How to Integrate Passkeys with On-Premise Infrastructure and Scale Passkey Authentication for Millions of Users?

How to integrate passkeys with on-premise infrastructure Scaleing passkey authentication for millions of users with Secfense

As organizations increasingly adopt passkeys as a passwordless authentication method, many are looking for ways to integrate this modern standard with their existing on-premise infrastructure. For companies that need to manage identity services internally, especially those relying on legacy systems, the challenge is ensuring a seamless migration to passkeys without disrupting the current environment. Furthermore, scaling this solution to accommodate millions of users across global networks adds an extra layer of complexity. This article will address both of these needs and explain how Secfense Identity Provider (IdP) can facilitate the integration of passkeys with on-premise infrastructure and scale passkey authentication for large user bases.

Part 1: Integrating Passkeys with On-Premise Infrastructure

Overview of Secfense IdP and Passkey Enrollment

Secfense IdP serves as a critical intermediary between your on-premise infrastructure and modern authentication protocols, including FIDO2, which supports passkeys. One of its primary functions is to enable passwordless authentication without requiring a complete overhaul of the existing identity management system. By leveraging the SAML (Security Assertion Markup Language) protocol and connecting to existing identity stores, Secfense IdP facilitates seamless migration to passkeys while allowing companies to keep their current IAM (Identity and Access Management) systems intact.

Here’s how to integrate passkeys with your on-premise infrastructure using Secfense IdP:

  1. Initial Integration Setup:
    To set up Secfense IdP with your existing infrastructure, you first need to link it to your on-premise User Access Security Broker. This broker acts as the bridge between the external passkey authentication mechanism and your internal IAM systems, such as Active Directory or other LDAP servers. The role of Secfense IdP is to manage authentication requests and handle SAML responses, but it does not store any user credentials itself, which adds an extra layer of security.
  2. Connecting to Your LDAP System:
    Secfense IdP communicates with your on-premise LDAP system to verify user identities during the enrollment process. For this integration, you will need to configure Secfense IdP to communicate with your Active Directory (or any LDAP-compliant system). This connection ensures that Secfense can validate users and assign appropriate security group permissions.
  3. Passkey Enrollment Process:
    The first time a user logs into a SAML-enabled service after deploying Secfense IdP, they will go through a one-time passkey enrollment process. This involves:
    • The user attempting to log in to the SAML-enabled service.
    • The service redirecting the user to the Secfense IdP for authentication.
    • The user providing their credentials, which are encrypted and validated by the Secfense Broker using the LDAP system.
    • Upon successful validation, the user is authenticated, and Secfense IdP sends a SAML response to complete the login process.
    Once the user is successfully enrolled, they no longer need to enter a password. Future logins will use the passkey stored on the user’s device, and Secfense IdP will communicate with the on-premise infrastructure to confirm the user’s identity and access rights.
  4. Maintaining On-Premise Control:
    One of the key advantages of Secfense IdP is that it allows businesses to retain full control of their on-premise identity systems. The authentication process continues to rely on the existing IAM structure, with the Secfense Broker performing identity verifications through LDAP queries. This ensures that companies can transition to passkey-based authentication without losing the investment made in their legacy infrastructure.
Understand the technical steps for seamless passkey deployment - Book a call with Secfense to get expert insights

Part 2: Scaling Passkey Authentication for Millions of Users

As enterprises grow, the demand to scale identity systems and authentication mechanisms becomes essential. Managing millions of users and ensuring a fast, secure, and reliable authentication process is critical for organizations operating at scale. Scaling passkey authentication requires both a resilient architecture and the right tools to manage large-scale operations.

Challenges of Scaling Passkey Authentication

Scaling passkey authentication for millions of users presents several challenges, including performance, user management, and security. Here’s how Secfense IdP helps to address these challenges:

