[email protected]

Authentik: Managed Hosting, Installation and Operations

WZ-IT plans, installs and operates Authentik as managed hosting, in your cloud or on premises. Depending on the target design, we also provide migration, secure network and identity integration, monitoring, backups, updates, integrations and further development.

Reviews
At a glance
  • OperationManaged Hosting
  • Monitoring24/7
  • Service Levelselectable as needed
Cloud Wolke HerausforderungServer NachhaltigkeitIT Beratung Service Consulting SoforthilfeTimo Wevelsiep Robin ZinsExperten für Innovation Migration AWSHetzner Hosting zuverlässig

Companies worldwide trust WZ-IT

  • Stadtwerke Brühl
  • DGHO e.V.
  • ABCO Water Systems
  • Golem.de
  • EVADXB
  • nextGYM
  • AInergy
  • ml&s
  • Odiseo Solutions
  • Annota
  • ARGE
  • SweetConnect GmbH
  • Aphy AG
  • CORGOS
  • Rekorder
  • SolidProof
  • Yonju
  • Keymate
  • Paritel
  • Mr. Clipart
  • Millenium
  • Negosh
  • Führerscheinmacher
  • Boese VA
Read client reviews

About the technology

What is Authentik?

Authentik is a self-hostable identity provider for single sign-on and access control. Operating it yourself enables controllable data flows and integration with existing identity sources.

As a Zero Trust Gateway, Authentik implements granular access control based on user identity, device, location, and behavior. The solution supports modern standards like OAuth2, OpenID Connect, SAML2 and provides seamless integration into existing infrastructures.

Authentik Features

  • Self-host Anywhere

    Run Authentik on your Docker or Kubernetes infrastructure with a controllable data location, network access and update process.
  • Single Sign-On (SSO)

    Unified login processes across all applications with support for industry-standard protocols.
  • Multi-factor Authentication

    Comprehensive MFA support with TOTP, WebAuthn/Passkeys in hardware or software for maximum security.
  • Conditional Access Control

    Granular policies based on user attributes, time, location, and more for precise access control.
  • FIDO2 & Passkey Support

    Passwordless authentication using FIDO2 standards for a secure, phishing-resistant login experience.
  • Zero Trust Architecture

    Implementation of Zero Trust principles with fine-grained access controls and continuous verification.
  • GeoIP & Impossible Travel Detection

    Detection of suspicious login attempts based on GeoIP location and travel patterns to prevent unauthorized access.
  • Advanced audit logging with Enterprise

    Field-level audit details require an appropriate Authentik Enterprise licence. Scope, retention and analysis are defined in advance.
  • Comprehensive Protocol Support

    OAuth2/OpenID Connect, SAML2, LDAP, RADIUS, and SCIM for seamless integration into existing systems.

Infrastructure, integration and operations

Authentik as part of your infrastructure

We do more than provide an application. WZ-IT designs the technical architecture, integrates network and identity, operates the agreed scope and develops integrations when the standard product is not enough.

Architecture and migration

Sizing, target environment, data transfer, cutover and recovery are resolved before production operations.

  • On-Premise

    In your data center: Installation on bare-metal, VM or Docker · Integration with existing Active Directory/LDAP

  • Cloud Installation

    AWS, Azure, Hetzner & more: Installation on AWS, Azure, GCP, Hetzner · Terraform/IaC setup (optional) · Kubernetes or Docker Compose · Capacity and scaling design

  • Enterprise Setup

    Advanced architecture after technical and licence assessment: HA and recovery design where supported by the application and edition · Logging according to feature set and edition · Custom security policies

Network and identity

SSO, secure access, internal systems and existing security components are integrated appropriately.

