Credential risk
Passwords on their own are the leading cause of account compromise in the enterprise.
Cloud identity provider · Managed SaaS
Axeso is a multi-tenant cloud identity provider that unifies how your people sign in — passwords, passwordless passkeys, MFA and hardware-backed device trust — and federates that verified identity to the tools they use every day.
The Axeso sign-in chain
The challenge
As organisations spread across SaaS applications, devices and remote work, identity fragments — and so does risk. Most breaches start with a stolen credential, not a breached firewall.
Passwords on their own are the leading cause of account compromise in the enterprise.
Every new application is another login, another silo, another place where access has to be governed.
Auditors demand provable, immutable control over who accessed what, when and from where.
The platform
Users authenticate once, through modern layered security, and Axeso passes that verified identity to the services that need it. You keep full control: the platform is multi-tenant, policy-driven and delivered as managed cloud SaaS — on shared or dedicated single-tenant infrastructure, your choice.
Password, passkey, MFA and device trust in a single chain.
Access rules by schedule, IP and policy, in every realm.
SSO with SAML 2.0 to Google Workspace and Microsoft 365.
An immutable, structured record of every action.
Category, plainly statedAxeso sits in the same class as Okta, Auth0, Microsoft Entra ID and Keycloak — a dedicated identity provider — not in the class of Google Workspace or Microsoft 365, where identity ships bundled inside a productivity suite.
The standout differentiator
A lightweight agent generates a non-exportable key inside the machine's secure hardware. At sign-in the device identifies itself by signing a server challenge — a credential that cannot be copied, phished or moved to another machine.
A lightweight agent stores a key in the device's secure hardware — TPM or Secure Enclave — and signs a challenge at every sign-in.
The native Axeso Device Trust app holds a StrongBox / TEE key and approves sign-ins with biometrics, out of band.
Require a hardware-backed passkey for every user — the mobile-web equivalent of device trust.
Even if an attacker steals a password and the MFA code, they still cannot sign in — because they are not on one of the company's trusted devices. The device key physically cannot leave the machine.
Feature catalogue
Grouped along the same four pillars, so you can find what matters to your team.
A menu, not an ultimatum. Start with password + MFA and move towards passwordless and device trust as you mature — customers mix methods freely.
FIDO2 / WebAuthn — the modern phishing-resistant standard backed by Apple, Google and Microsoft. Works with platform passkeys and hardware security keys, and can be enabled per realm.
TOTP with Google Authenticator, Microsoft Authenticator or any RFC-6238 app, plus FIDO2 hardware security keys. Managed per user from the dashboard's Security tab.
Even customers who stay on passwords get a high bar: Argon2id hashing — the algorithm OWASP recommends today — with a server-side pepper kept outside the database, so a full database leak alone cannot be cracked offline.
Automatic lockout after repeated failures, self-releasing or cleared by an admin with a one-click Unblock. Complexity rules and reuse prevention per group. Login response times are levelled so attackers cannot tell which addresses are real accounts.
Non-exportable EC P-256 keys sealed inside TPM, Secure Enclave or StrongBox. Three tracks cover desktop, Android and browser — with first-login enrolment for fleets without MDM.
Control who may sign in, from where and when. Grant, Deny or Override, by weekday and time window, in the rule's own timezone — for example, contractors sign in Monday to Friday, 08:00 to 18:00 only.
Apply a rule to a single user, a group, an IP range or every user in the realm. Named IPv4 / IPv6 CIDR groups — "office network", "VPN range" — are reusable across rules for tidy network policy.
Admin users with role-based access control, where roles carry permissions over resource types. A superadmin tier sees every realm; everyone else is scoped to their assigned realms — the same person can be an admin in one realm and read-only in another.
Axeso acts as a SAML 2.0 identity provider, so users authenticate once against Axeso and land signed in to downstream apps. Assertions are cryptographically signed by a dedicated signing service, so the receiving app can trust them.
Active SAML federation to both. Your users sign in once, with the full weight of Axeso's security, and reach Google and Microsoft alike — without tying your identity strategy to either one.
A directory connector installed inside your network lets employees sign in with their existing AD credentials — no separate password to manage. The dashboard shows the connector's configuration, push and status.
Every configuration change is recorded with its before and after state — and kept even if the admin who made it is later deleted. Auditors love it.
A filterable, paginated history of end-user sign-in and account events per realm, plus structured logging with Prometheus metrics and Grafana dashboards.
Realms are fully isolated tenants, each with its own users, branding, policies and configuration. One Axeso instance can host many — useful for MSPs, enterprise groups or separating business units.
Login and password-change pages are fully customisable per realm — logo, colours, copy, background image and card position — with a live preview as you configure. A genuinely branded page, not a generic vendor screen with a logo bolted on.
The dashboard runs in English and Spanish, switchable per user, with light and dark themes.
OpenID Connect federation to extend SSO beyond SAML, broader Microsoft 365 federation coverage, and frictionless fleet rollout with silent device-agent installation at scale, without MDM.
How it is delivered
Axeso runs in the Axeso cloud. Customers manage everything from a browser-based admin dashboard — there is no Axeso server for them to install or maintain.
Managed cloud infrastructure · shared multi-tenant or dedicated single-tenant — your choice
Several customers on shared infrastructure, each one fully isolated in its own realm.
