ZSoftly Cloud Platform
Professional Services

Authentik Implementation

Replace per-user identity licensing with a platform you own. SSO, MFA, and federation on your infrastructure, implemented and managed by ZSoftly.

Overview

Okta, CyberArk, and JumpCloud all price identity per user per month, so your security budget scales with headcount whether or not your risk does. Authentik is an open-source identity provider that can replace common workforce SSO, MFA, federation, and lifecycle use cases, confirmed against your environment during assessment, on infrastructure you own.

ZSoftly handles the full lifecycle: TCO assessment against your current renewal, deployment on ZCP or your own environment, migration from your current platform, and managed operations after go-live. Your team gets the outcome without becoming identity operators.

What this service covers

  • TCO comparison against your current Okta, CyberArk, or Active Directory spend
  • Authentik deployment on ZCP or your infrastructure
  • Migration of users, groups, and application federation
  • MFA rollout, offboarding automation, and audit-ready logging
  • Managed operations, upgrades, and 24/7 monitoring with defined response SLAs

The Business Case

What changes for your budget, your auditors, and your risk register.

Cost Optimization

Identity spend stops tracking headcount. You pay for the infrastructure Authentik runs on, sized and fixed during assessment, instead of a per-user subscription renegotiated at every renewal.

Compliance Without the Scramble

Every login, permission change, and policy decision lands in an audit trail you own. Access reviews, offboarding evidence, and SOC 2 or HIPAA control mapping come from the platform, not a quarter-end spreadsheet exercise.

Risk You Control

Your login flow runs on infrastructure you govern. Dependency on a third-party identity control plane goes away, recovery is designed around infrastructure you control, and your security team can inspect the code guarding the directory.

Authentik Platform Capabilities

Complete workforce identity on one self-hosted platform.

Single Sign-On & Federation

Every protocol your applications speak

  • SAML 2.0, OAuth2, and OIDC
  • WS-Federation for Windows apps such as SharePoint
  • Sign-in via Google, GitHub, Entra ID, Kerberos, or any upstream IdP
  • OIDC back-channel logout

Multi-Factor Authentication

Strong authentication for every login

  • Passkeys, WebAuthn, and FIDO2 security keys
  • TOTP apps, email and SMS one-time codes, Duo push
  • Conditional access with GeoIP and impossible-travel detection
  • Brute-force throttling on every factor

Directory & Provisioning

One source of truth for users and groups

  • Active Directory, Samba AD, and LDAP sync
  • LDAP and RADIUS interfaces for legacy systems
  • SCIM provisioning with policy-based filtering
  • Outbound sync to Google Workspace and Microsoft Entra

Application Access

Every app behind the same policy

  • Application proxy for apps with no SSO support
  • Browser-based remote access to RDP, SSH, and VNC
  • Per-app access policies with RBAC
  • Self-service user portal with an app library

Custom Flows & Policies

Login journeys shaped to your rules

  • Customizable login, enrollment, and recovery flows
  • Expression policies for fine-grained decisions
  • Invitation-based onboarding
  • Per-brand theming on your own domains

Automation & Compliance

Identity as code, evidence on demand

  • Configuration as code with blueprints and Terraform
  • Full REST API for every object
  • Object lifecycle reviews for audit cycles
  • FIPS-ready configuration with authentik Enterprise

What Authentik Can Replace, Feature by Feature

The capabilities SMBs and enterprises evaluate identity platforms for, the outcome each delivers, and the line item it can retire. Fit is confirmed during assessment.

Capability Business outcome What you stop paying for
SSO portal for every app One login for the whole company, fewer password resets and help-desk tickets Okta End-User Dashboard, CyberArk Identity portal
SAML 2.0 and OIDC federation Every cloud and internal app behind the same access policy Okta SSO, CyberArk Identity, AD FS
Multi-factor authentication Phishing-resistant login with TOTP, WebAuthn, and FIDO2 keys enforced everywhere Okta Verify, Duo, CyberArk Identity MFA
Central directory and LDAP One source of truth for who works here and what they reach Active Directory, AD LDS
User lifecycle and SCIM provisioning Day-one access for new hires, same-day revocation for departures Okta Lifecycle Management
Permissions and RBAC Access mapped to roles, so reviews take hours instead of weeks Okta groups, Active Directory security groups
Self-service password reset Recovery flows users complete without a help-desk ticket Okta, Active Directory SSPR add-ons
Social and external IdP login Contractors and partners sign in with Google, GitHub, or Microsoft Entra ID Okta external identity federation
Legacy app protection Apps with no SAML or OIDC support still sit behind SSO and MFA Okta Access Gateway
RADIUS for WiFi and VPN Network access tied to the same identity and the same offboarding switch Active Directory NPS
Audit logs and compliance evidence SOC 2 and HIPAA evidence exported from the platform on demand Okta System Log

