Atlas Identity
Identity & Access Management
One identity per person, SSO everywhere, MFA by policy — built on open standards you host yourself, with no identity-provider lock-in.
Why this exists
Without Atlas Identity
Users have separate accounts for every system. Password reuse is inevitable. When someone leaves, accounts are manually disabled one by one over days. There is no audit trail of who accessed what. A compliance auditor asks for an access control matrix — there is none.
With Atlas Identity
One identity per user. One authentication event covers every system. Leavers are disabled in one place and locked out everywhere in seconds. MFA enforced by policy. Keycloak federates SAML and OIDC so cloud apps join the SSO domain. The entire access control matrix is exportable for any audit.
Architecture
Regulatory compliance
| Regulation / Control | Requirement | Audit evidence |
|---|---|---|
| NIS2 Art. 21(2)(i) | Multi-factor authentication for all privileged accounts and remote access | Keycloak MFA audit log · failed login alerts |
| NIS2 Art. 21(2)(j) | Role-based access, leavers process, periodic access review | Keycloak RBAC policy export · user lifecycle report |
| GDPR Art. 5(1)(f) | Only authorised persons access personal data | Keycloak session audit · FreeIPA access policy export |
| GDPR Art. 32(1)(b) | Ongoing confidentiality and integrity of processing systems | FreeIPA sudo rules · Keycloak role mapping export |
| BSI ORP.4 | Documented RBAC, leavers deprovisioning, privileged access management | FreeIPA user/group report · Keycloak session log |
| DORA Art. 9(4)(c) | Least privilege, separation of duties, regular access review | Keycloak user export · privilege review log |
Standalone installation
Each component can be deployed independently. Download the Customer Request Form, describe your environment, and we quote within 2 business days.
Keycloak SSO — standalone install
Keycloak 24.x on Podman or Docker Compose. Realm config. One OIDC client integrated (OpenCloud, Gitea, or custom app). LDAP/AD federation. Basic RBAC roles defined.
€ 620
Net, excl. VAT · travel within 100km Hamburg · hardware not included
Download CRF & request quoteMFA enforcement — TOTP/WebAuthn
Enable TOTP (Google Authenticator / FreeOTP) or WebAuthn (FIDO2) on existing Keycloak or Active Directory. Enrolment flow. Policy exceptions for break-glass accounts. Zabbix alert on MFA bypass attempt.
€ 340
Net, excl. VAT · travel within 100km Hamburg · hardware not included
Download CRF & request quoteOpenSCAP compliance scan
CIS Benchmark Level 2 or DISA STIG scan on up to 10 Linux hosts. Findings mapped to NIS2/BSI controls. Remediation report with severity classification. One re-scan included after remediation.
€ 480
Net, excl. VAT · travel within 100km Hamburg · hardware not included
Download CRF & request quoteReady-made boxes
Three boxes, three fixed prices. Each one ships pre-configured and pre-hardened: you power it up, work through a short quick-start guide, and it runs. No audit, no project phase, no consulting engagement required. Need it fitted into an existing environment instead? See the consulting packages below.
5–50 users · 1 site · single server
€ 1,980
Net, excl. VAT · one-off fixed price · hardware not included
50–500 users · 1–5 sites · HA-ready
€ 2,650
Net, excl. VAT · one-off fixed price · hardware not included
500+ users · multi-site · cluster-ready
€ 3,380
Net, excl. VAT · one-off fixed price · hardware not included
Consulting services
The boxes are built to run on their own. When you want one fitted into what you already have, add a fixed-price package — no open-ended day rates.
Installation & handover
We install the box in your environment, connect it to your network and DNS, and hand it over configured and documented. Remote, or on-site within 100 km of Hamburg.
€ 890
Net, excl. VAT · fixed price
Request this packageIntegration into your environment
Connecting the box to what you already run — Active Directory, an existing DNS or firewall, your monitoring or SIEM — including migration of existing data.
€ 1,890
Net, excl. VAT · fixed price
Request this packageCompliance mapping & audit support
We map the delivered configuration to NIS2, BSI IT-Grundschutz or DORA controls and hand over the evidence package your auditor will ask for.
€ 1,490
Net, excl. VAT · fixed price
Request this packageAzure AD (now Microsoft Entra ID) ties your identities to the US cloud and a per-user subscription. Keycloak and FreeIPA provide single sign-on (SSO), MFA and directory services as a self-hosted open-source alternative — your identity data stays under your control, on-premises or in an EU cloud of your choice.
SAML, OAuth2/OIDC and LDAP are supported, so your existing applications stay connected without a Microsoft dependency. We migrate users and groups and hand over the documented configuration.
Copyright © XpertOne Security Consulting GmbH. All Rights Reserved. | Impressum | Datenschutz