Cloud identity provider · Managed SaaS

One identity layerfor the whole company.

Axeso is a multi-tenant cloud identity provider that unifies how your people sign in — passwords, passwordless passkeys, MFA and hardware-backed device trust — and federates that verified identity to the tools they use every day.

  • Passwordless & MFA
  • Hardware device trust
  • SSO with SAML 2.0
  • AD / LDAP federation
  • Dedicated cloud option
$4.17
per user / month, fully managed
42% lower
than Google Cloud Identity Premium
3 tracks
of device trust: desktop, Android, passkey

The Axeso sign-in chain

  • IdentifyPassword, passkey or Active Directory credentials
  • Second factorTOTP app or FIDO2 hardware security key
  • Trusted deviceNon-exportable key in TPM, Secure Enclave or StrongBox
  • Access rulesWho, from which IP range and within which hours
Then federated to Google Workspace Microsoft 365

The challenge

Identity is now the primary attack surface.

As organisations spread across SaaS applications, devices and remote work, identity fragments — and so does risk. Most breaches start with a stolen credential, not a breached firewall.

Credential risk

Passwords on their own are the leading cause of account compromise in the enterprise.

Tool sprawl

Every new application is another login, another silo, another place where access has to be governed.

Regulatory pressure

Auditors demand provable, immutable control over who accessed what, when and from where.

The platform

Axeso is your organisation's identity authority.

Users authenticate once, through modern layered security, and Axeso passes that verified identity to the services that need it. You keep full control: the platform is multi-tenant, policy-driven and delivered as managed cloud SaaS — on shared or dedicated single-tenant infrastructure, your choice.

01

Authenticate

Password, passkey, MFA and device trust in a single chain.

02

Authorise

Access rules by schedule, IP and policy, in every realm.

03

Federate

SSO with SAML 2.0 to Google Workspace and Microsoft 365.

04

Audit

An immutable, structured record of every action.

Category, plainly statedAxeso sits in the same class as Okta, Auth0, Microsoft Entra ID and Keycloak — a dedicated identity provider — not in the class of Google Workspace or Microsoft 365, where identity ships bundled inside a productivity suite.

The standout differentiator

Access only from the hardware you trust.

A lightweight agent generates a non-exportable key inside the machine's secure hardware. At sign-in the device identifies itself by signing a server challenge — a credential that cannot be copied, phished or moved to another machine.

Windows & macOS

Desktop agent

A lightweight agent stores a key in the device's secure hardware — TPM or Secure Enclave — and signs a challenge at every sign-in.

Android phones

Android app

The native Axeso Device Trust app holds a StrongBox / TEE key and approves sign-ins with biometrics, out of band.

Any mobile / browser

Passkey policy

Require a hardware-backed passkey for every user — the mobile-web equivalent of device trust.

Enrolment & rollout

  • First-login enrolment (TOFU). On Windows and macOS the device enrols itself the first time a user signs in from it. No tokens to hand out, no manual setup — built for fleets with no MDM.
  • Token + QR enrolment. For a second device, kiosks or re-enrolment, an admin issues a token rendered as a scannable QR code.
  • Approval queue. In strict realms new devices wait for admin approval before they are trusted; otherwise they self-approve.

Policy & assurance

  • Device policies. Scope enforcement to specific users or groups, with a maximum number of devices per user and a trust window that renews with use, so active devices never expire.
  • Hardware attestation on Android. The app's key is verified at enrolment to confirm it is genuine, non-exportable hardware — rooted, emulated and spoofed devices are rejected.
  • Works inside restricted browsers. The Android app approves sign-ins out of band, so it works even inside the Google Workspace login screen, which blocks app launches.
Even if an attacker steals a password and the MFA code, they still cannot sign in — because they are not on one of the company's trusted devices. The device key physically cannot leave the machine.

Feature catalogue

Everything the platform actually does.

Grouped along the same four pillars, so you can find what matters to your team.

