CloudrawSetup guides
Download PDF
Start here · For IT admins

Choose your sign-in method

Compare the ways your people can sign in to Cloudraw and pick the one that fits your organization.

Last updated 6 October 2026 · Download this guide as PDF

How sign-in works in Cloudraw

Your people use Cloudraw Connect, the desktop app, to reach the apps, file shares and networks you publish. The first time, they type your workspace name into Cloudraw Connect, and a browser window opens where they sign in. Cloudraw then registers that computer to that person.

The sign-in method decides where the password is checked:

  • Active Directory: against your own domain controller, reached privately through the Cloudraw connector.
  • Cloudraw accounts: by Cloudraw. You invite people and they choose their own password.
  • Microsoft Entra ID, Google Workspace, Okta or another OpenID Connect provider: at your provider. Cloudraw never sees the password.

A workspace can use Active Directory and one identity provider (for example Microsoft) side by side. Each person signs in with the account they were created with. You can change methods later, but read Changing method later first.

Tip

Find your workspace name in the Cloudraw admin console under Settings→Identity & SSO, in the Workspace sign-in card. Your people type it in Cloudraw Connect.

Quick decision

We run Windows Server domain controllers in the office and everyone has a domain account.Active Directory →
We use Microsoft 365, so people already have a work account at Microsoft.Microsoft Entra ID →
We use Google Workspace (Gmail for business).Google Workspace →
We use Okta, JumpCloud, Keycloak, Ping or another identity provider.Okta / OpenID Connect →
We have no directory. Workgroup PCs, a small office, or a few contractors.Cloudraw accounts →

Comparison

Active DirectoryCloudraw accountsMicrosoft Entra IDGoogle WorkspaceOkta / OpenID Connect
Where the password is checkedYour domain controller, through the Cloudraw connectorCloudrawMicrosoftGoogleYour provider
Second sign-in stepCloudraw e-mail code, sent to the user's AD e-mail addressCloudraw e-mail codeYour Entra MFA and Conditional AccessGoogle 2-Step VerificationYour provider's MFA (for example Okta Verify)
How people are addedMembers of the AD group you chooseYou add and invite themCreated when they first sign in, or provisioned by SCIMCreated when they first sign inCreated when they first sign in, or provisioned by SCIM
Groups for access rulesFrom Active DirectoryCloudraw groups you createFrom Entra via SCIM, or Cloudraw groupsCloudraw groups you createFrom your provider via SCIM, or Cloudraw groups
Needs a Cloudraw connectorYes, one that can reach a domain controllerNo (only for the resources you publish)NoNoNo
Works on domain-joined computersYesYesYesYesYes
Works on workgroup computersYesYesYesYesYes
Setup timeAbout 20 minutesAbout 5 minutesAbout 20 minutesAbout 15 minutesAbout 15 minutes
GuideGuide 2Guide 3Guide 4Guide 5Guide 6
Note

Providers connect over OpenID Connect; SAML is not supported. One-time codes can also be sent by SMS instead of e-mail: your Cloudraw administrator turns this on per workspace.

The options in more detail

Active Directory (on-premises)

People sign in with the username and password they already use for Windows. Cloudraw talks to your domain controller only through the Cloudraw connector inside your network, so you do not open any port to the internet. After the AD password, Cloudraw e-mails a one-time code to the address stored in the user's AD account. You choose an AD group, and only its members can sign in.

The computer does not have to be joined to the domain. A home laptop or a workgroup PC can sign in with a domain account.

Cloudraw accounts (no directory)

The simplest option. Add people in the admin console and click Invite. Each person gets an e-mail, sets a password and installs Cloudraw Connect. Every sign-in asks for a one-time code sent by e-mail. You organize people with Cloudraw groups.

Microsoft Entra ID, Google Workspace, Okta and other OpenID Connect providers

People sign in at your identity provider, with the account, password policy and MFA you already manage there. The first time someone signs in, Cloudraw creates them in your workspace automatically. When you disable someone at your provider, they cannot sign in to Cloudraw again.

You can also turn on Only allow sign-in through the provider. This sends people straight to your provider's sign-in page and turns off Cloudraw passwords in that workspace.

Add-on: SCIM provisioning

SCIM lets your identity provider create, update and remove people and groups in Cloudraw by itself. Cloudraw groups that come from SCIM can be used in access rules right away. When the provider deactivates a person, Cloudraw suspends them. SCIM works with Microsoft Entra ID, Okta and other providers that support SCIM 2.0. Google Workspace has no SCIM option for Cloudraw, so use Cloudraw groups there.

SCIM manages who exists and which groups they are in. It does not sign anyone in, so you still connect a sign-in provider.

After you choose

  1. Set up sign-inFollow the guide for your method. In the onboarding wizard this is step 3, Sign-in for your users.
  2. Decide on two-factor authenticationSee Two-factor authentication.
  3. Get people onto Cloudraw ConnectSend them Install Cloudraw Connect and enroll your computer together with your workspace name.

Changing method later

You can change the sign-in method. Keep these points in mind:

  • Replacing or removing an identity provider disconnects everyone who signed in through it. Cloudraw does not link accounts by e-mail address automatically, because that would let anyone who controls a provider take over an existing account. Cloudraw tells you how many users are affected and asks you to confirm before it makes the change.
  • Invitations (Cloudraw accounts) are not available while an identity provider is connected. People in those workspaces sign in with their provider account instead.
  • Computers that are already enrolled stay enrolled. Access still follows your device trust and access rules.
Important

Plan a provider change for a quiet time and tell your people beforehand. If you are unsure, e-mail support@cloudraw.com and we will help you plan it.