Start here
Every Cloudraw workspace needs one way for people to prove who they are. If you are not sure which one to use, read the first guide. It compares the options in one table.
Connect your sign-in
Active Directory (on-premises)
People sign in with their Windows domain account. Cloudraw reaches your domain controller privately through the Cloudraw connector.
Use this if you run your own Windows domain controllers. 3Cloudraw accounts (no directory)
Invite people by e-mail. They set their own password and sign in with a code sent by e-mail.
Use this if you have no directory: small offices, workgroup PCs, contractors. 4Microsoft Entra ID
Register an app in Entra, paste its details into Cloudraw, and optionally turn on SCIM provisioning for people and groups.
Use this if your people sign in to Microsoft 365. 5Google Workspace
Create an internal OAuth client in Google Cloud and connect it to your Cloudraw workspace.
Use this if your people sign in to Gmail and Google Drive for work. 6Okta and other OpenID Connect providers
Okta, JumpCloud, Keycloak, Ping and similar providers, with optional SCIM provisioning.
Use this if you use Okta or another OpenID Connect identity provider.Connect your apps and networks
Install a connector
Put a Cloudraw connector next to your apps on Windows, Linux or Docker. Outbound only, updates itself, and can run in pairs for high availability.
Start here before you publish any app. 8Publish one Windows program (RemoteApp)
Give people one program, such as an ERP client or Excel, instead of the whole desktop, in the browser. Includes the one-time server setup.
Use this to publish a single Windows application. 9Windows file shares (SMB)
Give access to file servers and their shares, with mapped drives that keep working.
Use this for \\server\share access. 10Private networks
Give access to a whole network range, and handle home networks that use the same addresses as the office.
Use this for legacy apps that need network-level access.Integrate your other tools
Send events to your SIEM
Splunk, Microsoft Sentinel, Datadog, Amazon S3, Syslog over TLS or any HTTPS endpoint.
Use this to get Cloudraw audit events and alerts into your SOC. 12Alerts in Slack, Telegram and e-mail
Choose where alerts go and which categories each channel receives.
Use this so the right people hear about problems right away. 13Lock a SaaS app to your connector's IP
Microsoft 365, Google Workspace, Salesforce, GitHub, AWS, Okta and others accept sign-ins only from your Cloudraw connector.
Use this to make cloud apps reachable only through Cloudraw. 14Send e-mails from your own domain
Invitations and sign-in codes from your company's domain, with the DNS records to add.
Use this so Cloudraw e-mails come from you and reach the inbox. 15Automate with the API
API tokens, request basics and ready-to-copy examples.
Use this to script Cloudraw or connect it to your own tools.Security
Two-factor authentication
The Cloudraw e-mail code, your provider's own MFA, sending codes from your own domain, and fixing codes that do not arrive.
Use this if you want to know what the second sign-in step looks like, or a code is not arriving. 17Require healthy devices
Disk encryption, antivirus, firewall, updates and more: decide which devices may connect, and to what.
Use this to keep unhealthy or unknown computers out. 18App firewall (allowed programs)
Only approved programs on a device may use an app. See what was blocked, and get alerted.
Use this to stop tools like telnet or unknown programs from reaching your servers.For your people
PDF versions
Each guide has a Download PDF button at the top of the page. You can also download them here:
- Choose your sign-in method (PDF)
- Active Directory (on-premises) (PDF)
- Cloudraw accounts (no directory) (PDF)
- Microsoft Entra ID (PDF)
- Google Workspace (PDF)
- Okta and other OpenID Connect providers (PDF)
- Two-factor authentication (PDF)
- Install Cloudraw Connect and enroll your computer (PDF)
- Install a connector (PDF)
- Publish one Windows program (RemoteApp) (PDF)
- Windows file shares (SMB) (PDF)
- Private networks (PDF)
- Send events to your SIEM (PDF)
- Alerts in Slack, Telegram and e-mail (PDF)
- Lock a SaaS app to your connector's IP (PDF)
- Send e-mails from your own domain (PDF)
- Automate with the API (PDF)
- Require healthy devices (PDF)
- App firewall (allowed programs) (PDF)