Request a demo →
RAINBOW SECURE FAQ

Quick answers to identity-security questions.

Learn how Rainbow Secure approaches MFA, SSO, IAM, privileged access, integrations, deployment and compliance—without searching across multiple product pages.

View popular questions Ask us directly
01

MFA and authentication

What is the difference between 2FA and MFA?+

Two-factor authentication requires two verification factors. Multi-factor authentication requires two or more. The terms are sometimes used interchangeably, but MFA can support additional methods, signals and policy-driven steps.

Why do colors and styles make login more secure?+

rSecureKey can require the user to apply expected visual dimensions such as color, font, size, style and position to authentication text. This expands the human interaction beyond reusable text alone. The strength of a deployment depends on its configuration and the surrounding controls.

What is adaptive security, and how does Rainbow Secure use it?+

Adaptive security evaluates the circumstances of an access request. Rainbow Secure can use device, location, time, behavior and policy context to allow the configured journey, require stronger verification, restrict access or record an event for review.

What is the difference between MFA and Adaptive MFA?+

MFA requires multiple forms or dimensions of verification. Adaptive MFA changes the required journey according to policy and risk context—for example, when a device, location, time or behavior differs from the expected pattern.

How does Rainbow Secure handle multi-layered authentication?+

Administrators can combine authentication methods and contextual checks in an approved sequence. Depending on the environment, a user may complete Rainbow Secure authentication alone or complete Rainbow Secure followed by another platform’s verification requirement.

How does device fingerprinting work?+

Rainbow Secure can evaluate device and browser characteristics as part of contextual authentication. Device information is one signal rather than proof of identity by itself, and the exact data and policy use depend on the deployment.

Can users sign in without passwords?+

Yes. Rainbow Secure supports passwordless journeys for compatible applications and environments. Available methods and recovery options are selected during solution design.

Does Rainbow Secure require a browser plugin for color and style authentication?+

No browser plugin is required for supported web-based Rainbow Secure authentication journeys. Application compatibility and the complete user flow are validated before rollout.

What makes Rainbow Secure different from authenticator-code applications?+

Authenticator applications typically generate or approve a possession-based verification step. Rainbow Secure can add multidimensional human interaction, multiple channels and contextual policy. It may complement an existing authenticator where the customer wants both journeys.

02

SSO and integrations

Does Rainbow Secure support Single Sign-On?+

Yes. Rainbow Secure provides SAML 2.0 SSO for compatible SaaS applications and can provide web-based HTTP GET/POST integration for compatible custom applications.

How does Single Sign-On work?+

A user authenticates through a trusted identity provider and receives access to an assigned application without maintaining a separate application password. The application still enforces its own approved business permissions.

What is an SSO authentication token?+

An SSO token or assertion carries a time-limited, digitally protected identity result from the identity provider to the application. It should be validated for issuer, audience, signature, timing and other required conditions.

What are IdP-initiated and SP-initiated SSO?+

In IdP-initiated SSO, the user starts from the identity provider or application dashboard. In SP-initiated SSO, the user starts at the target application and is redirected to the identity provider for authentication.

Can Rainbow Secure protect Microsoft 365 and Entra?+

Yes. Compatible Microsoft environments can use custom-domain federation and either full or selected-user adoption. Microsoft Entra continues to manage tenant identity, Conditional Access and authorization while Rainbow Secure provides the configured authentication journey.

Can Rainbow Secure protect Google Workspace and Google Cloud access?+

Yes. Google Workspace supports third-party SAML SSO profiles assigned at organizational-unit or group level. Google continues to manage accounts and cloud authorization while Rainbow Secure authenticates the assigned users.

Can Rainbow Secure integrate custom or on-premises applications?+

Yes, when the application can securely use the required web-based HTTP GET/POST request and response flow. The integration is not limited to .NET, Java or PHP; those are examples of completed customer implementations.

Can Rainbow Secure integrate with an existing IAM system?+

Yes, when the existing platform and target applications support the required identity or federation design. Rainbow Secure can add authentication and access capabilities without forcing a complete rip-and-replace.

Can I use Rainbow Secure MFA if I already use Okta?+

Potentially, yes. Rainbow Secure can complement an existing Okta environment for selected authentication use cases. The identity flow, supported protocol, user population, recovery and administrative dependencies must be reviewed first.

03

IAM and directory

What is a cloud directory service?+

A cloud directory centrally stores and manages user identities, groups and access assignments so they can be used across approved applications and devices. Rainbow Secure can bring supported identity sources into a coordinated access model.

