What you get
Full app catalog
Every SSO-enabled application across your org — sanctioned and shadow IT
User & group sync
Directory users, groups, org structure, department, and MFA status
OAuth grant inventory
Every third-party app with delegated access — scored by risk level
Login event tracking
See who’s actually accessing each app and how often
Supported providers
- Google Workspace
- Microsoft Entra ID
- Okta
Connects via OAuth with admin consent. Discovers SAML apps, OAuth-connected apps, directory users and groups, and login events from the Reports API.Directory sync coverage:
- Users ✅
- Groups ✅
- Org units ✅
- MFA status ✅
Set up Google Workspace
Step-by-step setup guide
How SSO discovery works
1
Connect your identity provider
Authenticate with admin credentials and grant read-only access. Porcia never modifies your IdP configuration.
2
Initial application sync
Porcia retrieves your full application catalog, user assignments, and group memberships. First sync typically completes in 5–10 minutes.
3
Directory sync
Users, groups, and org structure are synced so you can understand access in context — by department, team, or role.
4
OAuth grant inventory
Third-party OAuth grants are discovered and risk-scored based on permission scopes, grant age, and publisher reputation.
5
Login event tracking
Ongoing sync pulls login events to show who’s actively using each app vs who just has access.
6
Dashboard updates
Vendors appear in your catalog with usage, access, and risk data. Rules are evaluated against new discoveries.
Permissions required
All SSO integrations require read-only access. Porcia never writes to your identity provider.Multi-provider support
You can connect multiple identity providers simultaneously. Porcia deduplicates vendors found across providers so the same app doesn’t appear twice. Common reasons to connect multiple providers:- Post-acquisition environments with mixed IdPs
- Teams using Google Workspace while infrastructure uses Microsoft Entra
- Migrating from one IdP to another during a transition
Privacy & security
- All IdP connections are read-only
- OAuth tokens and API keys are stored encrypted at rest
- Login event data is synced as timestamps and frequencies — no session content
- User data is accessible to workspace admins only
- Full audit log of all sync activity
Disconnecting
- Go to Settings → Integrations → SSO
- Click Disconnect next to the provider
- Confirm
Next steps
Google Workspace
Connect Google SSO
Microsoft Entra ID
Connect Azure AD / Entra
Okta
Connect Okta