Authentik Implementation
Replace per-user identity licensing with a platform you own. SSO, MFA, and federation on your infrastructure, implemented and managed by ZSoftly.
Overview
Okta, CyberArk, and JumpCloud all price identity per user per month, so your security budget scales with headcount whether or not your risk does. Authentik is an open-source identity provider that can replace common workforce SSO, MFA, federation, and lifecycle use cases, confirmed against your environment during assessment, on infrastructure you own.
ZSoftly handles the full lifecycle: TCO assessment against your current renewal, deployment on ZCP or your own environment, migration from your current platform, and managed operations after go-live. Your team gets the outcome without becoming identity operators.
What this service covers
- TCO comparison against your current Okta, CyberArk, or Active Directory spend
- Authentik deployment on ZCP or your infrastructure
- Migration of users, groups, and application federation
- MFA rollout, offboarding automation, and audit-ready logging
- Managed operations, upgrades, and 24/7 monitoring with defined response SLAs
The Business Case
What changes for your budget, your auditors, and your risk register.
Cost Optimization
Identity spend stops tracking headcount. You pay for the infrastructure Authentik runs on, sized and fixed during assessment, instead of a per-user subscription renegotiated at every renewal.
Compliance Without the Scramble
Every login, permission change, and policy decision lands in an audit trail you own. Access reviews, offboarding evidence, and SOC 2 or HIPAA control mapping come from the platform, not a quarter-end spreadsheet exercise.
Risk You Control
Your login flow runs on infrastructure you govern. Dependency on a third-party identity control plane goes away, recovery is designed around infrastructure you control, and your security team can inspect the code guarding the directory.
Authentik Platform Capabilities
Complete workforce identity on one self-hosted platform.
Single Sign-On & Federation
Every protocol your applications speak
- SAML 2.0, OAuth2, and OIDC
- WS-Federation for Windows apps such as SharePoint
- Sign-in via Google, GitHub, Entra ID, Kerberos, or any upstream IdP
- OIDC back-channel logout
Multi-Factor Authentication
Strong authentication for every login
- Passkeys, WebAuthn, and FIDO2 security keys
- TOTP apps, email and SMS one-time codes, Duo push
- Conditional access with GeoIP and impossible-travel detection
- Brute-force throttling on every factor
Directory & Provisioning
One source of truth for users and groups
- Active Directory, Samba AD, and LDAP sync
- LDAP and RADIUS interfaces for legacy systems
- SCIM provisioning with policy-based filtering
- Outbound sync to Google Workspace and Microsoft Entra
Application Access
Every app behind the same policy
- Application proxy for apps with no SSO support
- Browser-based remote access to RDP, SSH, and VNC
- Per-app access policies with RBAC
- Self-service user portal with an app library
Custom Flows & Policies
Login journeys shaped to your rules
- Customizable login, enrollment, and recovery flows
- Expression policies for fine-grained decisions
- Invitation-based onboarding
- Per-brand theming on your own domains
Automation & Compliance
Identity as code, evidence on demand
- Configuration as code with blueprints and Terraform
- Full REST API for every object
- Object lifecycle reviews for audit cycles
- FIPS-ready configuration with authentik Enterprise
What Authentik Can Replace, Feature by Feature
The capabilities SMBs and enterprises evaluate identity platforms for, the outcome each delivers, and the line item it can retire. Fit is confirmed during assessment.
| Capability | Business outcome | What you stop paying for |
|---|---|---|
| SSO portal for every app | One login for the whole company, fewer password resets and help-desk tickets | Okta End-User Dashboard, CyberArk Identity portal |
| SAML 2.0 and OIDC federation | Every cloud and internal app behind the same access policy | Okta SSO, CyberArk Identity, AD FS |
| Multi-factor authentication | Phishing-resistant login with TOTP, WebAuthn, and FIDO2 keys enforced everywhere | Okta Verify, Duo, CyberArk Identity MFA |
| Central directory and LDAP | One source of truth for who works here and what they reach | Active Directory, AD LDS |
| User lifecycle and SCIM provisioning | Day-one access for new hires, same-day revocation for departures | Okta Lifecycle Management |
| Permissions and RBAC | Access mapped to roles, so reviews take hours instead of weeks | Okta groups, Active Directory security groups |
| Self-service password reset | Recovery flows users complete without a help-desk ticket | Okta, Active Directory SSPR add-ons |
| Social and external IdP login | Contractors and partners sign in with Google, GitHub, or Microsoft Entra ID | Okta external identity federation |
| Legacy app protection | Apps with no SAML or OIDC support still sit behind SSO and MFA | Okta Access Gateway |
| RADIUS for WiFi and VPN | Network access tied to the same identity and the same offboarding switch | Active Directory NPS |
| Audit logs and compliance evidence | SOC 2 and HIPAA evidence exported from the platform on demand | Okta System Log |
CyberArk entries refer to CyberArk Identity, the workforce SSO and MFA product. Privileged credential vaulting and session recording remain a dedicated PAM concern; see the checklist below.
