Request a demo →
RAINBOW SECURE FOR MICROSOFT

Strengthen Microsoft 365 and Azure access—without replacing Entra.

Use Rainbow Secure Human-Verified MFA as a federated authentication layer for selected or all users. Keep Microsoft Entra for identities, Conditional Access and authorization while adding stronger protection against stolen credentials, phishing automation and push fatigue.

Book a Microsoft security demo → See the architecture
  • Custom-domain SAML federation
  • Full or phased user adoption
  • Rainbow Secure alone or layered with Microsoft MFA
THE BUYER DECISION

Microsoft provides the identity platform. Rainbow Secure adds another way to defend the sign-in.

Microsoft Entra is powerful infrastructure for users, applications, Conditional Access and cloud authorization. Rainbow Secure is designed to complement that investment—not force customers to rebuild it.

The opportunity appears when organizations want stronger human verification, less dependence on push or personal devices, a phased path for specific groups, or identity controls that extend beyond a single MFA prompt.

IDENTITY THREATS AND RSECUREKEY VALUE

Show attackers that a valid credential is not enough.

rSecureKey adds patented multidimensional verification to the federated Microsoft sign-in. It evaluates the user’s text together with approved color, style, font, formatting placement and contextual dimensions—making stolen credential text only one incomplete part of the authentication response.

01

Credential stuffing and brute force

Attackers test stolen or repeatedly guessed passwords against Microsoft sign-in. rSecureKey adds approved color, style, font and formatting-placement dimensions, so matching the text alone does not reproduce the complete response.

02

Keylogger and infostealer malware

Malware may capture what a user types. rSecureKey can require a dynamic visual instruction and an exact interaction that is not represented by captured keystrokes alone.

03

Phishing and cloned sign-in pages

A convincing page may collect a password or one-time code. Rainbow Secure verifies an additional multidimensional response before returning the federated authentication result to Entra.

04

Adversary-in-the-middle attacks

AiTM proxies attempt to relay sign-in traffic or steal authenticated sessions. rSecureKey reduces reliance on reusable credential text, while device, location, time and behavior policies can add scrutiny.

05

MFA fatigue and accidental approvals

Repeated push prompts can pressure users into approving access. Rainbow Secure does not use push approval; the user must complete the configured Human-Verified interaction.

06

Shared and privileged credential exposure

Administrative, functional or team credentials can be copied or passed between people. rSecureKey strengthens the login, while controlled team access and activity evidence help restore individual accountability.

Rainbow Secure reduces exposure to these attack paths; it does not replace endpoint protection, secure session design, Conditional Access, monitoring or incident response.

WHY ADD RAINBOW SECURE?

Move beyond basic MFA where the risk justifies it.

Free or included MFA can be a reasonable baseline. Rainbow Secure is for organizations and user groups that need a different level of protection, flexibility or visibility.

01

Human verification beyond a code

Rainbow Secure can verify text, color, font, style and where formatting is applied—making captured credential text only one part of the answer.

02

No push-fatigue pathway

Rainbow Secure does not use push approval. Attackers cannot simply generate repeated approval prompts until a user accepts.

03

Flexible for shared and complex access

Device-less and multi-channel choices can support users who share workstations, cannot use personal phones or need a different verification path.

04

Identity controls around the login

Add team access, lifecycle governance, access evidence and risk-aware policies instead of treating MFA as an isolated prompt.

05

Adopt without a tenant-wide cutover

Use a custom federated domain or subdomain to begin with selected users while other groups continue using their existing Microsoft authentication experience.

HOW FEDERATION WORKS

Rainbow Secure verifies the user. Entra continues the Microsoft access decision.

A verified custom domain is configured for federation. When a user signs in with a UPN in that federated domain, Microsoft redirects authentication to Rainbow Secure. After successful Human-Verified authentication, the SAML response returns the user to Entra and the requested Microsoft resource.

Design requirement: Microsoft’s default onmicrosoft.com domain cannot be federated. The production design uses a verified custom domain and must align the UPN, issuer, claims and target tenant.

  1. 01 User requests Microsoft 365 or Azure

    The sign-in identifier determines the user’s Entra domain.

  2. 02 Federated domain redirects to Rainbow Secure

    Rainbow Secure performs the configured multidimensional and contextual verification.

  3. 03 Rainbow Secure returns a signed SAML assertion

    Entra validates the federation response and identifies the user.

  4. 04 Entra applies its remaining controls

    Conditional Access, resource authorization and session policies continue in Microsoft.

FULL OR PARTIAL ADOPTION

Choose the rollout that matches the organization.

MODEL 01

Full federated user base

Move the selected production custom domain to Rainbow Secure federation so users in that domain authenticate through Rainbow Secure before accessing Microsoft resources.

All users in federated domain Rainbow Secure Entra
MODEL 02

Partial user base using a custom subdomain

Create and verify a dedicated subdomain for the users adopting Rainbow Secure. Their UPN uses the federated subdomain, while their normal email address can remain available as an alias. Other users remain on a managed Microsoft domain.

admin@secure.company.com Rainbow Secure employee@company.com Microsoft-managed
UPN, proxy address, mail routing and application behavior must be validated during deployment.
MODEL 03

Layered verification with Microsoft MFA

For selected groups or resources, Conditional Access can still require a Microsoft authentication strength after Rainbow Secure federation. This creates two checkpoints when the policy requires both.

Rainbow Secure + Microsoft Authenticator or approved Entra method
START WHERE THE VALUE IS VISIBLE

Protect a high-value access path before broad adoption.

The best pilot is important enough to matter, small enough to govern and clear enough to measure.

