Self-hosted Workforce Login for 40,000 Employees
The Challenge
Coop needed a secure and user-friendly workforce login platform for 40,000 employees accessing web sites, applications, and mobile apps daily. The solution had to run inside Coop's internal Kubernetes environment, support strong authentication through either two-factor login or MitID, and still provide seamless single sign-on on the internal network. Mobile apps also required long-lived sessions protected by biometric, allowing users to remain signed in while the app quietly obtained new access tokens as needed. At the same time, employee identities had to be synchronised from the internal IAM infrastructure.
The Solution
By self-hosting FoxIDs in an internal Kubernetes environment, Coop established a central identity layer for workforce access. FoxIDs presents a customised, user-friendly login experience where employees can authenticate using either two-factor login or MitID. On the internal network, FoxIDs integrates with AD FS to provide seamless single sign-on. For mobile apps, FoxIDs issues long-lived refresh tokens protected by device biometrics, allowing users to maintain extended sessions while the app retrieves fresh access tokens when opened. Login monitoring, cross-device logout, and continuous access checks are handled centrally by FoxIDs, while employee identities are synchronised from Coop's internal IAM infrastructure.
The Result
Coop now has a self-hosted identity platform aligned with its internal operating model, providing employees with consistent access to the web sites, applications, and mobile apps they use every day. Authentication adapts to assurance requirements with MitID and two-factor login, while AD FS still delivers frictionless single sign-on on the internal network. Mobile users benefit from long sessions secured by biometrics and long-lived refresh tokens, access decisions are enforced continuously when fresh tokens are requested, and IT can monitor and terminate sessions across devices centrally in FoxIDs.