Where Authentik Fits, and Where It Does Not
An honest scope line keeps your identity project out of trouble.
Authentik can replace
- Okta SSO, federation, MFA, and lifecycle subscriptions
- CyberArk Identity workforce login portal and MFA
- AD FS and its Windows server footprint
- Active Directory as the LDAP source for cloud-first teams
- Per-user, per-month identity licensing
Keep a dedicated tool for
- Privileged credential vaulting and session recording (CyberArk PAM)
- Windows device management and Group Policy (we pair Authentik with JumpCloud)
- Microsoft-only environments built around GPO and Exchange
- Teams that want identity fully managed as SaaS (JumpCloud)
Start with the IdP You Already Run
Most companies already have an identity provider: Google Workspace, or Microsoft 365 with Entra ID. The question is what you add to it, and that depends on the requirement.
Your Suite + Authentik
Keep Google Workspace or Entra ID as the user source and let Authentik federate it outward: one SSO portal for every app, custom login flows, and LDAP and RADIUS for systems the suite cannot reach, at a cost that stays flat as headcount grows.
Your Suite + JumpCloud
Keep the suite as the identity source and add JumpCloud when the requirement is the fleet: cross-OS device management, patching, and endpoint policy in one managed console.
Authentik as the Core
No suite IdP, retiring Active Directory, or login data that must stay in your jurisdiction: Authentik becomes the directory and identity core itself, self-hosted on infrastructure you own. Still need a Windows domain? We pair it with Samba AD, so the whole stack stays open source.
How the Engagement Runs
Wave-based migration with a rollback path at every step. No big-bang cutover.
Assess
Phase 1We inventory applications, users, and current identity spend, then deliver a TCO comparison and migration plan your CFO can read.
Pilot
Phase 2Authentik runs alongside your current platform while a pilot group signs into real applications through it. Nothing cuts over yet.
Migrate
Phase 3Applications move in waves with rollback at each step. Users keep working; the login page changes and nothing else.
Operate
OngoingWe run upgrades, monitoring, and support, or hand your team the runbooks. Access-review reporting comes with the managed service.
Questions Your Board Will Ask
Is open source dependable enough for company-wide login?
Authentik is commercially backed open source with a dedicated security team and a public disclosure process. Your engineers can inspect the code guarding your directory, and ZSoftly hardens, patches, and monitors the deployment in production.
What does it cost to run compared with Okta or CyberArk?
A typical deployment is a small set of VMs and a database, a flat monthly cost we size during assessment. The assessment includes a line-by-line comparison against your current renewal, so the decision is made on your numbers, not ours.
How disruptive is the migration?
Applications move in waves while your current platform keeps running, with rollback at each step. Users see a new login page and keep their accounts and access. A failed wave rolls back in minutes, not days.
Who supports it at 2 a.m.?
ZSoftly managed IAM operations covers 24/7 monitoring with defined response SLAs, plus upgrades and incident response. Prefer to run it in-house? We hand over hardened infrastructure, runbooks, and training instead.
We use CyberArk for privileged access. Does this replace it?
No. Authentik replaces the workforce SSO and MFA layer, including CyberArk Identity. Privileged credential vaulting and session recording stay in your PAM tool, and we integrate the two so privileged access sits behind the same SSO and MFA.
See the Numbers for Your Team
Bring your current identity renewal. The assessment shows what the same capabilities cost when you own the platform.