About this policy
Effective date: September 10, 2026.
Org Login — Entra SSO is maintained by the Org Login project for R92 Corporation. It connects a locally installed Linux identity broker to Microsoft Entra sign-in in Firefox and Chrome/Chromium. This policy describes the browser extension, not the independent policies of Microsoft, your organization, your browser vendor or your desktop identity broker.
Information the extension handles
Account information: name, username or email address, account and tenant identifiers, and profile photo.
Authentication information: broker-issued tokens and SSO authentication headers used to authenticate the selected account. The desktop broker manages desktop credentials independently.
Device information: device identifiers available in authentication claims, device display name, compliance status, and broker connection/version status.
Website and sign-in information: the active tab’s URL or domain for per-site SSO controls, permitted site origins, and Microsoft sign-in tab URLs. On eligible Microsoft authorization pages, a bundled script checks page elements and whether input fields are nonempty before retrying an untouched sign-in once. This includes checking for account-selection, consent and MFA prompts. These page checks run locally; field values are not saved or sent by this retry script. The extension does not record keystrokes, mouse movements or a browsing-history log.
Why this information is used
The extension uses this information to display and select desktop accounts, reuse the desktop sign-in on supported Microsoft Entra sites, refresh authentication headers, show account and device status, manage site permissions, and retry sign-in when the broker becomes ready after the page loads. Data is not used for advertising, profiling unrelated to authentication, creditworthiness or lending. The extension has no R92-operated analytics or telemetry endpoint.
Where information is processed and shared
The extension exchanges account and authentication messages with the locally installed orglogin_entra_sso native messaging host and desktop broker. It sends broker-provided SSO authentication headers to Microsoft’s login.microsoftonline.com sign-in service. Microsoft Graph requests retrieve the profile photo and device information using the account’s access token. Microsoft and your organization process those requests under their own policies and configuration.
The extension does not send account data, tokens or browsing information to an R92 collection service, sell user data, or transfer it to advertisers or data brokers. Browser vendors may separately process installation and update information through their extension stores. Opening this policy website contacts GitHub Pages; GitHub states that it logs visitors’ IP addresses for security. That hosting activity is separate from the extension. This policy page contains no analytics scripts or forms.
Storage and retention
Browser-local extension storage retains account selection, account metadata including cached photos, and SSO enabled/paused state. Browser permissions and managed settings retain approved-site configuration. Runtime account and device state, including temporary access tokens, is held in memory or browser session storage. Authentication header rules are session-scoped and refreshed while SSO is enabled. The retry script stores a one-time retry marker in the Microsoft page’s session storage.
Cached data is replaced as state is refreshed. Temporary extension session data and rules normally expire when the browser session ends; local preferences can persist across restarts until cleared or the extension is removed. Desktop broker credentials and Microsoft website sessions have independent lifecycles. R92 does not operate a server-side store of this extension data.
Your controls
You can select an account, pause SSO, revoke optional site permissions, or uninstall the extension using browser controls. Disabling SSO removes its authentication header rules; it does not necessarily erase every cached item, sign you out of Microsoft websites, or remove your desktop account. Use browser extension-data controls to clear cached extension data, Microsoft website controls to end website sessions, and your organization’s tools to manage desktop credentials. Contact your administrator if site permissions or account access are managed by your organization.
Security and limited use
Microsoft service requests use HTTPS. Native broker communication stays on the local machine. The extension does not download and execute remote JavaScript or WebAssembly.
Org Login — Entra SSO’s use and transfer of information received from Google APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. Data is used only for the extension’s stated SSO features and is not sold or used for unrelated purposes or lending decisions.
Changes and contact
We will update this page and its effective date when the extension’s data practices change.
For privacy questions, contact the publisher through the public issue tracker at https://github.com/ziadsaleemi/orglogin-privacy/issues. Issues are public: describe your question without including passwords, tokens, MFA codes, account identifiers or other private information.