Apache Syncope
ATH Infosystems · Software Development
Certification per Microsoft Marketplace.
Evidence tier Source Confirmed · 2 captures on record
What the publisher says
As described on Microsoft Marketplace.
Apache Syncope is an open-source Identity and Access Management (IAM) and Identity Governance Administration (IGA) platform designed to manage digital identities, user provisioning, authentication, authorization, and access control across enterprise environments. It provides a centralized solution for identity lifecycle management and integration with cloud and on-premises applications.
The solution supports user and group management, role-based access control, delegated administration, workflow-driven provisioning, auditing, reporting, and integration with directories, databases, and enterprise applications. It is suitable for organizations seeking secure identity governance, compliance management, and automated user lifecycle operations.
Show the rest of the publisher’s description (24 more lines)
Version: Apache Syncope 4.1.2 (Azure Marketplace Image Version 1.0.0)
Features of Apache Syncope:
- Centralized Identity and Access Management (IAM) platform.
- User, group, role, and entitlement management.
- Automated user provisioning and deprovisioning workflows.
- Role-Based Access Control (RBAC) and delegated administration.
- Support for LDAP, Active Directory, databases, and external systems.
- REST APIs for integration and automation.
- Support for SAML 2.0, OpenID Connect (OIDC), and SCIM standards.
- Audit logging, compliance reporting, and governance capabilities.
- Web-based administrative console for identity management.
- Runs automatically through Docker containers after VM startup.
Usage instructions for Apache Syncope:
$ sudo su
$ cd /opt/syncope
$ docker compose ps
$ docker compose restart syncope
$ docker compose restart syncope-console
$ docker compose restart syncope-db
Access the Apache Syncope Administration Console:
Open your browser and navigate to:
http://your-server-ip:28080/syncope-console/
After opening the Administration Console, configure users, groups, roles, resources, connectors, and external identity repositories according to your organization's requirements. Additional integrations such as LDAP, Active Directory, SAML, OpenID Connect, and SCIM can be configured through the administrative interface.
Disclaimer: Apache Syncope is provided “as is” under the Apache License 2.0. Users are responsible for securing administrative credentials, configuring network access, implementing backup and disaster recovery procedures, maintaining compliance requirements, and validating all identity management policies before use in production environments.
Agent build and provenance
See the full provenance
The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.
Compliance
- FedRAMPConfirmedNot listed90%, registry-checkedNo FedRAMP Marketplace entry matched this vendor's domain, checked 2026-08-27registry recordas observed 2026-08-27
Confirmed means matched to a public authoritative registry. Claimed means the vendor or its listing states it, not yet cross-checked. A framework not shown was not found in any source we hold, which is not evidence against it. Not listed means a scoped registry check found no match for this vendor's domain: a No is a scoped registry check, not a compliance judgment. Confidence bands: 95% domain-verified, 90% registry-checked, 80% self-attested, 70% weak signal. Self-attested items marked “vendor's site” are gathered from the vendor's own website and are not verified by us.
Vendor
External enrichment · as of 2026-08-29
Reconciled on 9/3/2026
Sources
Publisher resources
1 linkLinked repositories
Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.
Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.

