Airlock identity- and access-management
The increasing automation and digitisation of business processes requires absolutely secure and efficient access procedures and this is precisely what Airlock’s customer identity and access management (cIAM) guarantees. The way in which users obtain authorisation to access data or applications is generally not standardised. This is where Airlock IAM comes in and offers centralised identity management and organisation of access permissions, for applications and APIs, alike. Integrated applications can be bundled as a single sign-on (SSO) group.
Airlock IAM is compatible with a wide spectrum of authentication methods and, therefore, offers various industries an easily integrated option for efficient user and access-rights management based on modern standards.
Airlock IAM is often used in combination with Airlock Gateway and Airlock Microgateway to protect web applications and APIs (WAAP) within the Airlock Secure Access Hub. Airlock IAM’s role is to manage and authenticate users and to forward the relevant identity information to the desired application in an appropriate form.
Identity-centric security
The trusted combination of IAM and WAAPAirlock Secure Access Hub is the central hub for secure access management in a digitalized world: identity-centric security from a single source, perfectly designed to work together. The following graphic illustrates the interaction of IAM and WAAP.
The digital identity (r)evolution
Find out how companies are preparing for the transition to decentralized identities.
In the white paper, Martin Kuppinger, founder and principal analyst at KuppingerCole, provides an assessment of decentralized identities and government activities in Europe.
The white paper was created in collaboration with KuppingerCole and PXL-Vision.
Friendly to users. Relentless to uninvited guests.
The Airlock components work together to provide maximum ease of use and effective protection without compromise. The diagram illustrates how this works.
Click on the (+) symbols to learn more about the Airlock components.
Protection against cyberattacks on APIs and applications
Be it malicious bots, zero-day exploits or typical attacks according to OWASP Top 10: Airlock Gateway keeps undesirable and malicious visitors away from your web applications and APIs, e.g. with hardened filter rules and anomaly detection based on machine learning. And in conjunction with Airlock IAM, only authenticated and authorized users are granted access to the application.
Protect yourself today from the risks of tomorrow.
Authentication and access control
Airlock's Identity and Access Management guarantees secure and efficient access to digital services. Users benefit from an excellent user experience and single sign-on, in combination with Airlock Gateway even for non-standard applications. Airlock IAM protects against identity theft and shines with flexible registration and login flows including a large number of authentication methods.
Ensure user-friendly and secure access to your applications.
Distributed security checks for modern applications
Application protection for today's APIs and tomorrow's microservices: Airlock Microgateway is designed for use in Kubernetes environments. Security policies and compliance can be perfectly automated thanks to Security as Code. This ensures better integration of security and governance throughout the DevSecOps lifecycle. Modern zero-trust architectures also benefit from micro-segmentation and distributed access controls.
Protect your cloud-native applications.
Gateway
IAM
Microgateways
From our point of view, the greatest advantages of Airlock IAM include the adaptability of the solution, the standardized connection options for new applications and surrounding systems, modularity and expandability. This project has clearly shown that the combination of a well thought-out architecture with the right product decision and the choice of the right partner leads to success.
Albert Frei, Head of Enterprise Platforms, Bank Vontobel AG
Airlock IAM
Highlights- Flexible Authentication
- Strong authentication, 2FA / MFA
- Step-up and step-down authentication
- Adaptive or risk-based authentication
- Continuous Adaptive Trust
- Extensive list of authentication methods (including FIDO, WebAuthN and Passkeys)
- Own, fully integrated 2FA solution
- Passwordless authentication
- Single sign-on (SSO)
- Identity federation
- User self-service options
- Social registration and logins (BYOI)
- Delegated user administration + helpdesk options
- Powerful REST API
- Loginapp Design Kit
Airlock 2FA
Airlock 2FA is integrated into Airlock IAM and makes strong authentication possible with a second factor. Every customer has the management and use of their personal keys on their smartphone (iOS and Android).
Airlock 2FA offers modern authentication methods such as one touch, offline QR code, passcode and passwordless. This user-friendly and future-proof solution is also cost-efficient.
The entire functionality is implemented as a REST API and therefore enables seamless integration into modern single page applications (SPA) and native smartphone apps.
