Connect Entra ID SSO to QS-WAN
Your administrators sign in to the console with the Microsoft account they already have, and your people get their VPN profile from behind a Microsoft sign-in window. There’s no second staff list to keep in step.
Our kernel drivers are attested by Microsoft, and QuantumNova is accredited by Portugal’s National Cybersecurity Centre.
Yes, QS-WAN works with Microsoft Entra ID
QS-WAN supports Entra ID SSO in two places. Administrators pick Entra ID from the provider list on the QS-WAN sign-in screen and sign in with the Microsoft work account they already have. On a device, QNova Client opens an embedded Microsoft sign-in window, and the token that comes back authorises a certificate to be issued for that device.
Three places you'd notice it working
One for the directory you already run, one for the morning your identity provider doesn’t answer, and one for the person who just wants to get online.
Sign in with the account you already have
The QS-WAN sign-in screen offers three providers, labelled Default, Entra ID and Local AD. Pick Entra ID and your administrator signs in with their existing work account, so the console never asks you to keep a second copy of your staff list. When somebody leaves, you remove them where you already remove them, and there’s no forgotten second account still working six months later.
Keep a way back in when the identity provider goes quiet
Local credentials keep working even when the identity provider is down, and that’s deliberate. Sending every administrator through one outside service is how a network becomes unreachable by the people paid to fix it. When an Entra ID sign-in does fail, that path reports five phase messages, so you can see which stage broke instead of reading somebody else’s documentation at 8am. The [Local AD path](/platform/integrations/active-directory/) is the same idea with a different directory, and it carries ten separate error codes.
Hand out device profiles without a portal or an emailed token
On the endpoint, the user opens [QNova Client](/platform/qnova-client/), picks Entra ID, and an embedded Microsoft window opens inside the app. They sign in, the token authorises a certificate for that device, and the profile arrives. There’s no enrolment portal to hunt for and nobody has to explain what a certificate is on a Tuesday morning, which is one fewer call for your helpdesk. Entra ID is one of four ways to get a profile onto a device, so the estates that need automatic, local Active Directory or manual import still have them.
What leaves, what stays, and what we haven't published yet
Entra ID stays Microsoft’s and your directory stays yours. The console sends an administrator to Entra ID to sign in, and the client asks the same question before a device gets a profile. The cryptography stays on the device: QNova Client generates its own key pair locally, the private keys are written into the protected profile and never sent anywhere, and only the public keys are registered. The token authorises the certificate to be issued. It doesn’t become the credential, and it isn’t what protects the tunnel afterwards.
- Entra ID stays your system of record. QS-WAN sends administrators to it and doesn't ask you to run a second directory beside it.
- The device makes its own keys. Private keys are written into the protected profile and never sent anywhere; only the public keys are registered.
- The token authorises the certificate. It's an entry ticket, not the credential the device uses afterwards.
- Local console accounts keep working when Entra ID doesn't. They're your way back in, so treat those passwords like the fallback they now are.
- Our kernel drivers are attested by Microsoft. That's the whole claim. It isn't a partnership and we won't stretch it into one.
- We haven't published the exact list of Entra ID attributes the console reads and keeps. If your DPO needs that list before signing, ask and we'll put it in writing.
Tell us what's on the other end
Which directory signs your administrators in today, Entra ID, on-premises Active Directory, or both at once while you finish the migration?