Overview
miniOrange Identity and Access Management (IAM) platform offers a comprehensive suite of products such as Single Sign-On (SSO) and Multi-Factor Authentication (MFA) solutions, which are developed for identity management, access control, and layered defences, to scale your businesses, and to easily secure workforce identity, including employees, partners, and clients.
Our on-premise IAM solution adheres to a range of regulatory compliances, such as GDPR, PCI DSS, and more. It is developed to withstand malicious cyber threats and unauthorized account access through strong granular policy frameworks.
Use miniOrange on-premise IAM with AWS Integrations, along with AWS IAM, AWS Organizations, AWS SSO, AWS Session Tags, and Amazon Control Tower.
On-Premise IAM Solution includes:
- Single Sign-On (SSO): Enable secure and effortless access to on-premise resources and 5000+ applications with just a single set of credentials with role-based access.
- Multi-Factor Authentication (MFA) & Passwordless Access MFA solution adds an extra layer of security and also enforces passwordless access via authentication methods, like OTP, TOTP, biometrics, push notifications, and hardware tokens.
- Identity Brokering & Federated Authentication Authenticate users from third-party Identity Providers (IDPs), like Entra ID, Active Directory (AD), or Google, for better on-prem access via a Single Sign-On solution.
- User Lifecycle Management & Provisioning Maximize productivity and manage workforce and customer identities with automated SCIM-based user provisioning and deprovisioning.
Highlights
- Unified Identity Platform: miniOrange Single Sign-On solution delivers security and the speed you need to manage your users access to your applications and data all in one place.
- Focused Advanced Security: Our on-premise identity management provides critical low latency and reliability for performance-sensitive advanced security, enabling immediate threat response and superior control.
- Customized Products: Tailor IAM products like SSO and MFA solutions for better integration with operational workflows, delivering a customized identity management solution for your security posture.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Financing for AWS Marketplace purchases
Pricing
Vendor refund policy
30 Day Free Trial
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
64-bit (x86) Amazon Machine Image (AMI)
Amazon Machine Image (AMI)
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
Additional details
Usage instructions
miniOrange IDP 5.2.2 - Getting Started
All components (PostgreSQL, Redis, RabbitMQ, Nginx, Java 17, IDP microservices) are pre-installed and start on boot. You only complete a one-time setup wizard.
Instance: x86_64 only (no ARM/Graviton). Minimum 4 vCPU / 16 GB RAM / 50 GB gp3 (e.g. t3.xlarge); 8 vCPU / 32 GB recommended.
1. Security Group
Inbound: TCP 443 from your users; TCP 22 from your admin IP only. Outbound: allow HTTPS 443 (email, identity sources, licensing). The appliance serves HTTPS only; there is no port 80 listener.
2. Launch
Launch from AWS Marketplace, selecting an EC2 key pair. Wait for Running plus 2/2 status checks (first boot 3-5 min), then note the Public IPv4 address.
3. Retrieve Credentials
Note MO_DB_PASS (PostgreSQL) and MO_MQ_PASS (RabbitMQ).
4. Setup Wizard
Open https://<instance-ip> and accept the self-signed certificate warning. Enter these connection details when prompted:
- PostgreSQL: Host localhost, Port 5432, Database miniorange, Username postgres, Password = MO_DB_PASS, SSL disabled.
- Redis: Host localhost, Port 6379, no password, SSL disabled.
- RabbitMQ: Host localhost, Port 5672, Virtual host /, Username admin, Password = MO_MQ_PASS, SSL disabled.
The wizard validates the connections, initializes the database, and prompts you to create your administrator account. Complete all steps and save.
5. Restart Services After Database Initialization (REQUIRED)
Once the wizard has initialized the database, restart all services one time so every microservice picks up the new configuration and schema. Until you do this, some services stay in a "setup pending" state and the console may not load fully.
sudo moctl service restartWait 2-3 minutes, then reload the application in your browser.
6. Verify
Core services configserver, eurekaserver, gatekeeper and miniorange must be healthy. Sign in at https://<instance-ip> with the administrator account you created.
7. Optional: Custom Domain
- Point a DNS A record at the instance IP.
- Replace /etc/nginx/conf/self-signed.crt and .key with your certificate, then sudo systemctl restart nginx.
- Admin console > gear icon > Settings > Server Base URL > your domain > save.
- sudo moctl service restart.
8. Before Production
Change the default postgres and admin passwords (admin console > infrastructure settings, then sudo moctl service restart), restrict port 22 to your admin network, and install a CA-issued TLS certificate.
Useful commands: moctl service restart [name], moctl log <name> -f, moctl system memory|cpu|disk. Logs: /opt/tomcat/latest/services/logs/
Support
miniOrange support: idpsupport@xecurify.com
Resources
Vendor resources
Support
Vendor support
Get 24*7 technical support from miniOrange seasoned engineers to effectively use IAM products and services. Our support team is available via email and phone to assist with troubleshooting, configuration, and deployment. Email Support: idpsupport@xecurify.com