Himmelblau - Himmelblau
Initializing search
Himmelblau
Cloud identity for Linux
SSO, MFA, compliance, and TPM-backed keys across Entra ID/Intune and OIDC providers such as Keycloak and Okta — with a practical path toward sovereign cloud identity.
Start installation<br>See how it works ↓
Scroll to explore
One identity plane
Your cloud identity should follow users to every Linux session.
Remote servers and graphical workstations are different security contexts. Himmelblau gives each the right authentication experience while connecting both to the same Entra ID, PAM, and NSS foundation.
⌁Remote access Cloud credentials + native MFA<br>◉Desktop access Device-bound Hello PIN
ssh tux@192.168.1.73
01Connect as a Cloud user
Himmelblau resolves the cloud identity as a Linux account through NSS—without pre-creating a local user.
02Authenticate with the Identity Provider
PAM hands the request to Himmelblau. The exact credential flow follows the authentication methods configured by the Identity Provider.
03Complete native MFA
MFA happens inside the SSH experience.
04Enter the shell
The authenticated cloud identity arrives as a normal POSIX session, ready for shared hosts, remote administration, and group-based access control.
01Choose the cloud account<br>“Not listed?” opens a prompt for entering your Cloud identity username.
02Establish identity<br>The user signs in with their Cloud credentials and the tenant’s configured authentication requirements.
03Satisfy MFA<br>Native MFA is presented at the Linux greeter, keeping the first-login journey in one coherent flow.
04Enroll a Hello PIN<br>The PIN unlocks a cryptographic credential tied to this device. With a hardware TPM configured, key material can be hardware-backed.
05Start the session<br>The desktop opens as the Cloud user, with the identity and token foundation needed by browser and application SSO.
01Wake the workstation<br>Return to the familiar local lock screen on the enrolled Linux device.
02Enter the device-bound PIN<br>The user authenticates locally with the Hello PIN enrolled during their first sign-in.
03Unlock the protected credential<br>Himmelblau validates the PIN and unlocks the cryptographic credential bound to this device.
04Continue the workday<br>The desktop opens with native SSO integration.
01Applications feel native<br>Launch Outlook, Teams, Word, Excel, and PowerPoint from the desktop rather than rebuilding the workday around browser tabs.
02Browser SSO<br>PRT-based authentication lets supported browsers reach Entra-protected services without another full sign-in.
03<br>Outlook, already signed in
Open Outlook from the desktop and get straight to mail and calendar with the same authenticated identity.
04<br>Meet in Teams
Join Teams meetings from Linux without breaking the flow of your desktop workspace.
05<br>Work in Word
Create and edit Microsoft 365 documents while remaining connected to your Entra identity.
06<br>Build in Excel
Work with spreadsheets from the Linux desktop without another round of authentication.
07<br>Present with PowerPoint
Open presentations directly from the desktop and keep the Microsoft 365 workflow connected end to end.
Intune integration
Linux devices, visible and compliant.
Himmelblau brings Linux devices into the Intune view and can apply compliance at authentication time.
Linux device registration<br>Compliance status in Intune<br>Policy enforcement during authentication
Explore Intune policy integration →
Linux devices reporting compliant in the Intune admin center.
GPLv3+Open source by design Review the implementation, follow development, and contribute on GitHub.
Security programGitHub Secure Open Source Fund Himmelblau participated in GitHub’s project security initiative.
Security engineeringPatch the Planet participant Himmelblau is participating in the OpenAI and Trail of Bits initiative that pairs AI-assisted research with expert review to find, validate, and patch security issues in open-source software.<br>Program overview →OpenAI announcement →
Featured in iX MagazineRead independent technical coverage of Himmelblau. Read the article →<br>Evaluating your options?<br>Compare Himmelblau with Authd, SSSD, and Intune for Linux.
Compare solutions →
Ready when you are
Bring your Linux systems into the identity plane.
The guided installer uses the native package manager, configures the identity provider, and starts the Himmelblau services.
curl -fsSL https://himmelblau-idm.org/install | shCopy
Review scripts before running them in your environment.
Package optionsDeployment documentation
SUSEopenSUSEUbuntuMintDebianFedoraRHELRockyOracleAlmaAmazonNixOS
Built by and for the community. Ask questions, report issues, help test, or support continued development.