Identity

Identity And Access Management

The directory you already run, reachable from anywhere over an encrypted overlay, with single sign-on and multi-factor in front of it.

We extend the Active Directory you already run out over the internet through an encrypted peer-to-peer overlay, so a laptop in another city authenticates against your domain controller without a VPN concentrator and without a single port exposed to the public internet. On top of that sits a full identity provider: OIDC, SAML 2.0, LDAP, WebAuthn and passkeys, with policy-driven access per application. The directory stays yours, on your hardware, under your audit.

Built on an open-source identity core, packaged and hardened by us, and supported by the same engineers who deploy it. No per-seat licence to a third-party identity vendor.

Who It Is For

  • Organisations keeping Active Directory on-premises
  • Teams replacing per-seat identity subscriptions
  • Teams with a compliance deadline for multi-factor coverage

What It Extends

The Active Directory you already run, unchanged and still on your premises

How It Travels

An encrypted peer-to-peer overlay, with no VPN concentrator and no public directory port

What Sits On Top

A full identity provider: single sign-on, multi-factor, per-application policy

Where Records Live

In your own database, exportable, on infrastructure you control rather than a tenant

Specification

Protocols

OIDC, OAuth 2.0, SAML 2.0, LDAP, SCIM

Factors

TOTP, WebAuthn, passkeys, push

Directory

On-premises Active Directory, reachable over the overlay

Policy

Per-application access and step-up rules

Transport

Encrypted peer-to-peer fabric, no VPN concentrator

Exposure

No public ports, no forced cloud tenant

What You Get

One Login, Every Application

SaaS, internal tools and legacy LDAP applications sit behind one sign-on flow over OIDC and SAML 2.0, with session lifetime and step-up policy set once rather than argued about per vendor.

Active Directory Stays Where It Is

The domain controllers stay on your premises. We carry them over an encrypted overlay so branch offices, home workers and remote sites resolve and authenticate against the same directory, with no Azure AD tenant, no forced sync and no cloud vendor holding the keys to your staff accounts.

Multi-Factor Without The Rollout Pain

Passkeys and WebAuthn first, TOTP as the fallback, enforced per application by policy. High-risk systems get step-up authentication; low-risk ones do not, so the rollout does not stall on user pushback.

Yours To Audit

The identity provider is self-hosted on an open-source core with a complete, exportable event log. When an auditor or an insurer asks who accessed what and when, the record is in a database you control.

How It Works

Five stages, in the order we run them. Applications move behind sign-on one at a time, never in a single weekend.

Inventory

We list the directories, the applications and the people who use them, then mark which applications speak OIDC or SAML 2.0, which only speak LDAP, and which will need a proxy standing in front of them.

Join The Overlay

Sites, servers and endpoints join an encrypted peer-to-peer fabric. Domain controllers stay exactly where they are and stop needing a port forwarded, a concentrator sized, or a tunnel up before a remote worker can log in.

Stand Up The Provider

The identity provider is deployed against your directory as the source of truth. Groups, attributes and organisational units drive policy in place, rather than being copied into somebody else's tenant and reconciled forever after.

Connect Applications

Applications move behind single sign-on in an order you set, starting with the ones that hurt least. Legacy software that cannot speak a modern protocol sits behind the LDAP outpost or a forward-auth proxy instead of staying outside.

Enforce Factors

Passkeys and WebAuthn go first, TOTP covers what cannot take them, and step-up rules apply only to the systems that warrant them. Coverage is reported per application, so it is a fact rather than an assumption.

Against Moving To Azure AD

The usual alternative is lifting identity into a cloud tenant. These are the axes on which the two choices actually diverge.

Where Identity Lives

Moving To Azure AD
A cloud tenant operated by the vendor, kept in step with your directory by a sync agent
Infinite Networks IAM
Your on-premises Active Directory, still authoritative, reached over an encrypted overlay

Commercial Model

Moving To Azure AD
Per user per month, with the controls you need often sitting in a higher tier
Infinite Networks IAM
Self-hosted on an open-source core, quoted as an engagement rather than counted per seat

Reach For Remote Staff

Moving To Azure AD
Endpoints published to the public internet, protected by the vendor's front door
Infinite Networks IAM
A peer-to-peer fabric between known members, with no directory port exposed publicly

Audit Records

Moving To Azure AD
Retained according to the tenant plan and exported through the vendor's interface
Infinite Networks IAM
A complete event log in a database you hold, exportable on your own terms

Legacy Applications

Moving To Azure AD
Older LDAP-only software usually needs a separate bridge or stays outside sign-on
Infinite Networks IAM
LDAP, SAML 2.0 and OIDC are served by one provider, so old and new sit behind one login

Leaving

Moving To Azure AD
Accounts, policy and history live inside the tenant you would be walking away from
Infinite Networks IAM
The directory, the policy set and the log stay on your infrastructure either way

What We Need From You

Identity work is mostly discovery. The more of this you can send at the start, the shorter the discovery is.

A Directory Snapshot

Forest and domain layout, roughly how many accounts are live, and the organisational units and groups that genuinely drive access rather than the ones nobody has cleaned up.

An Application List

Every system people sign into, with the protocol each one supports where you know it. A guess is fine here; confirming it is our job, not yours.

Your Sites

Offices, data centres, home workers and anything else that needs to reach the directory, plus what the links between them look like today.

A Policy Position

Which systems warrant step-up authentication, how long a session should live, and who on your side is allowed to approve an exception to either.

A Pilot Group

A department willing to be first. Identity rollouts stall on user experience far more often than they stall on protocol.

Send what you have and an integration plan comes back, with a rollout order set application by application rather than all at once.

Start An Enquiry

Questions About Identity

The objections we hear in the first conversation about identity.

  • No. This is built around the directory you already run. The domain controllers stay on your premises and stay authoritative, and we carry them between sites while putting a modern identity provider in front of them.

  • Not in the usual sense. There is no concentrator to size and no single tunnel that has to be up before anything works. Members of the overlay establish encrypted peer-to-peer connections directly, so a laptop reaching a domain controller does not have to route through one appliance first.

  • An open-source identity provider at the core. We package it, harden the deployment, integrate it with your directory and support the result. The core staying open is exactly why the event log and the configuration remain yours, and why you are never negotiating with us for access to your own data.

  • Yes. Microsoft 365 speaks SAML 2.0 and OIDC like any other application, so it can sit behind our sign-on. Keeping a Microsoft subscription and keeping your directory on your own premises are two separate decisions.

  • Users on the same local network as a domain controller continue to authenticate against it exactly as they always have. The overlay carries the directory between sites; it does not sit in the path of a login that never leaves the building.

Map Your Identity Estate

Send us the applications and directories in play and we will reply with an integration plan and a rollout order, application by application.

Sales

  • New servers, identity rollouts and workstation pilots
  • Specifications, sizing and monthly pricing
  • Moving an existing estate across to us
Email Sales

sales@infinite-networks.net

Support

  • Anything already running with us
  • Incidents, capacity changes and restores
  • Accounts, access and policy changes
Email Support

support@infinite-networks.net

Office

#002, Ceaser's Castle
Sainikpuri, Defence Colony
Hyderabad 500 094
India