Architecture and migration
Sizing, target environment, data transfer, cutover and recovery are resolved before production operations.

WZ-IT plans, installs and operates Authentik as managed hosting, in your cloud or on premises. Depending on the target design, we also provide migration, secure network and identity integration, monitoring, backups, updates, integrations and further development.
Companies worldwide trust WZ-IT
The following are trademarks of their respective owners: authentik (Authentik Security Inc.). WZ-IT is an independent service provider and has no business, partnership, or contractual relationship with these companies. We offer independent migration, installation, hosting, and operations services.

Authentik is a self-hostable identity provider for single sign-on and access control. Operating it yourself enables controllable data flows and integration with existing identity sources.
As a Zero Trust Gateway, Authentik implements granular access control based on user identity, device, location, and behavior. The solution supports modern standards like OAuth2, OpenID Connect, SAML2 and provides seamless integration into existing infrastructures.
We install, host and operate Authentik for your company - either on our secure, privacy-focused infrastructure in Germany or other locations, as well as on-premise in your own environment.
We provide 24/7 monitoring, backups and maintenance for your Authentik instance. Human response times and support coverage follow the selected service level. Note: specific Enterprise connectors (Google Workspace IdP, Microsoft Entra, RADIUS EAP-TLS, mTLS, advanced audit logs) require an Authentik Enterprise license key - we support selection and coordination of the appropriate licence; the licence agreement is concluded with the respective vendor.
Run Authentik on your Docker or Kubernetes infrastructure with a controllable data location, network access and update process.
Unified login processes across all applications with support for industry-standard protocols.
Comprehensive MFA support with TOTP, WebAuthn/Passkeys in hardware or software for maximum security.
Granular policies based on user attributes, time, location, and more for precise access control.
Passwordless authentication using FIDO2 standards for a secure, phishing-resistant login experience.
Implementation of Zero Trust principles with fine-grained access controls and continuous verification.
Detection of suspicious login attempts based on GeoIP location and travel patterns to prevent unauthorized access.
Field-level audit details require an appropriate Authentik Enterprise licence. Scope, retention and analysis are defined in advance.
OAuth2/OpenID Connect, SAML2, LDAP, RADIUS, and SCIM for seamless integration into existing systems.
Professional installation on your infrastructure - on-premise, cloud or hybrid
In your data center
AWS, Azure, Hetzner & more
Advanced architecture after technical and licence assessment
Single Sign-On for all your enterprise applications with centralized authentication and authorization
Conditional access and risk-based authentication for modern security architectures
FIDO2, WebAuthn and Passkey support for secure and user-friendly login without passwords
Centralized user management with LDAP and Directory Sync for seamless integration
OAuth2, SAML, LDAP and SCIM in one solution for maximum compatibility
Complete audit logs and compliance reports for regulated industries
Secure access and access control for your installation
WireGuard, NetBird or Tailscale
Directly or through an upstream identity layer
Depends on application, edition and identity provider
Fail2Ban, Rate Limiting, IP Whitelisting
We set up secure VPN access to your installation - ideal for remote work and external employees.
Full-service installation with no hidden costs
Authentik is extremely flexible because every authentication step is a 'stage' in a 'flow'. We use Python to inject logic directly into these flows.
Instead of rigid rules, we write Python code for policies. Access only if user is in office (IP range) AND shift plan API reports 'active'? No problem. We integrate external APIs directly into the auth decision.
When standard stages (MFA, password) aren't enough, we develop custom stages. For example, querying a proprietary hardware token database or legal disclaimer confirmation with versioning.
We don't configure Authentik manually. We define your complete IAM logic as code (Blueprints). This allows reproducible setups for Dev/Staging/Prod and disaster recovery.
How we implement Authentik development in practice.
User passwords are in an old Oracle DB with proprietary hash algorithm. Resetting all passwords is not an option.
A custom password stage checks login attempts against the old database. Upon success, Authentik transparently migrates the user and re-hashes the password to modern standards.
Group membership alone is insufficient. Permissions depend on project status or certifications stored in third-party systems.
A policy queries your HR API or project software upon login and dynamically injects permissions as claims into the OIDC/SAML token.
TOTP or WebAuthn aren't possible (e.g., in high-security areas without smartphones), smartcards or matrix cards are used instead.
Implementation of a custom MFA stage mapping the challenge-response logic of your physical tokens.
We do more than provide an application. WZ-IT designs the technical architecture, integrates network and identity, operates the agreed scope and develops integrations when the standard product is not enough.
Sizing, target environment, data transfer, cutover and recovery are resolved before production operations.
SSO, secure access, internal systems and existing security components are integrated appropriately.
Updates, backups, technical monitoring and response paths follow a transparent operational scope.
APIs, automation and custom extensions can be delivered beyond basic deployment.
The exact scope depends on the application, edition, infrastructure and criticality. Vendor licences and non-standard components are quoted separately.
Identity platforms sit in the critical access path. Directory, policies, keys, target applications and emergency access must be designed together.
Internal and external identities sign in to connected services through defined flows.
TLS, firewall rules, reverse proxies or private network paths are designed around the platform's exposure.
Local accounts, SSO, directories, service accounts and emergency access are connected through clear roles.
Authentication, authorisation, policies, tokens and administrative access are controlled centrally.
Local accounts, LDAP/AD, groups, attributes and governed provisioning.
Secrets, signing keys, database, backups and documented emergency access.
OIDC, OAuth 2.0, SAML, LDAP or application-specific integrations.
The diagram is a resilient target model. Its implementation depends on edition, data flows, load, availability objectives and existing infrastructure.
A clearly defined operating scope instead of an opaque hosting flat fee.
We set up a test instance for you, usually on the next business day. No payment details required. After seven days it is deleted unless you continue.
Compute, applications, storage and response are shown separately. You can see what ongoing operations include and which requirements need a technical assessment.
We also design custom Authentik architectures, integrations and migrations. Contact us for a technical assessment.
One managed standard Authentik application is included in the Starter workload. Business and higher levels add a flexible operations allowance for planned work during regular service hours. Select compute, additional applications, storage and the appropriate service level.
A workload is one compute instance with the applications agreed for it.
One standard app per workload is already included. Additional dedicated servers count as separate workloads.
€79.90 per started TB and month, including daily encrypted offsite backup with 7-day retention.
Enquiry
Briefly describe the current state and objective for Authentik. We assess infrastructure, integration, and ongoing operations.
As an alternative to managed hosting in the data centre, WZ-IT provides the hardware, configures Authentik, and handles hardening, monitoring, updates, backup and technical support. Access can be limited to the internal network or enabled through VPN and existing identities.
from EUR 349 excl. VAT / month · plus one-time provisioning and initial setup

11.05.2026
On 3 May 2026 the Vaultwarden maintainer team released version 1.36.0 — closing six security advisories, one of which is a server-side request forgery that...
01.04.2026
If you're looking for an Okta or Auth0 alternative, two open-source projects quickly rise to the top: Authentik and Zitadel. Both solve the same problem...
These solutions are often used together with Authentik
These solutions offer similar functionalities and can be evaluated together
These solutions are direct alternatives with similar use cases
No risk: worst case, you leave with a clearer understanding of your project than before.


“WZ-IT's advice on our Azure migration was technically sound and completely non-binding right from the intro call - we took away a great deal.”
Whether a specific IT challenge or just an idea - we look forward to the exchange. In a brief conversation, we'll evaluate together if and how your project fits with WZ-IT.