Identity and endpoint security can no longer operate as separate functions. Before granting access, organizations need to know who the user is, whether the device can be trusted and what resources that combination of user and device should be allowed to reach.
Hexnode IdP and 42Gears SureIdP both bring identity controls closer to endpoint management. Both support capabilities such as single sign-on (SSO), multi-factor authentication (MFA), conditional access and connections with device management. However, they approach the identity problem differently.
Hexnode IdP is designed to connect identity, access and endpoint operations while working with an organization’s existing identity infrastructure. SureIdP is positioned as an in-house identity provider integrated within the SureMDM platform, although it can also federate with external identity services.
This comparison examines those approaches across identity architecture, endpoint login, conditional access, lifecycle automation and identity-driven device management.
Two platforms, two identity strategies
Hexnode IdP is positioned around federated identity and access control connected to endpoint context. Organizations can integrate identity providers such as Microsoft Entra ID and Google Workspace, apply conditional access based on user and device signals, automate lifecycle changes through SCIM and control access to approved applications.
SureIdP is an in-house IdP embedded in SureMDM. Administrators can create a domain, add users manually or in bulk, authenticate users during device enrollment and associate enrolled devices with authenticated users. SureIdP is offered as an add-on to the Premium and Enterprise SureMDM packages.
| Area | Hexnode IdP | 42Gears SureIdP |
| Primary approach | Connect identity, access, and endpoint management while integrating existing identity providers | Provide an in-house identity provider within SureMDM |
| External identity integration | Integrates with providers such as Microsoft Entra ID, Google Workspace, and Okta | Supports federation with Microsoft Entra ID, Google Workspace, Okta, and SAML 2.0-compatible providers |
| Multi-IdP architecture | Documents a hub-and-spoke architecture for centrally governed and regionally operated identity environments | Supports external identity federation, while its Microsoft Entra integration allows one domain to be configured per SureMDM account |
| Endpoint login | Hexnode Access enables cloud IdP-backed login on Windows and macOS | SureIdP authentication can be applied to OS login on Windows, macOS, and Linux |
| Conditional access | Uses identity, device compliance, and security context in access decisions | Supports application and OS-login rules based on device state and contextual conditions |
| Lifecycle management | Supports SCIM-based lifecycle management, JIT provisioning, and identity-driven endpoint workflows | Supports manual and bulk user creation, external directory synchronization, and automated provisioning workflows |
| Identity-to-UEM automation | IdP attributes can place devices in dynamic groups that receive relevant policies and resources | Supports user groups, device-to-user binding, and access controls based on SureMDM management and compliance status |
| Session and activity visibility | Documents session-inactivity controls and centralized sign-in, provisioning, and authentication reports | Supports continuous user and device verification and can revoke access when configured risk conditions change |
Extend the identity systems your organization already trusts into access and endpoint workflows. Bring user context, device compliance and policy enforcement together with Hexnode IdP.
Try Hexnode IdPStart with the identity architecture
The following section examines how Hexnode IdP extends existing identity environments while SureIdP provides an in-house identity provider within SureMDM.
Many enterprises already have years of identity configuration in Microsoft Entra ID, Google Workspace or Okta. Their user directories, groups, application assignments and onboarding processes are built around those systems. Introducing another security layer should ideally extend that investment without creating an unnecessary identity reset.
Hexnode supports this model by using existing cloud identity credentials within endpoint workflows. With Hexnode Access, employees can use their established organizational credentials to sign in to managed Windows and macOS devices. The external IdP continues to authenticate the user while Hexnode connects that identity to the managed endpoint.
SureIdP takes a different approach in its documented Microsoft Entra integration. Administrators first synchronize Entra users into SureIdP and then enable federation for a verified domain. Once federation is enabled, authentication for users under that domain switches from Microsoft Entra to SureIdP.
Identity infrastructure rarely remains simple as an enterprise grows. Different subsidiaries may use different identity providers. An acquired company may continue using Okta while the parent organization relies on Microsoft Entra ID. Regional teams may also require operational independence.
Hexnode documents a multi-IdP architecture for these environments. Its hub-and-spoke model allows a central identity authority to establish governance while regional or subsidiary environments retain control over their local directories.
The architecture covers Microsoft Entra ID, Okta and Google Workspace and combines them with capabilities such as:
- Centralized visibility across connected environments
- Independent lifecycle control for subsidiary operations
- Just-in-time user creation based on SAML or OIDC claims
- Role and organizational placement derived from identity attributes
- SCIM 2.0-based lifecycle synchronization
SureIdP supports external identity federation, and its Microsoft Entra integration allows one domain to be configured per SureMDM account.
For multinational enterprises or companies integrating acquired business units, Hexnode’s hub-and-spoke model allows a central authority to govern identity policy while regional or subsidiary environments retain control over their local directories.
Application SSO reduces repeated authentication after a device is unlocked. However, the first login to the endpoint can still depend on a separate local account. Both Hexnode and SureIdP attempt to close that gap.
Hexnode Access
Hexnode Access allows users to sign in to managed desktops with cloud identity credentials. On Windows 10 version 1803 or later, excluding ARM-based PCs, Hexnode Access supports Microsoft Entra ID, Google Workspace, Okta and OneLogin. On macOS 10.13 or later, Hexnode Access supports Microsoft Entra ID, Google Workspace and Okta.
Administrators can configure permitted domains or user groups, control the creation of local accounts, synchronize local and cloud passwords and customize the login experience. Hexnode Access can also create a local account associated with the authenticated cloud identity, helping IT connect a user’s directory identity to their desktop profile.
The important advantage here is identity continuity: users can authenticate with credentials from the provider their organization already uses.
