:
- AD/Entra ID Domain Configuration
- Supports multiple domain configurations.
- Option to set defaults or allow user-supplied domain details for login.
- Domain trust relationships can be configured as needed.
- Credential Validation
- Uses .NET System.DirectoryServices.AccountManagement for on-prem AD.
- For Entra ID, supports modern authentication mechanisms like SAML via Microsoft identity platform.
- Logs all failed login attempts for security and audit readiness.
- Login Format Flexibility
- Accepts user login as:
- Simple Username
- Fully Qualified Domain Name (e.g., user@domain.com)
- UPN format (User Principal Name) for Entra ID
- Accepts user login as:
User Management & Provisioning
- User Profile Creation
- ETCETERA®-native users: Created manually or through batch import.
- AD/Entra ID users: Profiles can be auto-created on first login or pre-provisioned by admin.
- Role & Permission Mapping
- Role-based access control (RBAC) with mapping to AD groups or Entra ID security groups.
- Supports dynamic access controls based on group membership.
- Password Policy Enforcement (ETCETERA-native only)
- Includes:
- Length and complexity requirements
- Password history enforcement
- Account lockout thresholds
- Password aging and expiration policies
- Includes:
Portal Access for External Users
- Support for External Stakeholders
- Non-domain users (e.g., vendors, partners) can authenticate with ETCETERA®-native accounts.
- Optionally provide access to custom-branded portals or restricted content/workflows.
- Custom Login Interfaces
- Tailored login screens for different user groups.
- Branding options available to align with customer or partner-facing experiences.
Compliance, Security & Audit
- Login and Session Audit Trails
- Detailed tracking of all login events (success and failure).
- IP address logging and timestamping for all sessions.
- Session Management
- Idle timeout policies and session limits to prevent unauthorized use.
- SAML 2.0 Integration
- Support for SAML-based identity providers (including Microsoft Entra ID) for federated login.
- Enables broader SSO integrations with enterprise identity platforms.