  • VPN Access

    WireGuard, NetBird, Tailscale, Headscale, OpenVPN, Cloudflare Tunnel · Easy client setup for all devices

  • SSO Integration

    Directly or through an upstream identity layer

  • Multi-Factor Auth

    Depends on application, edition and identity provider

  • Firewall & Hardening

    Fail2Ban, Rate Limiting, IP Whitelisting

Monitoring and service level

Updates, backups, technical monitoring and response paths follow a transparent operational scope.

  • 24/7 proactive monitoring

  • Updates and patches

    CVE and security-advisory monitoring for the operating system and managed application, regular updates, and priority deployment of available patches for critical vulnerabilities

  • Daily backup with 7-day retention

  • Personal technical contact

Integration and development

APIs, automation and custom extensions can be delivered beyond basic deployment.

  • Expression Policies (Python)

    Instead of rigid rules, we write Python code for policies. Access only if user is in office (IP range) AND shift plan API reports 'active'? No problem. We integrate external APIs directly into the auth decision.

  • Custom Flow Stages

    When standard stages (MFA, password) aren't enough, we develop custom stages. For example, querying a proprietary hardware token database or legal disclaimer confirmation with versioning.

  • Blueprints & IaC

    We don't configure Authentik manually. We define your complete IAM logic as code (Blueprints). This allows reproducible setups for Dev/Staging/Prod and disaster recovery.

Full-service installation with no hidden costs

What the Authentik setup includes

  • Complete installation & configuration
  • SSL certificate & reverse proxy setup
  • Backup strategy & disaster recovery
  • Performance optimization & tuning
  • Security hardening following OWASP
  • Monitoring & logging setup
  • Documentation & best practices
  • Administrator training (remote)
  • 30 days email support included
  • Dedicated contact person
  • Optional integration: LDAP/AD, SSO, MFA
  • Update strategy & patch management setup

The exact scope depends on the application, edition, infrastructure and criticality. Vendor licences and non-standard components are quoted separately.

Use Cases

Using Authentik in your organisation

  • Enterprise SSO

    Single Sign-On for all your enterprise applications with centralized authentication and authorization
  • Zero Trust Security

    Conditional access and risk-based authentication for modern security architectures
  • Passwordless Authentication

    FIDO2, WebAuthn and Passkey support for secure and user-friendly login without passwords
  • Identity Management

    Centralized user management with LDAP and Directory Sync for seamless integration
  • Multi-Protocol Support

    OAuth2, SAML, LDAP and SCIM in one solution for maximum compatibility
  • Compliance & Audit

    Complete audit logs and compliance reports for regulated industries

Concrete Use Cases

Authentik Development & Integration

Authentik is extremely flexible because every authentication step is a 'stage' in a 'flow'. We use Python to inject logic directly into these flows.

Legacy System Migration

Problem

User passwords are in an old Oracle DB with proprietary hash algorithm. Resetting all passwords is not an option.

Solution

A custom password stage checks login attempts against the old database. Upon success, Authentik transparently migrates the user and re-hashes the password to modern standards.

Dynamic Permissions

Problem

Group membership alone is insufficient. Permissions depend on project status or certifications stored in third-party systems.

Solution

A policy queries your HR API or project software upon login and dynamically injects permissions as claims into the OIDC/SAML token.

Specialized MFA Methods

Problem

TOTP or WebAuthn aren't possible (e.g., in high-security areas without smartphones), smartcards or matrix cards are used instead.

Solution

Implementation of a custom MFA stage mapping the challenge-response logic of your physical tokens.

Managed Hosting & Operations

How much does hosting for Authentik cost?

Compute, applications, storage and response are shown separately. You can see what ongoing operations include and which requirements need a technical assessment.

Starter workload from€129.90/ month · Modular pricing based on your requirements - service level, apps and compute selectable individually.