How is a directory service different from Active Directory?+

A directory service is the general capability for storing and managing identities. Microsoft Active Directory is a specific directory technology commonly used for Windows domains and on-premises resources. A cloud directory is designed for cloud-delivered identity and application access.

Can Rainbow Secure manage onboarding and offboarding?+

Yes. Administrators can create or synchronize identities, assign groups, roles and applications, update access when responsibilities change and disable Rainbow Secure and configured downstream access during offboarding.

Can application access be assigned through groups?+

Yes. Supported applications can be assigned directly or through roles and groups, including approved permanent or time-bound access.

Does Rainbow Secure replace every application’s authorization model?+

No. Rainbow Secure can centralize identity, groups and application assignments, but each application remains responsible for securely mapping that context to its business roles, data and sensitive actions.

04

PAM and least privilege

What is Privileged Access Management?+

PAM governs powerful administrative and service access through controls such as ownership, approval, least privilege, time limits, stronger authentication, monitoring and review.

Who is considered a privileged user?+

Privileged users include system, cloud, database, network and application administrators, support personnel, vendors and others whose access can change configuration, reach sensitive data or affect many users.

Why is PAM important?+

A compromised privileged identity can create organization-wide impact. PAM reduces standing access, improves accountability and makes high-risk administrative activity easier to review.

What do least privilege and just-in-time access mean?+

Least privilege gives a person only the access required for an approved task. Just-in-time access grants that privilege only when needed and removes or expires it afterward.

Can PAM include MFA and suspicious-activity detection?+

Yes. Strong authentication can verify the person before privileged access is granted, while activity and policy signals can support alerting and review. Available controls depend on the deployment.

How is PAM different from IAM?+

IAM governs identities and routine access across the organization. PAM concentrates on high-impact administrative, service and shared access that requires tighter control and accountability.

How does PAM support compliance?+

PAM can produce evidence of who received privileged access, why it was approved, when it was used and when it expired. It supports a broader compliance program but does not create certification by itself.

05

Devices and deployment

What devices and platforms does Rainbow Secure support?+

Rainbow Secure supports compatible modern web environments across desktop, laptop, tablet and mobile use cases. Exact browser, operating-system and application support is confirmed for the customer’s intended journey.

Does Rainbow Secure support ChromeOS?+

Rainbow Secure can support compatible browser-based authentication journeys on ChromeOS. The target application, browser policy, device management and recovery experience should be validated in a pilot.

Can I use Rainbow Secure MFA with a Windows laptop?+

Yes, for compatible browser and application sign-in journeys. Windows device sign-in itself is a separate use case and should not be assumed without technical assessment.

How easy is Rainbow Secure to set up?+

A focused deployment can begin with one application or group. Complexity depends on identity sources, federation, user matching, policies, hosting, recovery and application behavior.

What hosting options are available?+

Rainbow Secure offers shared and dedicated hosting options for supported deployments. Hosting location, isolation, data, availability and continuity requirements are confirmed during solution design.

06

Compliance, encryption and evidence

Is Rainbow Secure compliant with industry security standards?+

Rainbow Secure provides controls and evidence that can support requirements across frameworks and regulations. Compliance belongs to the organization’s complete people, process and technology environment; using one product does not automatically provide certification.

How does Rainbow Secure help with compliance?+

It can support unique user identification, stronger authentication, role and group access, privileged-access governance, lifecycle processes, attempted-access records and reviewable reporting.

Can Rainbow Secure export audit logs?+

Supported deployments can export or integrate authentication and access activity with enterprise reporting, SIEM or data platforms. Microsoft Sentinel is one customer implementation. Format, transport, frequency, retention and destination compatibility are confirmed during design.

What encryption methods does Rainbow Secure use?+

Rainbow Secure uses encryption and secure transport controls appropriate to the configured service. Exact algorithms, key-management responsibilities, hosting boundary and data flows should be reviewed through the security and technical assessment rather than reduced to one universal answer.

Does Rainbow Secure SSO support compliance integration?+

SSO can centralize authentication and produce consistent identity evidence across connected applications. Compliance reporting still depends on application logs, retention, authorization, operating procedures and the applicable framework.

NEED AN ANSWER FOR YOUR ENVIRONMENT?

Show us the problem you need to solve.

Bring your current identity tools, users and applications. We will focus the conversation on where Rainbow Secure can help and what a sensible first phase could include.

Book a Demo → Browse Documentation Security & Compliance