Atlas Identity
Identity & Access Management
One identity per person, SSO everywhere, MFA by policy — built on open standards you host yourself, with no identity-provider lock-in.
Why this exists
Without Atlas Identity
Users have separate accounts for every system. Password reuse is inevitable. When someone leaves, accounts are manually disabled one by one over days. There is no audit trail of who accessed what. A compliance auditor asks for an access control matrix — there is none.
With Atlas Identity
One identity per user. One authentication event covers every system. Leavers are disabled in one place and locked out everywhere in seconds. MFA enforced by policy. Keycloak federates SAML and OIDC so cloud apps join the SSO domain. The entire access control matrix is exportable for any audit.
Architecture
Regulatory compliance
| Regulation / Control | Requirement | Audit evidence |
|---|---|---|
| NIS2 Art. 21(2)(i) | Multi-factor authentication for all privileged accounts and remote access | Keycloak MFA audit log · failed login alerts |
| NIS2 Art. 21(2)(j) | Role-based access, leavers process, periodic access review | Keycloak RBAC policy export · user lifecycle report |
| GDPR Art. 5(1)(f) | Only authorised persons access personal data | Keycloak session audit · FreeIPA access policy export |
| GDPR Art. 32(1)(b) | Ongoing confidentiality and integrity of processing systems | FreeIPA sudo rules · Keycloak role mapping export |
| BSI ORP.4 | Documented RBAC, leavers deprovisioning, privileged access management | FreeIPA user/group report · Keycloak session log |
| DORA Art. 9(4)(c) | Least privilege, separation of duties, regular access review | Keycloak user export · privilege review log |
Standalone installation
Each component can be deployed independently. Download the Customer Request Form, describe your environment, and we quote within 2 business days.
Keycloak SSO — standalone install
Keycloak 24.x on Podman or Docker Compose. Realm config. One OIDC client integrated (OpenCloud, Gitea, or custom app). LDAP/AD federation. Basic RBAC roles defined.
€ 890
Net, excl. VAT · travel within 100km Hamburg · hardware not included
Download CRF & request quoteMFA enforcement — TOTP/WebAuthn
Enable TOTP (Google Authenticator / FreeOTP) or WebAuthn (FIDO2) on existing Keycloak or Active Directory. Enrolment flow. Policy exceptions for break-glass accounts. Zabbix alert on MFA bypass attempt.
€ 590
Net, excl. VAT · travel within 100km Hamburg · hardware not included
Download CRF & request quoteOpenSCAP compliance scan
CIS Benchmark Level 2 or DISA STIG scan on up to 10 Linux hosts. Findings mapped to NIS2/BSI controls. Remediation report with severity classification. One re-scan included after remediation.
€ 790
Net, excl. VAT · travel within 100km Hamburg · hardware not included
Download CRF & request quoteFull integration
Full integration starts with a 2–3 week audit. XpertOne maps your existing environment, identifies gaps, and produces a fixed-price statement of work. On-site engineer included for the full integration period.
5–50 users · 1 site · 1 month on-site
from € 14,400
Net, excl. VAT · fixed price scoped by audit
50–500 users · multi-site · 3 months on-site
from € 42,000
Net, excl. VAT · fixed price scoped by audit
500+ users · multi-site · 6 months on-site
from € 96,000
Net, excl. VAT · fixed price scoped by audit
Azure AD (now Microsoft Entra ID) ties your identities to the US cloud and a per-user subscription. Keycloak and FreeIPA provide single sign-on (SSO), MFA and directory services as a self-hosted open-source alternative — your identity data stays under your control, on-premises or in an EU cloud of your choice.
SAML, OAuth2/OIDC and LDAP are supported, so your existing applications stay connected without a Microsoft dependency. We migrate users and groups and hand over the documented configuration.
All integration engagements begin with a 2–3 week technical audit. The audit is a paid engagement producing a gap analysis, architecture recommendation, and fixed-price statement of work.
Request audit engagementCopyright © XpertOne Security Consulting GmbH. All Rights Reserved. | Impressum | Datenschutz