Azure and Entra administrators

Protect daily privileged administrators whose accounts can change policies, identities, subscriptions and cloud resources.

Microsoft 365 email access

Make a stolen password less useful before it reaches Exchange Online, Teams, SharePoint or other Microsoft 365 services.

Team and functional accounts

Replace loosely shared credentials with controlled team access and clearer individual accountability.

High-risk or targeted users

Begin with executives, finance, IT, contractors or other groups exposed to phishing and credential theft.

Shared-workstation users

Support operational teams that cannot rely on a personal phone or hardware token at every sign-in.

BEYOND THE MICROSOFT ENVIRONMENT

Keep identity security unified as your cloud portfolio grows.

Many organizations begin with Entra and Microsoft 365, then adopt Google Workspace or Google Cloud, Salesforce, Oracle and other business platforms. Rainbow Secure can provide a coordinated identity-security and access-management layer across compatible environments—helping teams avoid separate login policies, disconnected user access and inconsistent evidence for every new cloud service.

One governed access strategyApply consistent authentication, user, group and application-access policies across supported platforms. Protect the Microsoft investmentContinue using Entra for Microsoft identities, Conditional Access and resource authorization while extending Rainbow Secure controls to additional cloud services. Expand in phasesStart with Microsoft administrators, team access or a selected user group, then connect additional applications as business adoption grows.
CUSTOM CLOUD APPLICATIONS

Bring advanced login security to the .NET applications you build.

For customer-facing or workforce .NET applications running in the cloud, the Rainbow Secure SDK can add advanced authentication and user-verification capabilities directly to the application journey. This gives development teams a consistent security foundation without treating every custom application as a separate identity island.

Explore custom application integration →
  1. 01 Identify the protected journey

    Map sign-in, onboarding, privileged actions or other sensitive user events.

  2. 02 Integrate the Rainbow Secure SDK

    Connect the application to the approved authentication or verification flow.

  3. 03 Apply policy and preserve evidence

    Use the agreed identity controls and maintain reviewable authentication activity.

!
EMERGENCY ACCESS SAFEGUARD

Protect administrators—but do not create one dependency for every break-glass account.

Rainbow Secure is well suited for daily cloud administrators and controlled high-risk access. However, Microsoft recommends separate cloud-only emergency-access accounts for tenant recovery. At least one recovery path should remain independent of the same federation service so an outage or federation error does not lock the organization out.

A Microsoft security consultation should define which administrator accounts use Rainbow Secure, which emergency accounts remain independent, how credentials are controlled, and how every emergency use is alerted and reviewed.

ROLE OF EACH PLATFORM

Use each platform for what it does best.

Responsibility Microsoft Entra Rainbow Secure
Directory and Microsoft tenant identity Primary system Federates or synchronizes as designed
Conditional Access and resource authorization Primary system Provides authentication result and context
Human-Verified multidimensional interaction Not the core purpose Purpose-built capability
Push-free authentication path Depends on selected Microsoft method No push approvals
Shared workstations and team access Varies by application and design Device-less and controlled team-access options
Layered Microsoft MFA Conditional Access can require it Can authenticate first through federation
BUSINESS IMPACT

A safer Microsoft journey without throwing away the Microsoft investment.

Reduce credential-only risk

Add a user interaction that a captured password or OTP does not fully represent.

Avoid forced big-bang adoption

Start with a custom federated subdomain, selected groups and high-value workflows.

Preserve Microsoft controls

Keep Entra Conditional Access, resource authorization and Microsoft application governance.

Support different user needs

Use Rainbow Secure, Microsoft MFA or both according to user group and resource policy.

MICROSOFT DEPLOYMENT FAQ

Questions to resolve before rollout.

Does Rainbow Secure replace Microsoft Entra?+

No. In this design, Entra remains the Microsoft identity and authorization platform. Rainbow Secure provides federated Human-Verified authentication and related identity-security controls.

Can only some users use Rainbow Secure?+

Yes. A dedicated verified and federated subdomain can provide a phased user population while other users remain on a managed Microsoft domain. UPN, email alias, claims and application compatibility must be validated.

Can users still use Microsoft Authenticator?+

Yes. Some groups may remain entirely on Microsoft authentication. For others, Entra Conditional Access may require an additional approved Microsoft method after Rainbow Secure authentication.

Can Rainbow Secure help when we add Google, Salesforce or Oracle?+

Yes, where the target platform supports the required integration. Rainbow Secure can help coordinate authentication, access management and evidence across compatible Microsoft and non-Microsoft environments. Each connection and responsibility is validated during technical discovery.

Can we protect a custom .NET cloud application?+

Yes. Development teams can use the Rainbow Secure SDK and supported integration patterns to add advanced login security or user verification to a custom .NET application. The exact flow, claims, authorization boundary and recovery behavior are confirmed during solution design.

Should every break-glass account use federation?+

No. Microsoft recommends independent cloud-only emergency-access accounts. Do not make every recovery path dependent on the same external federation service.

What should a pilot measure?+

Measure successful sign-in, user completion, administrator effort, Conditional Access behavior, application compatibility, recovery procedures and the agreed security outcome.

SECURE YOUR MICROSOFT ACCESS

Choose one Microsoft access path to protect first.

Bring your Entra tenant model, custom domains, target users, Conditional Access policies and priority resources. We will map a safe pilot and show both the user and administrator experience.

Book a Microsoft security demo → Review customer stories

Microsoft, Microsoft 365, Azure, Entra and Microsoft Authenticator are trademarks of Microsoft. Rainbow Secure is an independent identity-security provider and Microsoft ISV partner. Final capabilities depend on Microsoft licensing, tenant configuration, supported protocols and the approved deployment design.