Frequently Asked Questions


 

Questions that we hear the most. If yours is not here, ask us.
cirrus logo in cloud and circle



About Cirrus

What does Cirrus Identity do?

Cirrus is an authentication proxying company. Our products sit between the identity providers an institution runs and the applications and federations its people need to reach, handling the translation and the operational work in between.

We work with more than 200 institutions in higher education and research. Every member of our leadership team came from higher education identity management.

 

What is the difference between Bridge and Proxy?

Bridge connects one authentication provider to many applications. Proxy connects many authentication providers to one or more applications.

Bridge is for institutional users reaching federated and legacy applications. Proxy is for people who do not have institutional credentials at all.

 

Is Cirrus a replacement for Entra ID or Okta?

No. Both products extend your existing authentication provider rather than replacing it. Your users continue to sign in exactly as they do today.

 

What is InCommon and do we have to be a member?

InCommon is the identity federation for US research and education. It maintains shared metadata that lets thousands of applications and institutions trust each other without configuring each relationship individually. eduGAIN connects InCommon to equivalent federations in other countries.

You do not have to be a member to work with Cirrus, but most Bridge customers either are members or are joining. If you are not sure whether your institution is registered, InCommon's Federation Manager is where you would check.

 

Cirrus Bridge

Why can't Entra ID, Okta, or Duo SSO join InCommon on their own?

Enterprise authentication providers are built around bilateral trust. You configure one application at a time, exchanging metadata with each service provider individually.

Multilateral federation works the other way. Thousands of applications and institutions trust each other through metadata published and maintained by a federation operator, and the membership changes constantly. Enterprise authentication providers do not support that model natively.

Microsoft says as much in its own documentation on multilateral federation with Entra ID, where Cirrus Bridge is the first listed solution.

 

Will our users notice anything different?

No. Users authenticate with your authentication provider exactly as they do today, on the same sign-in screen. Bridge sits behind that interaction and has no user interface of its own.

 

Do we have to reconfigure our applications?

In most cases, no.

The DNS Add-On redirects your existing federation endpoint to Bridge. Applications keep pointing where they always pointed, and federation registration stays as it is. Applications move together at cutover rather than one at a time.

 

Does Bridge support SAML applications that are not in federation?

Yes. The base subscription includes up to ten bilaterally integrated SAML or CAS applications, on top of unlimited federated applications. More can be added.

Some institutions route campus applications through Bridge temporarily to accelerate a migration, then move them to their authentication provider directly over time. Others keep them on Bridge long term. Both are supported.

 

Does our MFA still apply?

Yes. Authentication is fully mediated by your authentication provider, so MFA, conditional access, device management, and logging all apply to federated access the same way they apply to any other application.

This works with Duo as an external authentication method in Entra ID, with Microsoft Authenticator, and with other configurations. Many of our customers run Entra ID with Duo.

 

What does rollback look like?

Reversing the DNS change. Traffic returns to your previous environment.

 

How long does implementation take?

It varies with the number of applications and how ready your environment is. A straightforward deployment for a new federation member can be a couple of weeks. An institution retiring existing infrastructure with a large application inventory is more often two to three months.

The main variable is not technical. It is whether you can coordinate the people needed to test before cutover.

 

Who does the work during implementation?

You do, with our team guiding. Configuration happens in your authentication provider's portal, and most of it is yours to control. Our implementation leads meet with you regularly, review your configuration against patterns that have worked at other institutions, and stay with you through testing and production.

 

How long does an evaluation take?

Most Bridge evaluations take one call. There is no user interface to walk through, so the technical review is short, and the conversation is usually about your applications and your timeline rather than about the product.

 

How is Bridge priced?

An annual subscription plus a one-time implementation fee. The subscription is based on annual authentications hitting the bridge, in tiers.

The tier is a soft cap. If your volume exceeds it, we prorate to the next tier rather than interrupting service.

 

What is included in the subscription?

Integration with all InCommon, CAF, or GakuNin applications. Up to ten bilaterally integrated SAML or CAS applications. Ninety days of authentication event logs, viewable and downloadable. Cloud hosting with no patching or upgrades. 24x365 production support for critical events.

 

Can we get authentication logs into our SIEM?

Ninety days of event logs are included and downloadable from the console. The Log API add-on streams events to a SIEM or another application in real time through a REST API.

 

 

Cirrus Proxy

Who is Proxy for?

People your institution serves who do not have campus credentials, or should not have them yet. Applicants, parents, alumni, retirees, continuing education learners, contractors, community members, clinical participants, and colleagues at partner institutions.

 

Why not just create accounts for them in our authentication provider?

Some institutions do, and it works until it does not.

The costs show up as licensing for people who sign in twice a year, provisioning and deprovisioning overhead, accounts that stay active long after the relationship ended, and credential formats that do not fit the enterprise directory. Institutions partway through a migration often find these users are the reason the project stalls.

 

Can applicants sign in before they have campus credentials?

Yes. If your institution uses Slate, applicants can use their Slate credentials to reach financial aid, housing, or other campus applications before they are provisioned campus accounts.

This lets you move credential creation from acceptance to enrollment confirmation, so you are not creating accounts for students who never arrive.

 

What can people sign in with?

Personal and social providers including Google, Microsoft, LinkedIn, Amazon, Apple, and ORCID iD. Credentials from other InCommon and eduGAIN institutions. Slate credentials. Or OrgBrandedID, a hosted username and password credential that we operate rather than you.

 

Do you store our users' personal data?

No, not unless you ask us to. Our default is transient: we pass the authentication through and keep no record of the user beyond 90 days of event logs. Some use cases need a persistent record, and that is a configuration you choose rather than a default you inherit.

 

Security, Compliance, and Procurement

Is Cirrus SOC 2 compliant?

Yes. We complete an annual SOC 2 Type II audit and third-party penetration testing. Our HECVAT is published and available without a request.

 

What are your support hours?

24x365 for critical production events, business hours for questions and routine requests. Service level agreements are published.

 

Do you work with resellers?

Yes. We work with several, and purchasing through a reseller your institution already has an agreement with is often faster than contracting with us directly, because it avoids a separate legal review. If your institution belongs to a consortium or cooperative purchasing group, let us know.

 

 

Description Goes Here