01 — Authenticate

Sign-in methods

A menu, not an ultimatum. Start with password + MFA and move towards passwordless and device trust as you mature — customers mix methods freely.

  • Password
  • Passkey
  • MFA
  • Device trust
  • AD credentials

Passwordless & passkeys

FIDO2 / WebAuthn — the modern phishing-resistant standard backed by Apple, Google and Microsoft. Works with platform passkeys and hardware security keys, and can be enabled per realm.

  • Face ID
  • Windows Hello
  • YubiKey
  • Titan
  • Synced / device-bound badges

Multi-factor authentication

TOTP with Google Authenticator, Microsoft Authenticator or any RFC-6238 app, plus FIDO2 hardware security keys. Managed per user from the dashboard's Security tab.

  • TOTP
  • FIDO2
  • Per-user management

Password security

Even customers who stay on passwords get a high bar: Argon2id hashing — the algorithm OWASP recommends today — with a server-side pepper kept outside the database, so a full database leak alone cannot be cracked offline.

  • Argon2id
  • Server-side pepper
  • Account lockout
  • Anti-enumeration

Account protection

Automatic lockout after repeated failures, self-releasing or cleared by an admin with a one-click Unblock. Complexity rules and reuse prevention per group. Login response times are levelled so attackers cannot tell which addresses are real accounts.

  • Password history
  • One-click unblock
  • Seamless migration

Hardware device trust

Non-exportable EC P-256 keys sealed inside TPM, Secure Enclave or StrongBox. Three tracks cover desktop, Android and browser — with first-login enrolment for fleets without MDM.

Read the full breakdown →

02 — Authorise

Access rules

Control who may sign in, from where and when. Grant, Deny or Override, by weekday and time window, in the rule's own timezone — for example, contractors sign in Monday to Friday, 08:00 to 18:00 only.

  • Grant / Deny / Override
  • Per-rule timezone

Scope & IP groups

Apply a rule to a single user, a group, an IP range or every user in the realm. Named IPv4 / IPv6 CIDR groups — "office network", "VPN range" — are reusable across rules for tidy network policy.

  • IPv4 / IPv6
  • CIDR
  • Reusable groups

Roles & delegation (RBAC)

Admin users with role-based access control, where roles carry permissions over resource types. A superadmin tier sees every realm; everyone else is scoped to their assigned realms — the same person can be an admin in one realm and read-only in another.

  • Per-realm assignments
  • Superadmin tier

03 — Federate

SAML 2.0 single sign-on

Axeso acts as a SAML 2.0 identity provider, so users authenticate once against Axeso and land signed in to downstream apps. Assertions are cryptographically signed by a dedicated signing service, so the receiving app can trust them.

  • SAML 2.0
  • XML-DSig
  • OIDC on the roadmap

Google Workspace & Microsoft 365

Active SAML federation to both. Your users sign in once, with the full weight of Axeso's security, and reach Google and Microsoft alike — without tying your identity strategy to either one.

  • No ecosystem lock-in
  • Signed assertions

Active Directory & LDAP

A directory connector installed inside your network lets employees sign in with their existing AD credentials — no separate password to manage. The dashboard shows the connector's configuration, push and status.

  • LDAP
  • Local connector
  • Existing credentials

04 — Operate & audit

Immutable audit log

Every configuration change is recorded with its before and after state — and kept even if the admin who made it is later deleted. Auditors love it.

  • Before / after state
  • Tamper-evident

Authentication logs & observability

A filterable, paginated history of end-user sign-in and account events per realm, plus structured logging with Prometheus metrics and Grafana dashboards.

  • Prometheus
  • Grafana
  • Filterable history

Multi-tenant realms

Realms are fully isolated tenants, each with its own users, branding, policies and configuration. One Axeso instance can host many — useful for MSPs, enterprise groups or separating business units.

  • Full isolation
  • Realm switcher
  • MSP-ready

Your brand at every sign-in

Login and password-change pages are fully customisable per realm — logo, colours, copy, background image and card position — with a live preview as you configure. A genuinely branded page, not a generic vendor screen with a logo bolted on.