Airlock IAM 8.3
User-Centered SecurityVersion 8.3 brings numerous new features for increased flexibility in OpenID Connect configurations, more targeted event notifications, enhanced security against modern threats in Airlock 2FA, and much more.
Customer IAM vs. Workforce IAM
Unlike workforce IAM systems, cIAM systems such as Airlock IAM focus on managing external users accessing in-house systems. cIAM systems are designed for simple scalability and large numbers of users. They also provide a seamless user experience, with optimized, integrated user interfaces for onboarding and self-services. Airlock IAM’s capacity for handling social identities (BYOI) and a high degree of flexibility in the authentication process (Continuous Adaptive Trust) are two of its greatest strengths.
Features
The authentication platform Airlock IAM provides versatile features that make it easy for you to securely manage your users.
Connecting to user directories
cIAM projects generally do not start as a blank slate. Airlock IAM’s integrated user management has thus been to easily connect to existing user databases and directories such as LDAP and Active Directory.
Authentication
Airlock supports a variety of methodsAdaptive authentication
Airlock IAM can dynamically manage user access in a range of ways, striking the perfect balance between security and user-friendliness for all requirements. In particular, it is possible to consider the real-time circumstances of the access attempt, for example, from the workplace, home or on the road, and a user’s access history. Supported concepts include:
- RBAC/ABAC (role/attribute-based access control)
- Risk-based authentication
- Step-up and step-down authentication
- Re-authentication and time-out functions for individual roles
- Implementation of complex access policies via rules and logical operators
Strong authentication, broad selection
Strong authentication with two factors, also known as multi-factor authentication or MFA, is often used to ensure that a login is not compromised by the vulnerabilities of any single authentication method. Flexible combination options are especially important here and Airlock IAM is compatible with a range of solutions, including use with a password, FIDO / WebAuthn, Mobile TAN (mTAN), email OTP, OATH OTP, client certificates, as well as OneSpan Cronto-Sign and many more.
With Airlock 2FA, the cIAM offers the most modern methods of 2-factor authentication. 2FA is integrated directly into the IAM as a REST API.
Single Sign-On (SSO) standards
The Secure Access Hub decouples the individual accesses from the applications and can, therefore, act as a smart identity switch. Depending on to where an access attempt is being forwarded, the identity of the authenticated user can be represented differently. This enables transparent, single sign-on that combines high levels of security with high user acceptance.
Airlock IAM supports a range of SSO standards and formats, including SAML 2.0, Kerberos, OAuth 2.0, OpenID Connect, HTTP headers, URL tickets, and others.
Social registration and BYOI
Users want to register and log in quickly and easily. To avoid creating even more passwords, they can reuse existing identities, e.g. with BYOI (Bring Your Own Identity). An alternative to the password mess are the standards OAuth 2.0 and OpenID Connect. These allow the re-use of identities and give users more control. Should you not wish to rely entirely on an external identity provider, such as Facebook, Airlock IAM can add a second factor to these identities to enable strong authentication.
OAuth 2.0 is HTTP-based and, therefore, ideally suited to protect RESTful web services. When it comes to authorising access to enterprise APIs, for example to enable partners to access them, these standards are ideally suited.
Comprehensive user self-service options
Registration and login processes raise many questions among users. An optimised user experience is therefore of utmost importance to avoid overloading the helpdesk. Airlock IAM offers dozens of optimised and integrated UIs for login, onboarding and self services. These include kiosk and portal functions for managing one's own data, self-registration (also via social media channels) and the management of the corresponding accounts and tokens, including migration workflows. The integrated consent management can also help to solve DSGVO requirements for connected applications quickly and easily.
Deployment
- Docker image
- Self-contained application
Ready for excellent IT security?
Contact us now.Airlock IAM 8.0
Mit Vollgas in die CloudIAM ist für den Betrieb in der Cloud optimiert. Mit der Version 8.0 freuen sich Betreiber, Administratoren und Helpdesk-Benutzer über zahlreiche neue Funktionen und eine flüssigere Bedienung. Die Administrationsoberfläche hat zudem einem kleines Facelifting erhalten.