How sign-in works in Cloudraw
Your people use Cloudraw Connect, the desktop app, to reach the apps, file shares and networks you publish. The first time, they type your workspace name into Cloudraw Connect, and a browser window opens where they sign in. Cloudraw then registers that computer to that person.
The sign-in method decides where the password is checked:
- Active Directory: against your own domain controller, reached privately through the Cloudraw connector.
- Cloudraw accounts: by Cloudraw. You invite people and they choose their own password.
- Microsoft Entra ID, Google Workspace, Okta or another OpenID Connect provider: at your provider. Cloudraw never sees the password.
A workspace can use Active Directory and one identity provider (for example Microsoft) side by side. Each person signs in with the account they were created with. You can change methods later, but read Changing method later first.
Find your workspace name in the Cloudraw admin console under Settings→Identity & SSO, in the Workspace sign-in card. Your people type it in Cloudraw Connect.
Quick decision
Comparison
| Active Directory | Cloudraw accounts | Microsoft Entra ID | Google Workspace | Okta / OpenID Connect | |
|---|---|---|---|---|---|
| Where the password is checked | Your domain controller, through the Cloudraw connector | Cloudraw | Microsoft | Your provider | |
| Second sign-in step | Cloudraw e-mail code, sent to the user's AD e-mail address | Cloudraw e-mail code | Your Entra MFA and Conditional Access | Google 2-Step Verification | Your provider's MFA (for example Okta Verify) |
| How people are added | Members of the AD group you choose | You add and invite them | Created when they first sign in, or provisioned by SCIM | Created when they first sign in | Created when they first sign in, or provisioned by SCIM |
| Groups for access rules | From Active Directory | Cloudraw groups you create | From Entra via SCIM, or Cloudraw groups | Cloudraw groups you create | From your provider via SCIM, or Cloudraw groups |
| Needs a Cloudraw connector | Yes, one that can reach a domain controller | No (only for the resources you publish) | No | No | No |
| Works on domain-joined computers | Yes | Yes | Yes | Yes | Yes |
| Works on workgroup computers | Yes | Yes | Yes | Yes | Yes |
| Setup time | About 20 minutes | About 5 minutes | About 20 minutes | About 15 minutes | About 15 minutes |
| Guide | Guide 2 | Guide 3 | Guide 4 | Guide 5 | Guide 6 |
Providers connect over OpenID Connect; SAML is not supported. One-time codes can also be sent by SMS instead of e-mail: your Cloudraw administrator turns this on per workspace.
The options in more detail
Active Directory (on-premises)
People sign in with the username and password they already use for Windows. Cloudraw talks to your domain controller only through the Cloudraw connector inside your network, so you do not open any port to the internet. After the AD password, Cloudraw e-mails a one-time code to the address stored in the user's AD account. You choose an AD group, and only its members can sign in.
The computer does not have to be joined to the domain. A home laptop or a workgroup PC can sign in with a domain account.
Cloudraw accounts (no directory)
The simplest option. Add people in the admin console and click Invite. Each person gets an e-mail, sets a password and installs Cloudraw Connect. Every sign-in asks for a one-time code sent by e-mail. You organize people with Cloudraw groups.
Microsoft Entra ID, Google Workspace, Okta and other OpenID Connect providers
People sign in at your identity provider, with the account, password policy and MFA you already manage there. The first time someone signs in, Cloudraw creates them in your workspace automatically. When you disable someone at your provider, they cannot sign in to Cloudraw again.
You can also turn on Only allow sign-in through the provider. This sends people straight to your provider's sign-in page and turns off Cloudraw passwords in that workspace.
Add-on: SCIM provisioning
SCIM lets your identity provider create, update and remove people and groups in Cloudraw by itself. Cloudraw groups that come from SCIM can be used in access rules right away. When the provider deactivates a person, Cloudraw suspends them. SCIM works with Microsoft Entra ID, Okta and other providers that support SCIM 2.0. Google Workspace has no SCIM option for Cloudraw, so use Cloudraw groups there.
SCIM manages who exists and which groups they are in. It does not sign anyone in, so you still connect a sign-in provider.
After you choose
- Set up sign-inFollow the guide for your method. In the onboarding wizard this is step 3, Sign-in for your users.
- Decide on two-factor authenticationSee Two-factor authentication.
- Get people onto Cloudraw ConnectSend them Install Cloudraw Connect and enroll your computer together with your workspace name.
Changing method later
You can change the sign-in method. Keep these points in mind:
- Replacing or removing an identity provider disconnects everyone who signed in through it. Cloudraw does not link accounts by e-mail address automatically, because that would let anyone who controls a provider take over an existing account. Cloudraw tells you how many users are affected and asks you to confirm before it makes the change.
- Invitations (Cloudraw accounts) are not available while an identity provider is connected. People in those workspaces sign in with their provider account instead.
- Computers that are already enrolled stay enrolled. Access still follows your device trust and access rules.
Plan a provider change for a quiet time and tell your people beforehand. If you are unsure, e-mail support@cloudraw.com and we will help you plan it.