The right user, the right resource, the right time.
One identity layer across on-prem, cloud and hybrid — directory sync, SSO, MFA and risk-based decisions from a single control plane.
- 8auth profiles_
- 6MFA methods_
- 7IdP protocols_
- 11report types_
What is IAM?
Identity & Access Management
Who they are, what they may touch.
Identity and Access Management is the discipline of knowing, at all times, three things: who your users are, what each of them is allowed to touch, and whether the person at the keyboard right now is really that user.
- Users live in a directoryNot in a spreadsheet and not in a manager's memory. One record per person, synced from Active Directory, LDAP, Azure AD, Google Workspace or O365 — or held in InstaSafe's own directory if you have none.
- Access is granted to roles, not to peopleGroups and roles carry the entitlements; individuals inherit them. Your AD group structure becomes your access model instead of being re-typed into a second one.
- Authentication is layeredSomething you know, something you have, something you are — password, phone or hardware key, fingerprint or face. Which layers apply is set per group through 8 auth profiles.
- And when someone leaves, one action removes everythingDisable the identity once. Portal, applications, tunnels and OS logins close together, because none of them kept a private copy of the user.
A login page is not access control. What it opens is.
Identity drifts. Quietly, and in every direction.
Two user lists, one truth
The directory says someone left. The VPN, the jump box and three SaaS tenants have not heard. Every extra copy of the user list is a door nobody is watching.
Passwords doing a job they cannot do
A valid credential from a new country on an unmanaged laptop looks exactly like a valid credential. Without device and context in the decision, authentication is a single point of failure.
Access nobody can evidence
The audit does not ask whether you have IAM. It asks who could reach the finance system last March, and what proved it was them. That answer has to exist before it is asked for.
Consume identity. Then issue it.
Sync users and groups from what you already run — three provider types can coexist — or let InstaSafe be the directory. Either way it also acts as an identity provider downstream, which is how one identity reaches equipment a browser-based IdP never will.
One person. Four contexts. Four answers.
Same user, same entitlements, same password. Only the context around the login changes — and the verdict changes with it. That is what risk-based authentication means in practice, and why a credential on its own stops being a key.
Known device, corporate network, business hours. Nothing to challenge — the friction is invisible.
Access approved — no step-up required
08:42:21 arun.k@instasafe.com ALLOW rule: engineering-accessDetailed access rules.
Combine identity, device, location and risk into one precise rule — exactly who gets in, from which device, to which app.
Learn moreEvery login, on the record.
Login activity, authentication summaries and device login reports — 11 report types, exportable, SIEM ready. Inactive users are warned, suspended or removed on schedule, so the gaps a joiner-mover-leaver process leaves open close on their own.
Every login, request and block streams to one live feed — and straight to your SIEM. When a user trips repeated failures, InstaSafe spots the pattern and locks the account before it becomes a breach.
- Live audit of every allow and deny
- Anomaly detection on failed-login bursts
- Device approvals and access requests in one queue
IAM specs, at a glance.
- Directory syncAD, LDAP, Azure AD, Google Workspace, O365, built-in
- Provider types3 concurrent
- IdP protocolsSAML 2.0, RADIUS, OIDC, OAuth, JWT, CAS, TACACS+
- Auth profiles8 profiles · 6 MFA methods
- Risk conditionsIP · geolocation · device · time
- RBACRoles, groups, per-app entitlements
- OS-level authWindows logon, RDP, SSH, VDI
- Self-serviceAD password reset
- 7IdP protocols_
- 3concurrent providers_
- 202event log types_
One record.Every doorit opens.
Sources converge on a single identity, and the estate follows it — including the parts of the estate a browser never touches.
One source of identity truth
Your directory drives everything. There is no second user list left to drift out of date.
Offboarding in one action
Disable the user once — portal, apps, tunnels and OS logins all close together.
Authentication that matches risk
Admins get hard factors, low-risk roles get low friction, and anomalies get challenged automatically.
so which factor does a given person actually get
Six methods, eight profiles. Who decides which?
the auth profile does — per group, not per user↓//Ready when you are//
Ditch the VPN. Keep your apps invisible.
Runs alongside the VPN you have, app by app, until there is nothing left to switch off. Nothing to rack, no network to re-architect.
Regulated, air-gapped, or on-premise? See deployment options