  • Live preview
  • No code
  • Per realm

Localisation & themes

The dashboard runs in English and Spanish, switchable per user, with light and dark themes.

  • EN / ES
  • Light & dark

On the roadmap

OpenID Connect federation to extend SSO beyond SAML, broader Microsoft 365 federation coverage, and frictionless fleet rollout with silent device-agent installation at scale, without MDM.

  • OIDC
  • Silent rollout

How it is delivered

A clear separation between control and execution.

Axeso runs in the Axeso cloud. Customers manage everything from a browser-based admin dashboard — there is no Axeso server for them to install or maintain.

Control plane

  • DashboardThe browser console where each realm, user and policy is managed.
  • Admin APIA secure REST API that drives the whole configuration.

Running IdP

  • Login serverAuthenticates end users and enforces every policy at sign-in.
  • Signing serviceXML-DSig signatures that make federation trustworthy.

Edge components

  • Device agentsCryptographic proof that a sign-in comes from a trusted machine.
  • Directory connectorThe local bridge to corporate Active Directory.

Managed cloud infrastructure · shared multi-tenant or dedicated single-tenant — your choice

Model 01

Shared multi-tenant

Several customers on shared infrastructure, each one fully isolated in its own realm.

Sell it toMost customers — efficient and quick to roll out.

The only things installed on your sideA small directory connector, if you use Active Directory — and device agents on employee machines, only if you use device trust policies. Nothing else to host, patch or run.

How Axeso compares

Method by method, side by side.

Pick the platform you already run. Each comparison is framed honestly — including where the other side wins.

Google bundles identity inside a productivity suite. Axeso is a purpose-built identity provider delivered as managed cloud. The question is not "which suite", but "who should own your authentication".

Authentication capabilities compared between Axeso and Google Workspace
Capability Axeso Google Workspace
Password with policy and history Argon2id, policy per group Managed policy
MFA with a TOTP authenticator Built in Built in
FIDO2 hardware security keys Yes Yes (Titan / YubiKey)
Passwordless passkeys Yes Yes
Hardware device trust (TPM key as a factor) Cryptographic, key-bound Posture-based, Enterprise tier
Access rules by schedule, day and IP at sign-in Included Context-Aware Access, higher tiers
On-premise Active Directory / LDAP federation Local connector Directory Sync / Secure LDAP
Dedicated single-tenant infrastructure option Shared or dedicated Shared cloud (+ CSE keys)
Fully customisable sign-in experience Per realm Limited branding

Google Workspace capabilities and tiers per public sources, 2026. Details change — verify before contracting.

Axeso — a cryptographic bind

  • A lightweight agent stores a non-exportable key in the device's TPM, and it signs every sign-in challenge.
  • The credential cannot be copied, phished or moved to another machine.
  • Enforced per user or per group; strict realms add an admin approval queue.

Google — posture signals

  • Context-Aware Access evaluates device posture: OS version, screen lock, encryption, IP.
  • Solid Zero Trust signals — but heuristics, not a hardware-bound key.
  • Available on Enterprise / Cloud Identity Premium tiers, and non-trivial to configure.

Pricing

Identity to identity, the gap is real.

The fair comparison is identity against identity — Axeso against the standalone identity products, not against a full productivity suite that also bundles mail, documents and storage.

Google's standalone identity

Cloud Identity Premium

$86.40

per user / year

$7.20 per user / month at list price. A limited free tier covers up to 50 users.

  • Device trust is posture-based, not key-bound
  • No dedicated single-tenant option
  • Limited login-page branding
See the capability table

Microsoft's standalone identity

Entra ID P1

$84

per user / year

$7 per user / month, up from $6 on 1 July 2026. P2 is $120 per user / year.