SureIdP OS login
SureIdP OS Login allows users to sign in with SureIdP credentials on SureMDM-enrolled Windows, macOS and Linux devices. Administrators can manage offline credential expiry, take over existing local accounts, bind users to authorized devices, customize login screens and limit the number of SureIdP users permitted on a device.
SureIdP therefore has extra documented OS-login platform coverage because it includes Linux. Hexnode’s differentiation is not platform breadth; it is the direct extension of several established third-party identity providers into Windows and macOS login.
Synchronizing users is useful. Turning identity data into endpoint action is where integration can reduce day-to-day administration.
Hexnode’s Identity Anchor architecture can use attributes from Microsoft Entra ID, Google Workspace, Okta or on-premises Active Directory to determine dynamic UEM group membership.
Attributes such as department, location or directory group can become conditions for assigning devices to the right operational group. Once a device enters a dynamic group, the appropriate UEM policies and resources can follow. For example:
- A new member of the finance department can receive finance applications and stricter security configurations.
- An employee moving to another region can receive the Wi-Fi, certificates and configurations required for that location.
- A user leaving a department can be removed from the corresponding dynamic group so that department-specific resources no longer apply.
This creates a continuous connection between the identity directory and endpoint configuration. IT does not have to update both systems manually every time a user’s role, department or location changes.
SureIdP documents user groups, device limits, user-device binding and compliance-based access controls. Those are valuable identity-management functions. However, it does not describe the same attribute-to-dynamic-group workflow in which external directory metadata directly changes UEM policy and resource assignments.
Identity security depends on what happens after an account is created. A useful platform must account for new hires, role changes, suspensions and departures.
Hexnode connects these lifecycle events to endpoint management. Its documented identity orchestration model combines just-in-time provisioning with SCIM 2.0 lifecycle enforcement. A user can be created when they first authenticate, while later suspension or deletion events from a supported IdP can trigger downstream access changes.
When an account is disabled in a connected identity provider, Hexnode can send a real-time command to lock the associated device, terminate the active user session and prevent further login attempts.
Hexnode also documents how synchronized identity groups can drive application catalogs, device policies and security restrictions. This means a directory change can affect both access and the configuration of associated endpoints.
SureIdP supports individual user creation, CSV-based bulk import, group assignment and synchronization from external identity providers. Administrators can enable MFA, reset passwords, bind or unbind devices, disable users and delete accounts.
Hexnode’s advantage is the depth of the documented chain from identity-provider events to group membership, endpoint policy and access enforcement.
Hexnode IdP can evaluate user identity, device compliance and security context before granting access. Its connection to endpoint management helps make device posture part of the access decision, including scenarios involving managed and verified personal devices.
SureIdP authentication policies can restrict SAML application access by platform, user and device-management state. Administrators can select password or certificate-based passwordless authentication, require MFA and define a default allow-or-deny result when no rule matches.
Hexnode IdP provides policy-controlled application access, SSO, contextual authentication and step-up two-factor MFA for higher-risk actions. It also provides role-based access control so that permissions can reflect a user’s organizational function.
SureIdP provides SAML 2.0-based SSO for Microsoft Entra or Office 365, Google Workspace, Okta and custom SAML-compatible applications. Its authentication policies support passwords, certificate-based passwordless authentication and optional MFA.
Hexnode IdP explicitly documents inactivity-based session policies that limit how long unattended sessions remain accessible. It also centralizes reports covering sign-ins, provisioning activity and authentication history across users and applications.
These capabilities help IT and security teams investigate access activity, review provisioning changes and demonstrate that access policies are being applied consistently.
SureIdP supports authentication policies, user administration, device binding, OS-login enforcement, continuous identity verification and access revocation when configured conditions are no longer satisfied. It does not provide the same level of detail about centralized sign-in, provisioning and authentication-history reporting or inactivity-based application session controls.
Which solution fits your organization?
The right choice depends on your existing identity infrastructure and how closely identity needs to connect with endpoint policies. The following scenarios highlight where each platform may be the better fit.
- Hexnode IdP
- SureIdP
- The organization wants to preserve Microsoft Entra ID, Google Workspace, Okta or another established identity environment.
- Employees should use existing cloud credentials to access Windows and macOS devices.
- Multiple identity providers must coexist across business units, subsidiaries or regions.
- Identity attributes need to drive dynamic endpoint groups and UEM policy assignments.
- IT wants a documented combination of JIT provisioning, SCIM lifecycle enforcement and endpoint automation.
- Session governance and centralized identity activity reporting are important requirements.
- The organization wants an in-house identity provider managed within SureMDM.
- OS login must cover Windows, macOS and Linux.
- Device binding and contextual OS-login rules are primary requirements.
- The business is prepared for SureIdP to become the authentication authority for a federated Microsoft Entra domain.
- SAML-based application SSO and certificate-based passwordless access meet the organization’s application requirements.
Hexnode IdP vs 42Gears SureIdP: FAQs
Hexnode IdP focuses on connecting existing identity providers with application access, device trust and endpoint management. SureIdP is an in-house identity provider built into SureMDM, although it also supports user synchronization and federation with external identity platforms.
Yes. Hexnode integrates with identity environments such as Microsoft Entra ID, Google Workspace and Okta. Hexnode Access can extend supported cloud identities to Windows and macOS login while allowing the external provider to remain part of the organization’s authentication infrastructure.
Hexnode provides a more clearly documented architecture for enterprises operating multiple identity providers across regions, subsidiaries or business units. Its hub-and-spoke model supports centralized governance, regional identity environments, just-in-time provisioning, SCIM-based lifecycle management and identity attributes that can drive endpoint policy assignments.
Turn identity signals into endpoint action
Connect access decisions, user lifecycle changes and device management with Hexnode IdP.
Try Hexnode Idp