Skip to main content

Enterprise features

authentik Enterprise adds features for identity provisioning, security, compliance, and device access. These features are included with both Enterprise plans.

Enterprise and Enterprise Plus​

Enterprise includes all the product features on this page and ticket-based support for qualifying subscriptions.

Enterprise Plus includes everything in Enterprise, with additional options for organizations that need a customized agreement:

  • Dedicated support channels (Slack and/or scheduled calls)
  • Assistance with onboarding best practices
  • SLA-backed response times
  • Volume discounts for large teams
  • Auditable FIPS-compliant deployments to meet FedRAMP requirements
  • Billing and purchase via invoice

See the pricing page for current plan details.

Product features​

Identity and provisioning​

Authentication and network access​

  • Privileged access management lets users request access to applications and entitlements, with approval rules and time-limited grants. This feature is in preview.
  • Password history compliance prevents users from reusing previous passwords.
  • Client certificate authentication authenticates or enrolls users with client certificates from devices, smart cards, PIV cards, or hardware tokens.
  • RADIUS EAP-TLS authenticates network clients with EAP-TLS and client certificates.
  • Account Lockdown immediately secures a compromised account by disabling it, revoking its tokens, ending its sessions, and recording the action in the audit log.

Audit and reporting​

  • Enhanced audit logging records detailed object changes and shows before-and-after values for compliance review.
  • Event maps and charts visualize recent events by location, type, and volume.
  • CSV data exports export user and event data for analysis, reporting, or backup.
  • Object Lifecycle Management schedules periodic reviews of applications, groups, and roles, assigns reviewers, and tracks overdue reviews. This feature is in preview.

Device security​

  • The Fleet connector uses device information from Fleet in device-aware access decisions. This feature is in preview.
  • The Google Chrome connector uses Chrome Enterprise Device Trust signals in device-aware access decisions.
  • Local device login enables users to sign in to Windows and Linux devices with authentik credentials. This feature is in preview.
  • Advanced device compliance adds device facts and integrations to device-aware access decisions. This feature is in development; see the Endpoint Devices feature overview.

Feature availability can change as preview features mature. Refer to the linked technical documentation for current platform support and configuration requirements.