Skip to main content
Your identity provider is the most authoritative source of who has access to what across your organization. Connect it to Porcia and get a complete, continuously-updated picture of your app catalog, user access, and third-party OAuth grants.

What you get

Full app catalog

Every SSO-enabled application across your org — sanctioned and shadow IT

User & group sync

Directory users, groups, org structure, department, and MFA status

OAuth grant inventory

Every third-party app with delegated access — scored by risk level

Login event tracking

See who’s actually accessing each app and how often

Supported providers

Connects via OAuth with admin consent. Discovers SAML apps, OAuth-connected apps, directory users and groups, and login events from the Reports API.Directory sync coverage:
  • Users ✅
  • Groups ✅
  • Org units ✅
  • MFA status ✅

Set up Google Workspace

Step-by-step setup guide

How SSO discovery works

1

Connect your identity provider

Authenticate with admin credentials and grant read-only access. Porcia never modifies your IdP configuration.
2

Initial application sync

Porcia retrieves your full application catalog, user assignments, and group memberships. First sync typically completes in 5–10 minutes.
3

Directory sync

Users, groups, and org structure are synced so you can understand access in context — by department, team, or role.
4

OAuth grant inventory

Third-party OAuth grants are discovered and risk-scored based on permission scopes, grant age, and publisher reputation.
5

Login event tracking

Ongoing sync pulls login events to show who’s actively using each app vs who just has access.
6

Dashboard updates

Vendors appear in your catalog with usage, access, and risk data. Rules are evaluated against new discoveries.

Permissions required

All SSO integrations require read-only access. Porcia never writes to your identity provider.

Multi-provider support

You can connect multiple identity providers simultaneously. Porcia deduplicates vendors found across providers so the same app doesn’t appear twice. Common reasons to connect multiple providers:
  • Post-acquisition environments with mixed IdPs
  • Teams using Google Workspace while infrastructure uses Microsoft Entra
  • Migrating from one IdP to another during a transition

Privacy & security

  • All IdP connections are read-only
  • OAuth tokens and API keys are stored encrypted at rest
  • Login event data is synced as timestamps and frequencies — no session content
  • User data is accessible to workspace admins only
  • Full audit log of all sync activity

Disconnecting

  1. Go to Settings → Integrations → SSO
  2. Click Disconnect next to the provider
  3. Confirm
Historical data is preserved. To fully revoke access, also remove the OAuth grant or API token from your identity provider’s admin console.

Next steps

Google Workspace

Connect Google SSO

Microsoft Entra ID

Connect Azure AD / Entra

Okta

Connect Okta