Integration · Microsoft Entra ID
The team vault that opens
with your Microsoft identity
If your organisation runs Microsoft 365 or Entra ID (formerly Azure AD), every member already has their Keyvaci sign-in. No new passwords to distribute, no user lists to upload, no directory changes to review.
What the integration does
Directory-verified from the very first click
Admin-gated signup
Only a Global Administrator or Privileged Role Administrator of your tenant can create your organisation. Keyvaci verifies the role from Microsoft's own signed tokens, blocking anyone from squatting your company's name.
Standards, not agents
OpenID Connect with PKCE, multi-tenant, tokens verified against Microsoft's published keys on every request. Nothing to install in your tenant, nothing running inside your network.
Lifecycle that follows Entra
Members sign in with their work account. Suspend or remove them in Entra ID and Keyvaci access goes with it; revoking their vault access additionally re-encrypts the vaults they could open.
SSO without weakening encryption
Entra ID answers who you are. What you can decrypt still comes only from your master password, derived on your device. The two systems are separated by design, so adding SSO never dents the zero-knowledge property.
Your MFA policy rides along
Conditional Access, MFA, device compliance: whatever your directory enforces at sign-in applies to Keyvaci automatically, because sign-in is your directory.
Five-minute setup
Sign in, confirm your admin role, save the recovery kit your browser generates, invite the team. Most organisations store their first shared credential inside the first coffee.
Setup, in full
Three steps, no ticket to IT
Sign in with Microsoft
Your tenant admin clicks "Start with Microsoft" and consents to the Keyvaci application, exactly like any Microsoft 365 app. Optional tenant-wide admin consent removes the per-user prompt.
Create the organisation
Keyvaci verifies the admin role, then your browser generates the organisation's signing and recovery keys locally, shows them once, and never sends them to us.
Invite by email
Members sign in with their existing Microsoft account and are recognised automatically. Each sets a master password, gets countersigned by an admin, and starts receiving vaults.
Entra ID questions
Asked by every IT admin so far
Does this require changes to our Entra ID tenant?
No. Keyvaci is a standard multi-tenant OIDC application. Users consent at first sign-in like with any Microsoft 365 app; a tenant admin can optionally grant consent for everyone at once. Nothing is written to your directory.
Who can create our organisation?
Only a Global Administrator or Privileged Role Administrator of your tenant, verified from the directory-role claims in Microsoft's signed tokens, checked server-side against Microsoft's keys. An intern with a work email cannot register your company.
Does SSO weaken the zero-knowledge encryption?
No, because sign-in and decryption are separate systems. Entra ID proves who you are. Decryption keys are derived from your master password, on your device, and neither the password nor the keys are ever transmitted. Full detail on the security page.
What about members who are not in our tenant?
Guest scenarios and email-based members are supported through email sign-up with mandatory verification, with the same encryption and the same countersignature step before they can receive any vault. Partners running Google Workspace can sign in with their own directory instead.
Your tenant is the hard part. It's done.
Everything else takes minutes. 14 days, every feature, no card.