Phishing-resistant MFA · AD · RADIUS · Database

Agentless MFA for Active Directory

Okta and Entra protect your cloud apps. Authnull adds MFA to the things they don't — domain logons, RDP, VPNs, firewalls, and your Windows servers — with identity governance built in.

Get in touch
No AD sync requiredAgentless or agent-basedPhishing-resistant MFA
What it covers

MFA for all of your infrastructure.

Active Directory MFA

Native MFA for on-prem AD — agentless or agent-based. No account syncing, no infrastructure changes. Protect domain logons, domain controllers, and domain-joined machines.

Windows & RDP

MFA on RDP sessions and Windows console logon via a custom logon provider. Block credential-based attacks like Pass-the-Hash and Kerberoasting without replacing your stack.

Identity Governance (IGA)

Access reviews, certification campaigns, and lifecycle management for every identity — human, service account, or AI agent. Prove who has access to what, and why, at audit time.

RADIUS / TACACS+

Add MFA to VPNs, Wi-Fi, and network gear via a lightweight RADIUS bridge. Works with Cisco, Aruba, Juniper, and Fortinet — no rip-and-replace required.

Database Protection

Proxy-based MFA and data masking for MySQL and PostgreSQL. Every connection — human or AI agent — is authenticated, scoped, and logged before a single query runs.

Conditional Access Policies

Define who can access what — by identity, device, time, location, and risk score. Apply least-privilege policies to humans, service accounts, and AI agents from one place.

Every access path

One MFA layer across protocols your IdP skips.

Access pathYour IdPAuthnull
Active Directory logon
Covered
RDP & Windows servers
Covered
VPN & RADIUS
Covered
Firewalls & network gear
Covered
Identity governance (IGA)
Covered
Cloud & SaaS apps
CoveredComing soon
Solution approach
Cisco Duo

Duo's Authentication Proxy sits in the middle of LDAP and RADIUS — a man-in-the-middle service you deploy on-prem. Clients authenticate to Duo; Duo binds to Active Directory, then calls Duo's cloud for the second factor.

  • Active Directory sync is required — users must be imported into Duo before MFA can run.
  • Windows Logon agent must be installed on every workstation and server you want to protect (console and RDP).
Better
Authnull

Authnull works with Active Directory itself. Kerberos and NTLM stay native to your domain controllers — no proxy to point clients at, no LDAP bind in the middle, no extra hop between the user and the domain.

  • No AD user sync — identities stay in the directory you already run.
  • No agents on Windows endpoints. MFA is enforced at the domain controller.

Frequently asked questions

No. For Active Directory and RADIUS, AuthNull is agentless — MFA is enforced at the domain controller or via a protocol bridge, with nothing installed on workstations, member servers, or network devices. Lightweight agents are optional for Linux and Windows when you want session recording or offline coverage.

Close the gap before your next audit.

Stand up MFA and identity governance on AD, RADIUS, and Windows — deployed in days, not months.

Get in touch