Identity & access management

MFA, SSO and identity management in Dubai

Most breaches start with a working password, not a clever exploit. Identity is the control that stops that — and the one most UAE businesses have half-finished. We design it, build it and hand it over, either as managed MFA or as an identity platform you own outright.

This is implementation work, not a licence

Anyone can sell you multi-factor authentication. The reason it so often stops at email is that the rest of it is a project: mapping which applications exist, working out which speak SAML or OIDC and which speak neither, deciding what happens to the VPN and the server consoles, agreeing what a contractor's access looks like, and getting through the rollout without the helpdesk drowning.

That project is what we do. The licence is the small part.

Two ways to do it

They lead to different places, and the right answer depends on how many people you have and how much you want to run yourself.

Cisco Duo — managed

A hosted MFA and access service. Push approval, passwordless, single sign-on, and device trust that checks whether the laptop asking for access is patched and encrypted before it gets in. Plugs into Active Directory and Entra ID, and into VPNs and server logins over RADIUS and LDAP.

Priced per user per month. Fastest to stand up, least for you to operate, and the usual answer when nobody on your team wants to own an identity platform.

authentik — self-hosted, open source

A full identity provider that runs on your own infrastructure. SAML, OIDC, LDAP, SCIM and RADIUS out of one system, plus a forward-auth proxy that puts a login in front of internal applications that have no SSO support of their own and never will.

No per-user licence. You own the data and the directory, it can run in our Dubai or Fujairah cloud or in your own rack, and it suits organisations with a lot of users, a lot of internal apps, or a requirement that identity data stays in the country.

Plenty of environments end up with both — Duo for staff MFA because it is quick and people like the app, authentik in front of internal tools where per-user pricing would be painful. We are not attached to either.

Duo or authentik — how to choose

Where it runsCisco's cloudYour infrastructure, or ours in the UAE
Cost shapePer user, per month, foreverHosting plus implementation; no per-user licence
Time to first rolloutDaysWeeks
Who operates itCisco, with us managing your tenantYou, or us under a support agreement
Apps with no SSO supportNetwork gateway for web apps and RDPForward-auth proxy in front of anything HTTP
Device trustBuilt in and maturePossible, more assembly required
Where identity data livesCisco's regionsWherever you put it, including in-country
Best fitSmall teams, no platform staff, fast rolloutLarger headcount, many internal apps, data-residency requirements

If you have been looking at Keycloak, the comparison is a fair one — it is the other serious open-source identity provider, it is more established, and it will do the job. authentik tends to be quicker to configure and has the application proxy built in rather than bolted on; Keycloak has the longer track record and the bigger ecosystem. We will implement either. What we would push back on is running one unsupported, with nobody named as its owner, which is how self-hosted identity turns into a liability.

What we actually implement

MFA everywhere, not just email

Microsoft 365 and Google Workspace, yes — but also the VPN, the server consoles, the firewall admin, the hypervisor, the remote desktop gateway and the finance system. The accounts an attacker actually wants are rarely the mailboxes.

Single sign-on across the applications you have

One login, one directory, one place to switch someone off. We work through the real inventory, including the two applications nobody documented and the one the finance team bought without telling anyone.

Joiners, movers and leavers

Accounts created from one source of truth and disabled the day someone leaves. The single most common finding in our assessments is former staff with live credentials, sometimes years after they left.

Conditional access

Rules that reflect how you work: unmanaged devices get less, access from outside the country prompts differently, the finance group is treated more strictly than everyone else.

Legacy applications

The on-premise system from 2013 with its own user table and no SSO support. A reverse proxy puts a real login in front of it without touching the application, which is usually the only option short of replacing it.

Privileged accounts

Domain admin, root, the shared service accounts and the emergency break-glass login. Separated from daily-use accounts, protected differently, and documented so nobody has to guess during an incident.

How a rollout runs

1. Inventory

Which applications, which directories, who has access to what today. This step always finds something nobody expected.

2. Design

Which platform, which policies, what happens to shared accounts and contractors, and what the exception process is — agreed before anything is switched on.

3. Pilot

IT first, then one willing department. Every rollout that skipped this step generated the helpdesk queue that gets the project paused.

4. Roll out and hand over

Group by group, with documentation and training for whoever runs it afterwards — your team or ours.

What we tend to find first

  • MFA on email and nowhere else. The VPN, the server console and the admin portals are still on a password alone.
  • Leavers with live accounts. Off the payroll, still in the directory, often still in the mailbox.
  • Shared logins. One administrator account used by four people, so no action can be attributed to anyone.
  • SMS as the second factor. Better than nothing, defeated by a SIM swap, and worth moving off for privileged accounts at least.
  • No break-glass account. Everything behind MFA, including the way back in when the identity provider is the thing that is broken.
  • Nobody owns identity. It belongs to whoever set up Microsoft 365, who has since changed jobs.

Start with what you already have

Most identity projects begin by finding out which accounts exist and what they can reach. That answer is usually uncomfortable, and it is the fastest security win available to most businesses.