+1 646 851 2603

What Is External Authentication in FileMaker?

August 29, 2026

External authentication allows FileMaker users to sign in using identities managed outside the FileMaker database file.

Instead of maintaining a separate username and password in every FileMaker custom app, an organization can use an existing directory or identity provider.

FileMaker Server supports several forms of external authentication, including Active Directory, Open Directory, OAuth 2.0, and OpenID Connect.

Authentication and authorization

Authentication answers the question:

Who is this user?

Authorization answers a different question:

What is this user allowed to do?

An external identity provider authenticates the user. FileMaker’s privilege sets continue to determine which records, layouts, scripts, and features that user can access.

Using OAuth or Active Directory does not move the FileMaker security model outside the custom app. It connects an externally managed identity or group to a FileMaker privilege set.

External server authentication

FileMaker’s traditional external server authentication integrates with operating-system and directory accounts.

Depending on the server platform and configuration, this may include:

  • Microsoft Active Directory
  • Apple Open Directory
  • Local accounts and groups on the FileMaker Server machine
  • Active Directory Federation Services in supported Linux configurations

In FileMaker Pro, the developer creates an External Server account access entry using the name of an external group. That entry is assigned a FileMaker privilege set.

When a member of that group signs in, the external server verifies the credentials and FileMaker applies the associated privilege set.

Although LDAP is often mentioned when discussing directory services, FileMaker does not simply connect to any arbitrary LDAP directory. It supports specific external authentication environments such as Active Directory and Open Directory.

OAuth and OpenID Connect

FileMaker Server can also authenticate users through supported OAuth identity providers.

These include predefined providers such as:

  • Microsoft
  • Google
  • Apple
  • Amazon
  • AD FS
  • fmcloud.fm (based on Keycloak)

Current versions can also use a custom OAuth or OpenID Connect identity provider.

This makes it possible to integrate FileMaker with modern identity platforms and organizational authentication policies.

OAuth authentication is configured in FileMaker Server Admin Console. Corresponding OAuth user or group access entries are then created in the FileMaker custom app and assigned to privilege sets.

fmcloud.fm has its own OAuth service, based on Keycloak, which allows you fine-tuning your authentication, 2-factor authentication (MFA), and password recovery policy.

What is Single Sign-On?

Single Sign-On, or SSO, allows a user who has already authenticated with an organizational identity system to access FileMaker without entering another independent password.

Traditional Windows SSO can be provided through an appropriate Active Directory and FileMaker Server configuration.

OAuth or OpenID Connect can provide a broader sign-in experience through an external identity provider, often combined with multifactor authentication and centralized access policies.

SSO is not a separate FileMaker security model. It is an authentication experience built on top of a correctly configured identity provider, FileMaker Server, client, and custom app.

Why use external authentication?

External authentication can provide:

  • Centralized user administration, especially worthy if you have multiple files.
  • Faster removal of access when an employee leaves
  • Organizational password policies
  • Multifactor authentication through the identity provider
  • Reduced password duplication
  • Group-based access management (not supported by all providers)
  • A more consistent sign-in experience
  • Integration with an existing identity strategy

It is particularly useful when an organization has several FileMaker files or many users.

Important security considerations

External authentication must be implemented carefully.

Group names and their priority determine which privilege set a user receives. A person belonging to several matching groups may receive the privileges of the first matching account access entry.

Organizations should also retain a secure FileMaker account with Full Access. This provides an emergency administrative path if the external identity provider or network is unavailable.

Database encryption, SSL certificates, identity-provider security, and careful privilege-set design remain essential. External authentication does not compensate for an overly permissive FileMaker security model.

Authentication expertise from fmcloud.fm

At fmcloud.fm, we help organizations integrate FileMaker Server with Microsoft Entra ID, Active Directory, OAuth providers, OpenID Connect, and other identity platforms.

Our role covers both the FileMaker custom app and its hosted environment: provider configuration, callback URLs, SSL certificates, group mapping, account priority, privilege sets, and client behavior.

We also have our own authentication system (OAuth, based on Keycloak), if you need more flexibility in your security policy.

This complete approach is important because a successful sign-in does not by itself guarantee a secure implementation. The external identity must still be mapped to the correct FileMaker permissions.

Learn more

You may also like…

What Is Linux?

In the FileMaker ecosystem, Linux is one of the operating systems on which FileMaker Server can run. Its importance...

15-day Free Hosting

Start your journey with us and discover fmcloud.fm now.