Sell it toMost customers — efficient and quick to roll out.
The customer gets their own isolated infrastructure — a level of isolation productivity suites do not offer to general customers.
Sell it toRegulated sectors, strict privacy or data-residency needs, large enterprises.
The only things installed on your sideA small directory connector, if you use Active Directory — and device agents on employee machines, only if you use device trust policies. Nothing else to host, patch or run.
How Axeso compares
Pick the platform you already run. Each comparison is framed honestly — including where the other side wins.
Google bundles identity inside a productivity suite. Axeso is a purpose-built identity provider delivered as managed cloud. The question is not "which suite", but "who should own your authentication".
| Capability | Axeso | Google Workspace |
|---|---|---|
| Password with policy and history | Argon2id, policy per group | Managed policy |
| MFA with a TOTP authenticator | Built in | Built in |
| FIDO2 hardware security keys | Yes | Yes (Titan / YubiKey) |
| Passwordless passkeys | Yes | Yes |
| Hardware device trust (TPM key as a factor) | Cryptographic, key-bound | Posture-based, Enterprise tier |
| Access rules by schedule, day and IP at sign-in | Included | Context-Aware Access, higher tiers |
| On-premise Active Directory / LDAP federation | Local connector | Directory Sync / Secure LDAP |
| Dedicated single-tenant infrastructure option | Shared or dedicated | Shared cloud (+ CSE keys) |
| Fully customisable sign-in experience | Per realm | Limited branding |
Google Workspace capabilities and tiers per public sources, 2026. Details change — verify before contracting.
Microsoft is a different case, and a harder one. Entra ID is a mature, dedicated identity provider — so this is not an argument about categories. It is about what the controls cost, and what you have to deploy to switch them on.
| Capability | Axeso | Microsoft Entra ID |
|---|---|---|
| MFA with a TOTP authenticator | Included | Included, even on Free |
| FIDO2 keys and passwordless passkeys | Yes | Yes — GA March/April 2026 |
| Hardware device trust | No MDM — first-login enrolment | Requires Intune plus P1 |
| Access rules by schedule and day | Native, timezone per rule | No such Conditional Access condition |
| IP and network restrictions | Named CIDR groups | Named locations (P1+) |
| Risk-based adaptive access (ML) | Not offered | Identity Protection (P2) |
| Privileged identity management | RBAC per realm | Full PIM (P2) |
| SSO application catalogue | SAML 2.0 · OIDC on roadmap | Thousands of apps, SAML + OIDC |
| Audit log retention | Immutable, no cap | 30 days max, on P1 and P2 alike |
| Dedicated single-tenant infrastructure | Standard option | Public multi-tenant cloud |
| Fully customisable sign-in experience | Per realm | Limited; CSS positioning retired July 2026 |
Microsoft Entra and Intune capabilities, tiers and list prices per Microsoft's official documentation, July 2026, after the 1 July price rise. Details change — verify before contracting.
Where Microsoft winsIf you already pay for Microsoft 365 E3, E5 or Business Premium, then Entra ID P1 or P2 and Intune are already included — adding Axeso has to be justified on capability, not on price. Microsoft is also ahead on risk-based adaptive access, privileged identity management, native Windows integration and the sheer size of its SSO catalogue.
Pricing
The fair comparison is identity against identity — Axeso against the standalone identity products, not against a full productivity suite that also bundles mail, documents and storage.
Managed identity SaaS
From$50
per user / year
Just $4.17 per user / month, fully managed — nothing to host or run.
Volume, multi-year and public-sector pricing available. Every deployment is scoped individually — talk to us about your headcount.
Google's standalone identity
$86.40
per user / year
$7.20 per user / month at list price. A limited free tier covers up to 50 users.
Microsoft's standalone identity
$84
per user / year
$7 per user / month, up from $6 on 1 July 2026. P2 is $120 per user / year.
Cloud Identity Premium list price: $7.20 / user / month per Google, 2026. Axeso list price: $50 / user / year. List prices before negotiated discounts — verify current figures before contracting.
Compare against
That is a 42% reduction on identity spend at list prices — volume pricing improves it further.
Total cost of ownership
And it still includes hardware device trust, access rules and a dedicated infrastructure option that Cloud Identity either reserves for a higher tier or does not offer at all.
| Headcount | Axeso | Cloud Identity Premium | Annual saving |
|---|---|---|---|
| 250 | $12,500 | $21,600 | $9,100 |
| 1,000 | $50,000 | $86,400 | $36,400 |
| 5,000 | $250,000 | $432,000 | $182,000 |
Google's identity is sold per user, bundled with productivity, and the strongest controls sit at the top of the ladder. Prices rose 17–22% in 2025 with the inclusion of Gemini. These figures include the full productivity suite, so they are not a like-for-like identity comparison.
$7
/user/month
Annual. Basic 2SV. No Context-Aware Access.$14
/user/month
Annual. More storage; security still basic.$22
/user/month
Annual. Enhanced security; 300-user cap.Quote
20–40% at scale
Context-Aware Access, DLP, S/MIME, CSE.Google list prices, annual commitment, 2026. Figures change — verify before contracting.
An honest view
Credibility matters. Axeso is not the answer for everyone — and when the identity already bundled with your suite is enough, we will say so.
FAQ