CyberArk entries refer to CyberArk Identity, the workforce SSO and MFA product. Privileged credential vaulting and session recording remain a dedicated PAM concern; see the checklist below.

Where Authentik Fits, and Where It Does Not

An honest scope line keeps your identity project out of trouble.

Authentik can replace

  • Okta SSO, federation, MFA, and lifecycle subscriptions
  • CyberArk Identity workforce login portal and MFA
  • AD FS and its Windows server footprint
  • Active Directory as the LDAP source for cloud-first teams
  • Per-user, per-month identity licensing

Keep a dedicated tool for

  • Privileged credential vaulting and session recording (CyberArk PAM)
  • Windows device management and Group Policy (we pair Authentik with JumpCloud)
  • Microsoft-only environments built around GPO and Exchange
  • Teams that want identity fully managed as SaaS (JumpCloud)

Start with the IdP You Already Run

Most companies already have an identity provider: Google Workspace, or Microsoft 365 with Entra ID. The question is what you add to it, and that depends on the requirement.

Your Suite + Authentik

Federation and cost

Keep Google Workspace or Entra ID as the user source and let Authentik federate it outward: one SSO portal for every app, custom login flows, and LDAP and RADIUS for systems the suite cannot reach, at a cost that stays flat as headcount grows.

Your Suite + JumpCloud

Devices and fleets

Keep the suite as the identity source and add JumpCloud when the requirement is the fleet: cross-OS device management, patching, and endpoint policy in one managed console.

Authentik as the Core

Standalone core

No suite IdP, retiring Active Directory, or login data that must stay in your jurisdiction: Authentik becomes the directory and identity core itself, self-hosted on infrastructure you own. Still need a Windows domain? We pair it with Samba AD, so the whole stack stays open source.

How the Engagement Runs

Wave-based migration with a rollback path at every step. No big-bang cutover.

1

Assess

Phase 1

We inventory applications, users, and current identity spend, then deliver a TCO comparison and migration plan your CFO can read.

2

Pilot

Phase 2

Authentik runs alongside your current platform while a pilot group signs into real applications through it. Nothing cuts over yet.

3

Migrate

Phase 3

Applications move in waves with rollback at each step. Users keep working; the login page changes and nothing else.

4

Operate

Ongoing

We run upgrades, monitoring, and support, or hand your team the runbooks. Access-review reporting comes with the managed service.

Questions Your Board Will Ask

Is open source dependable enough for company-wide login?

Authentik is commercially backed open source with a dedicated security team and a public disclosure process. Your engineers can inspect the code guarding your directory, and ZSoftly hardens, patches, and monitors the deployment in production.

What does it cost to run compared with Okta or CyberArk?

A typical deployment is a small set of VMs and a database, a flat monthly cost we size during assessment. The assessment includes a line-by-line comparison against your current renewal, so the decision is made on your numbers, not ours.

How disruptive is the migration?

Applications move in waves while your current platform keeps running, with rollback at each step. Users see a new login page and keep their accounts and access. A failed wave rolls back in minutes, not days.

Who supports it at 2 a.m.?

ZSoftly managed IAM operations covers 24/7 monitoring with defined response SLAs, plus upgrades and incident response. Prefer to run it in-house? We hand over hardened infrastructure, runbooks, and training instead.

We use CyberArk for privileged access. Does this replace it?

No. Authentik replaces the workforce SSO and MFA layer, including CyberArk Identity. Privileged credential vaulting and session recording stay in your PAM tool, and we integrate the two so privileged access sits behind the same SSO and MFA.

See the Numbers for Your Team

Bring your current identity renewal. The assessment shows what the same capabilities cost when you own the platform.