Check this [SaaS Deployment Guide](https://github.com/aws-quickstart/saas-identity-cognito) out from AWS.
HN user
mmaha
Work in the Identity and Access Management area.
[ my public key: https://keybase.io/mmaha; my proof: https://keybase.io/mmaha/sigs/V8-CmzBLyvBxN598aUzf2AVcExKv8sna0slHJgdAQc4 ]
https://findkismet.com/# : ee6f65
[Disclaimer: I work for Okta]
Sorry about the confusing product and pricing page.There are typically two different scenarios for pricing: Users can be employees, consultants, contractors etc. or Users can be consumers, customers etc. Depending on the context, the pricing differs.
Not only can you remove the user/employee from the centralized service (Okta) but you can also hook-up to various HR systems (if you so desire) like AD, Workday, Ultipro, BambooHR etc. and have them act authoritatively to determine if an employee is employed, on-leave or has terminated their employment.
[1] If you work for a Startup, you may want to consider https://www.okta.com/blog/2017/12/okta-for-startups-launches...
Disclaimer: I work for Okta.
Have you considered Okta [http://www.okta.com] for your enterprise needs?
Check out Nymi [https://www.nymi.com/], also in this space.
+1. Any SAML enabled (or WS-FED) site can be integrated with Okta to offer 2FA.
Okta (www.okta.com) is hiring. Ton of roles: Check it out here: http://www.okta.com/company/careers.html
Please feel free to contact me (email in profile) for any details. Challenging problems to solve in an interesting area.
Oracle contributions to Linux: http://www.oracle.com/us/technologies/linux/026042.htm