  • Device trust needs Intune on top: $180/user/year in total
  • No schedule-based access rules at any tier
  • Audit retention capped at 30 days
See the capability table
Your price is locked The rate you sign at holds for the life of your subscription — and existing customers keep the price they came in on.

Cloud Identity Premium list price: $7.20 / user / month per Google, 2026. Axeso list price: $50 / user / year. List prices before negotiated discounts — verify current figures before contracting.

Model your own numbers

1,000
255,000

Compare against

Axeso · $50 / user / year$50,000
Google Cloud Identity Premium · $86.40 per user / year$86,400
Annual saving$36,400

That is a 42% reduction on identity spend at list prices — volume pricing improves it further.

Total cost of ownership

Roughly 42% less per user.

And it still includes hardware device trust, access rules and a dedicated infrastructure option that Cloud Identity either reserves for a higher tier or does not offer at all.

Headcount Axeso Cloud Identity Premium Annual saving
250$12,500$21,600$9,100
1,000$50,000$86,400$36,400
5,000$250,000$432,000$182,000

For context: the Google Workspace ladder

Google's identity is sold per user, bundled with productivity, and the strongest controls sit at the top of the ladder. Prices rose 17–22% in 2025 with the inclusion of Gemini. These figures include the full productivity suite, so they are not a like-for-like identity comparison.

Business Starter

$7

/user/month

Annual. Basic 2SV. No Context-Aware Access.
Business Standard

$14

/user/month

Annual. More storage; security still basic.
Business Plus

$22

/user/month

Annual. Enhanced security; 300-user cap.
Enterprise

Quote

20–40% at scale

Context-Aware Access, DLP, S/MIME, CSE.

Google list prices, annual commitment, 2026. Figures change — verify before contracting.

An honest view

Choose by what you are optimising for.

Credibility matters. Axeso is not the answer for everyone — and when the identity already bundled with your suite is enough, we will say so.

Choose Axeso when…

  • You need dedicated single-tenant isolation or strict data residency
  • You want hardware device trust as an actual factor
  • You federate with Google and Microsoft (and more)
  • You have on-premise Active Directory to integrate
  • You want a dedicated identity authority, not bundled identity
  • You want advanced controls without moving up a tier
  • You must prove to auditors who accessed what, when and from where

Choose Google Workspace when…

  • You are a small, fully cloud-native team — under roughly 50 people, entirely inside Google's apps, with no on-premise or compliance burden
  • You already pay for Workspace and its 2SV and passkeys cover you
  • Every app your users touch is already a Google service
  • Simplicity outweighs dedicated control and isolation

Choose Microsoft 365 when…

  • You already pay for E3, E5 or Business Premium — Entra ID P1 or P2 and Intune are bundled in already
  • You need risk-based adaptive access, scored by machine learning on global telemetry
  • You need privileged identity management: just-in-time elevation and access reviews
  • Your fleet is natively Windows — Entra join and Windows Hello for Business
  • You need a very large SSO catalogue with both SAML and OIDC

FAQ

Questions we get on every call

Do we have to host anything?
No. Axeso is a managed cloud service. The only things on your side are a small directory connector, if you use Active Directory, and device agents, only if you use device trust policies.
Can we keep our data isolated?
Yes. Choose the dedicated single-tenant option and the infrastructure is entirely yours — built for strict privacy or data-residency requirements.
Does it work with our current Microsoft or Google setup?
Yes. Axeso federates to both over SAML 2.0. Users authenticate against Axeso and get single sign-on into those applications.
We already have Google Workspace. Why add Axeso?
For a dedicated identity authority across all of your applications, not just Google's; stronger controls such as hardware-backed device trust included as standard rather than reserved for a higher tier; and a login page that is genuinely yours.
How does device trust work if we have no MDM?
First-login enrolment. On Windows and macOS the device enrols itself the first time the employee signs in from it — no MDM, and no tokens to hand out.
Is it phishing-resistant?
Yes. Passkeys and hardware-backed device trust defeat phishing and stolen-credential attacks, because there is nothing reusable to steal.