Identity
Identity And Access Management
The directory you already run, reachable from anywhere over an encrypted overlay, with single sign-on and multi-factor in front of it.
We extend the Active Directory you already run out over the internet through an encrypted peer-to-peer overlay, so a laptop in another city authenticates against your domain controller without a VPN concentrator and without a single port exposed to the public internet. On top of that sits a full identity provider: OIDC, SAML 2.0, LDAP, WebAuthn and passkeys, with policy-driven access per application. The directory stays yours, on your hardware, under your audit.
Built on an open-source identity core, packaged and hardened by us, and supported by the same engineers who deploy it. No per-seat licence to a third-party identity vendor.
Who It Is For
- Organisations keeping Active Directory on-premises
- Teams replacing per-seat identity subscriptions
- Teams with a compliance deadline for multi-factor coverage
What It Extends
The Active Directory you already run, unchanged and still on your premises
How It Travels
An encrypted peer-to-peer overlay, with no VPN concentrator and no public directory port
What Sits On Top
A full identity provider: single sign-on, multi-factor, per-application policy
Where Records Live
In your own database, exportable, on infrastructure you control rather than a tenant
Specification
Protocols
OIDC, OAuth 2.0, SAML 2.0, LDAP, SCIM
Factors
TOTP, WebAuthn, passkeys, push
Directory
On-premises Active Directory, reachable over the overlay
Policy
Per-application access and step-up rules
Transport
Encrypted peer-to-peer fabric, no VPN concentrator
Exposure
No public ports, no forced cloud tenant
What You Get
One Login, Every Application
SaaS, internal tools and legacy LDAP applications sit behind one sign-on flow over OIDC and SAML 2.0, with session lifetime and step-up policy set once rather than argued about per vendor.
Active Directory Stays Where It Is
The domain controllers stay on your premises. We carry them over an encrypted overlay so branch offices, home workers and remote sites resolve and authenticate against the same directory, with no Azure AD tenant, no forced sync and no cloud vendor holding the keys to your staff accounts.
Multi-Factor Without The Rollout Pain
Passkeys and WebAuthn first, TOTP as the fallback, enforced per application by policy. High-risk systems get step-up authentication; low-risk ones do not, so the rollout does not stall on user pushback.
Yours To Audit
The identity provider is self-hosted on an open-source core with a complete, exportable event log. When an auditor or an insurer asks who accessed what and when, the record is in a database you control.
How It Works
Five stages, in the order we run them. Applications move behind sign-on one at a time, never in a single weekend.
Inventory
We list the directories, the applications and the people who use them, then mark which applications speak OIDC or SAML 2.0, which only speak LDAP, and which will need a proxy standing in front of them.
Join The Overlay
Sites, servers and endpoints join an encrypted peer-to-peer fabric. Domain controllers stay exactly where they are and stop needing a port forwarded, a concentrator sized, or a tunnel up before a remote worker can log in.
Stand Up The Provider
The identity provider is deployed against your directory as the source of truth. Groups, attributes and organisational units drive policy in place, rather than being copied into somebody else's tenant and reconciled forever after.
Connect Applications
Applications move behind single sign-on in an order you set, starting with the ones that hurt least. Legacy software that cannot speak a modern protocol sits behind the LDAP outpost or a forward-auth proxy instead of staying outside.
Enforce Factors
Passkeys and WebAuthn go first, TOTP covers what cannot take them, and step-up rules apply only to the systems that warrant them. Coverage is reported per application, so it is a fact rather than an assumption.
Against Moving To Azure AD
The usual alternative is lifting identity into a cloud tenant. These are the axes on which the two choices actually diverge.
Where Identity Lives
- Moving To Azure AD
- A cloud tenant operated by the vendor, kept in step with your directory by a sync agent
- Infinite Networks IAM
- Your on-premises Active Directory, still authoritative, reached over an encrypted overlay
Commercial Model
- Moving To Azure AD
- Per user per month, with the controls you need often sitting in a higher tier
- Infinite Networks IAM
- Self-hosted on an open-source core, quoted as an engagement rather than counted per seat
Reach For Remote Staff
- Moving To Azure AD
- Endpoints published to the public internet, protected by the vendor's front door
- Infinite Networks IAM
- A peer-to-peer fabric between known members, with no directory port exposed publicly
Audit Records
- Moving To Azure AD
- Retained according to the tenant plan and exported through the vendor's interface
- Infinite Networks IAM
- A complete event log in a database you hold, exportable on your own terms
Legacy Applications
- Moving To Azure AD
- Older LDAP-only software usually needs a separate bridge or stays outside sign-on
- Infinite Networks IAM
- LDAP, SAML 2.0 and OIDC are served by one provider, so old and new sit behind one login
Leaving
- Moving To Azure AD
- Accounts, policy and history live inside the tenant you would be walking away from
- Infinite Networks IAM
- The directory, the policy set and the log stay on your infrastructure either way
What We Need From You
Identity work is mostly discovery. The more of this you can send at the start, the shorter the discovery is.
A Directory Snapshot
Forest and domain layout, roughly how many accounts are live, and the organisational units and groups that genuinely drive access rather than the ones nobody has cleaned up.
An Application List
Every system people sign into, with the protocol each one supports where you know it. A guess is fine here; confirming it is our job, not yours.
Your Sites
Offices, data centres, home workers and anything else that needs to reach the directory, plus what the links between them look like today.
A Policy Position
Which systems warrant step-up authentication, how long a session should live, and who on your side is allowed to approve an exception to either.
A Pilot Group
A department willing to be first. Identity rollouts stall on user experience far more often than they stall on protocol.
Send what you have and an integration plan comes back, with a rollout order set application by application rather than all at once.
Start An EnquiryQuestions About Identity
The objections we hear in the first conversation about identity.
No. This is built around the directory you already run. The domain controllers stay on your premises and stay authoritative, and we carry them between sites while putting a modern identity provider in front of them.
Not in the usual sense. There is no concentrator to size and no single tunnel that has to be up before anything works. Members of the overlay establish encrypted peer-to-peer connections directly, so a laptop reaching a domain controller does not have to route through one appliance first.
An open-source identity provider at the core. We package it, harden the deployment, integrate it with your directory and support the result. The core staying open is exactly why the event log and the configuration remain yours, and why you are never negotiating with us for access to your own data.
Yes. Microsoft 365 speaks SAML 2.0 and OIDC like any other application, so it can sit behind our sign-on. Keeping a Microsoft subscription and keeping your directory on your own premises are two separate decisions.
Users on the same local network as a domain controller continue to authenticate against it exactly as they always have. The overlay carries the directory between sites; it does not sit in the path of a login that never leaves the building.
Map Your Identity Estate
Send us the applications and directories in play and we will reply with an integration plan and a rollout order, application by application.
Sales
- New servers, identity rollouts and workstation pilots
- Specifications, sizing and monthly pricing
- Moving an existing estate across to us
sales@infinite-networks.net
Support
- Anything already running with us
- Incidents, capacity changes and restores
- Accounts, access and policy changes
support@infinite-networks.net
Office
#002, Ceaser's CastleSainikpuri, Defence Colony
Hyderabad 500 094
India
