Authentication & authorization

User authentication, access control, and secure device enrollment in DeviceHub.

To safeguard your data, DeviceHub employs a comprehensive security framework grounded in industry-standard authentication and authorization.

This framework incorporates a range of security features that ensure only verified and appropriately authorized users can access DeviceHub, namely:

Identity & Access Management:

DeviceHub uses the Microsoft Entra service for authentication. Organizations can enable Single-Sign-On (SSO) or allow users to register for the service with an email address.
  • Single-Sign-On (SSO) is supported with the following protocols: SAML 2.0, OpenID Connect, OAuth 2.0.

Multi-factor Authentication (MFA):

Multi-factor authentication (MFA) is available to all users through single sign-on (SSO). Support via Sennheiser’s own solution, using a second email verification code, will follow soon.

Role-Based Access Control (RBAC):

Assign roles to users to control permissions. Current roles include Organization Owner and Location Admin, with more coming soon. For a detailed description, please refer to the DeviceHub user documentation.

Device Enrollment:

Devices can be securely enrolled in Sennheiser DeviceHub to enable cloud-based device control, using a time-limited enrollment code.