Authentik hosting in Germany: GDPR-compliant operations

  • One managed standard application included
  • Dedicated compute workload in S, M, L or XL
  • Subdomain on wz-it.cloud included
  • German provider, German data centres, no US clouds
  • ISO 27001-certified and BSI C5-attested data centres
  • 99.9 % standard availability per month
  • CVE and security-advisory monitoring for the operating system and managed application, regular updates, and priority deployment of available patches for critical vulnerabilities
  • Central collection of agreed system and operations logs with immutable retention
  • Daily backup with 7-day retention
  • 5 TB outbound traffic per workload and month
  • 24/7 proactive monitoring
  • Five clearly separated service levels
  • 24/7 P1 response with Production or Critical
  • Personal technical contact

All prices are net and exclude statutory VAT. The offers are addressed to businesses. All on-premises options

Target architecture

Integrate Authentik into your infrastructure with clear controls

Identity platforms sit in the critical access path. Directory, policies, keys, target applications and emergency access must be designed together.

Users, devices and applications

Internal and external identities sign in to connected services through defined flows.

Secure access

TLS, firewall rules, reverse proxies or private network paths are designed around the platform's exposure.

Identity and permissions

Local accounts, SSO, directories, service accounts and emergency access are connected through clear roles.

Authentik platform

Authentication, authorisation, policies, tokens and administrative access are controlled centrally.

Directory and identity data

Local accounts, LDAP/AD, groups, attributes and governed provisioning.

Keys and recovery

Secrets, signing keys, database, backups and documented emergency access.

Connected applications

OIDC, OAuth 2.0, SAML, LDAP or application-specific integrations.

The diagram is a resilient target model. Its implementation depends on edition, data flows, load, availability objectives and existing infrastructure.

Role in the overall system

Related services for Authentik

This page covers installation and the agreed platform operations for Authentik. Custom code, the access layer and special confidentiality requirements remain clearly separated responsibilities that can be added when needed.

Three relevant adjacent paths instead of a long list of further products. All prices are net and exclude statutory VAT. The offers are addressed to businesses.

View the overall system

Reviews & projects

Client feedback and projects worldwide

WZ-IT moved our studio infrastructure from decentralised individual devices to a central platform: every site is securely connected via VPN, new devices are onboarded automatically and an entire site is provisioned from a template, without manual steps on location. What impressed me most is the breadth and depth of their knowledge: Timo and Robin are not a typical IT provider who sets up a server and leaves. The two of them think their way into highly complex infrastructure and software topics, work through every requirement we put in front of them, and build networking, provisioning and operations so that everything fits together in the end. WZ-IT is an excellent partner for complex software, network and architecture projects.
Steve KirchnerManaging Director, nextGYM GmbH
View project

International

Built in Germany's Ruhr Valley. Running worldwide.

WZ-IT designs, develops and operates infrastructure and software for clients in Germany and internationally. We deliver projects remotely and continue supporting them in ongoing operations after go-live.

Selected projects

Read client reviews

  • Secure your Proxmox & backup setup
  • Modernize your infrastructure - sovereign
  • Plan a sovereign open-source stack
  • Integrate a local AI solution
  • Modernize your legacy software
  • Cut cloud cost - up to −81%
  • Build a high-availability Proxmox cluster
  • Virtualize with Managed Proxmox
  • Design an open-source AI architecture
  • Get collaboration fully managed
  • Ship your prototype to production
  • Connect sites and clusters securely

Managed Hosting & Operations

Enquire about hosting and operations for Authentik

Briefly describe the current state and objective for Authentik. We assess infrastructure, integration, and ongoing operations.

  • Straight with Timo and Robin - no sales team, no pitch
  • An honest take, including when we are not the right fit
  • Concrete next steps for infrastructure, software or AI

No risk: worst case, you leave with a clearer understanding of your project than before.

Timo and Robin, founders of WZ-IT

Which Authentik service do you need?

Choose the appropriate starting point or simply describe the situation.

We usually respond within one business day. Please do not submit credentials.

WZ-IT's advice on our Azure migration was technically sound and completely non-binding right from the intro call - we took away a great deal.
Jakob ÖschlbergerInno7 GmbH