Why this exists

The problem Atlas Identity solves

Without Atlas Identity

Users have separate accounts for every system. Password reuse is inevitable. When someone leaves, accounts are manually disabled one by one over days. There is no audit trail of who accessed what. A compliance auditor asks for an access control matrix — there is none.

With Atlas Identity

One identity per user. One authentication event covers every system. Leavers are disabled in one place and locked out everywhere in seconds. MFA enforced by policy. Keycloak federates SAML and OIDC so cloud apps join the SSO domain. The entire access control matrix is exportable for any audit.

Architecture

How it works

Atlas Identity — SSO federation flow
Architecture overview — Atlas Identity component relationships

Regulatory compliance

What Atlas Identity satisfies

Regulation / ControlRequirementAudit evidence
NIS2 Art. 21(2)(i)Multi-factor authentication for all privileged accounts and remote accessKeycloak MFA audit log · failed login alerts
NIS2 Art. 21(2)(j)Role-based access, leavers process, periodic access reviewKeycloak RBAC policy export · user lifecycle report
GDPR Art. 5(1)(f)Only authorised persons access personal dataKeycloak session audit · FreeIPA access policy export
GDPR Art. 32(1)(b)Ongoing confidentiality and integrity of processing systemsFreeIPA sudo rules · Keycloak role mapping export
BSI ORP.4Documented RBAC, leavers deprovisioning, privileged access managementFreeIPA user/group report · Keycloak session log
DORA Art. 9(4)(c)Least privilege, separation of duties, regular access reviewKeycloak user export · privilege review log

Standalone installation

Install one component — no full integration required

Each component can be deployed independently. Download the Customer Request Form, describe your environment, and we quote within 2 business days.

Keycloak SSO — standalone install

Keycloak 24.x on Podman or Docker Compose. Realm config. One OIDC client integrated (OpenCloud, Gitea, or custom app). LDAP/AD federation. Basic RBAC roles defined.

  • Realm + client config
  • LDAP/AD federation
  • 1 OIDC application integrated
  • RBAC role mapping
  • 5-day post-install support

€ 890

Net, excl. VAT · travel within 100km Hamburg · hardware not included

Download CRF & request quote

MFA enforcement — TOTP/WebAuthn

Enable TOTP (Google Authenticator / FreeOTP) or WebAuthn (FIDO2) on existing Keycloak or Active Directory. Enrolment flow. Policy exceptions for break-glass accounts. Zabbix alert on MFA bypass attempt.

  • TOTP or WebAuthn policy
  • Enrolment flow + user comms template
  • Break-glass exception process
  • Zabbix alert hook
  • 5-day post-install support

€ 590

Net, excl. VAT · travel within 100km Hamburg · hardware not included

Download CRF & request quote

OpenSCAP compliance scan

CIS Benchmark Level 2 or DISA STIG scan on up to 10 Linux hosts. Findings mapped to NIS2/BSI controls. Remediation report with severity classification. One re-scan included after remediation.

  • OpenSCAP scan on up to 10 hosts
  • CIS Benchmark L2 or DISA STIG
  • Remediation report (severity-mapped)
  • NIS2/BSI control mapping
  • One re-scan included

€ 790

Net, excl. VAT · travel within 100km Hamburg · hardware not included

Download CRF & request quote
Note: Standalone components do not include cross-product integration. Full Atlas Identity integration — connecting it into your existing environment — starts with an audit engagement.

Full integration

Foundation · Plus · Enterprise

Full integration starts with a 2–3 week audit. XpertOne maps your existing environment, identifies gaps, and produces a fixed-price statement of work. On-site engineer included for the full integration period.

Foundation

5–50 users · 1 site · 1 month on-site

1 month on-site

from € 14,400

Net, excl. VAT · fixed price scoped by audit

  • Keycloak SSO (single node)
  • LDAP/AD federation
  • TOTP MFA enforcement
  • Basic RBAC policy
  • WireGuard VPN for remote users
  • OpenSCAP baseline scan
  • Documentation + runbook
Request audit to start
Enterprise

500+ users · multi-site · 6 months on-site

6 months on-site

from € 96,000

Net, excl. VAT · fixed price scoped by audit

  • FreeIPA multi-master replication
  • Keycloak cluster (3+ nodes)
  • SAML federation with external IdPs
  • SCIM just-in-time provisioning
  • PAM for privileged sessions
  • ISO 27001 access control evidence
  • Full user lifecycle automation
Request audit to start

An Azure AD / Entra ID alternative: self-hosted SSO

Azure AD (now Microsoft Entra ID) ties your identities to the US cloud and a per-user subscription. Keycloak and FreeIPA provide single sign-on (SSO), MFA and directory services as a self-hosted open-source alternative — your identity data stays under your control, on-premises or in an EU cloud of your choice.

SAML, OAuth2/OIDC and LDAP are supported, so your existing applications stay connected without a Microsoft dependency. We migrate users and groups and hand over the documented configuration.

Start with an audit

All integration engagements begin with a 2–3 week technical audit. The audit is a paid engagement producing a gap analysis, architecture recommendation, and fixed-price statement of work.

Request audit engagement