Phishing-resistant MFA · AD · RADIUS · Database

Agentless MFA for Active Directory

Okta and Entra protect your cloud apps. Authnull adds MFA to the things they don't — domain logons, RDP, VPNs, firewalls, and your Windows servers — with identity governance built in.

Get in touch
No AD sync requiredAgentless or agent-basedPhishing-resistant MFA
HOW IT WORKS

Three steps. No rip-and-replace.

Deploy in days, not quarters. Layer security on top of your existing stack — no forklift required.

01
Connect

Drop in an agent or use the agentless protocol bridge. We meet AD, Linux, Windows, Radius, and your databases where they already are.

Active DirectoryLinuxWindowsRadius
02
Discover

Autonomous AI agents map every identity, endpoint, and access path — including the ones nobody documented.

Identity mappingEndpoint discoveryAI-powered
03
Enforce

Apply biometric MFA, least-privilege policy, and time-bound elevation. Audit every session end-to-end.

Biometric MFAZero-trustSession audit
What it covers

MFA across every surface your IdP misses.

Active Directory MFA

Native MFA for on-prem AD — agentless or agent-based. No account syncing, no infrastructure changes. Protect domain logons, domain controllers, and domain-joined machines.

Windows & RDP

MFA on RDP sessions and Windows console logon via a custom logon provider. Block credential-based attacks like Pass-the-Hash and Kerberoasting without replacing your stack.

Identity Governance (IGA)

Access reviews, certification campaigns, and lifecycle management for every identity — human, service account, or AI agent. Prove who has access to what, and why, at audit time.

RADIUS / TACACS+

Add MFA to VPNs, Wi-Fi, and network gear via a lightweight RADIUS bridge. Works with Cisco, Aruba, Juniper, and Fortinet — no rip-and-replace required.

Database Protection

Proxy-based MFA and data masking for MySQL and PostgreSQL. Every connection — human or AI agent — is authenticated, scoped, and logged before a single query runs.

Conditional Access Policies

Define who can access what — by identity, device, time, location, and risk score. Apply least-privilege policies to humans, service accounts, and AI agents from one place.

Every access path

One MFA layer across protocols your IdP skips.

Access pathYour IdPAuthnull
Active Directory logon
Covered
RDP & Windows servers
Covered
VPN & RADIUS
Covered
Firewalls & network gear
Covered
Identity governance (IGA)
Covered
Cloud & SaaS apps
CoveredComing soon
Use cases

Built for the access paths your identity provider cannot reach.

Protect Active Directory logons
Secure VPN and RADIUS access
Add MFA to database connections
Protect Windows and RDP access
Secure Linux and SSH access
Control service-account access
Extend existing IdP coverage to on-premises systems
Security & deployment

How AuthNull deploys — without disrupting what you have.

Agentless where it matters

AD and RADIUS connect through a protocol bridge — no client software on endpoints or devices.

Agents only where you choose

Lightweight agents are available for Linux and Windows when you want session recording or offline coverage — never required.

No changes to Active Directory

AuthNull connects via LDAP and a RADIUS bridge. No schema changes, new OUs, or account sync — AD stays exactly as it is.

Works alongside your IdP

AuthNull sits next to Okta, Entra ID, and any SAML 2.0 / OIDC provider, extending coverage to the on-prem systems they can't reach.

Every session is logged

Access decisions, MFA challenges, and session activity are captured in a searchable audit log for compliance review.

Breakglass, not lockout

If MFA can't be completed, emergency breakglass access keeps your team moving — every event is logged and alerted.

Frequently asked questions

No. AuthNull supports agentless deployment via protocol bridges for AD and RADIUS — no client installs on endpoints or devices. Lightweight agents are available for Linux and Windows where you want session recording or offline coverage.

Close the gap before your next audit.

Stand up MFA and identity governance on AD, RADIUS, and Windows — deployed in days, not months.

Get in touch