  1. Performance Optimization:
    The Secfense IdP is designed to handle a high volume of authentication requests with minimal latency. Since the Secfense Broker is deployed on-premise, it can handle user verification locally, which reduces the time it takes for users to authenticate. By leveraging long-polling communication protocols, Secfense IdP minimizes the time between an authentication request and a response, ensuring that millions of users can authenticate simultaneously without significant slowdowns.
  2. Load Balancing and Redundancy:
    For large-scale deployments, implementing load balancing is essential to distribute authentication requests evenly across multiple servers. Secfense IdP can be deployed in a distributed fashion, allowing organizations to add more nodes as the user base grows. This improves reliability and ensures that the system can handle peak authentication loads without downtime or bottlenecks.
  3. Scaling with Identity Federation:
    Secfense IdP supports identity federation standards like SAML, which is widely adopted across enterprises. This allows companies to scale their authentication systems horizontally by federating identities across multiple systems, geographies, and business units. Each instance of Secfense IdP can communicate with both cloud-based and on-premise IAM systems, enabling large organizations to synchronize authentication requests across regions while maintaining a centralized control point.
  4. User Lifecycle Management:
    Scaling passkey authentication requires robust user management, especially when dealing with millions of users. Secfense IdP integrates with your existing LDAP or Microsoft Entra ID, ensuring that user provisioning, de-provisioning, and updates are handled consistently across the entire user base. Whether you need to onboard new users or update access permissions, the integration with your IAM systems ensures that changes are reflected immediately in the Secfense IdP, without disrupting service for the user.
  5. Multi-Tenant Capabilities:
    Organizations that operate in multi-tenant environments, such as managed service providers or enterprises with multiple business units, can benefit from Secfense’s ability to isolate identity management across different tenants. Each tenant can have its own unique set of policies, authentication workflows, and access controls, allowing organizations to scale passkey authentication across different parts of the organization without compromising security.
  6. Security at Scale:
    Security is a paramount concern when scaling authentication systems for millions of users. Secfense IdP ensures that every authentication request follows the FIDO2 passkey protocol, which eliminates the need for passwords and reduces the risk of phishing attacks. Moreover, all communication between the IdP, Secfense Broker, and the IAM systems is encrypted, ensuring that sensitive data is never exposed during the authentication process.
Explore how passkeys improve security and cut costs - Schedule a call with Secfense to learn more

Conclusion

Integrating passkeys with on-premise infrastructure and scaling that solution for millions of users is a complex challenge, but with the right approach and tools, it can be achieved seamlessly. Secfense IdP offers a powerful solution that allows organizations to migrate to passwordless authentication using FIDO2 passkeys without disrupting their existing infrastructure. By leveraging Secfense IdP’s support for LDAP integration, identity federation, and robust scalability features, businesses can ensure that their authentication systems are both future-proof and capable of handling large-scale deployments.

Secfense IdP provides the flexibility and scalability needed to meet the growing demands of modern authentication while maintaining the security and control required by enterprises that manage their infrastructure on-premise. As organizations move toward passwordless authentication, tools like Secfense IdP will be instrumental in making this transition smooth and scalable for millions of users worldwide.

Antoni takes care of all the marketing content that comes from Secfense. Read More

Testimonials

We are faced with new challenges every day. We must always be one step ahead of the attackers and know what they are going to do before they do it. We are convinced that the User Access Security Broker will bring security to a new level, both for those working at the office and from home. For us, working with Secfense is an opportunity to exchange experience with developers who put great value on out-of-the-box thinking.

Krzysztof Słotwiński

Business Continuity and Computer Security Officer

BNP Paribas Bank Poland

As part of the pre-implementation analysis, we verified that users utilize a wide range of client platforms: desktop computers, laptops, tablets, smartphones, and traditional mobile phones. Each of these devices differs in technological advancement, features, and level of security. Because of this, and also due to the recommendation of the Polish Financial Supervision Authority (UKNF), we decided to introduce additional protection in the form of multi-factor authentication mechanisms based on FIDO. As a result, users of our applications can log in safely, avoiding common cyber threats such as phishing, account takeover, and theft of their own and their clients’ data.

Marcin Bobruk

CEO

Sandis

We are excited to partner with Secfense to enhance our user access security for our web apps. By integrating their User Access Security Broker, we ensure seamless and secure protection for our applications and systems, delivering superior security and convenience to our customers.

Charm Abeywardana

IT & Infrastructure

Visium Networks

Before investing in Secfense, we had the opportunity to talk to its existing clients. Their reactions were unanimous: wow, it’s so easy to use. We were particularly impressed by the fact that implementing their solution does not require the involvement of IT developers. It gives Secfense a huge advantage over the competition, and at the same time opens the door to potential customers who so far were afraid of changes related to the implementation of multi-factor authentication solutions.

Mateusz Bodio

Managing Director

RKKVC

Even when the network and infrastructure are secured enough, social engineering and passwords can be used to gain control of the system by attackers. Multifactor authentication is the current trend. Secfense addresses this and allows you to build zero trust security and upgrade your current systems to passwordless applications within minutes, solving this problem right away,” said Eduard Kučera, Partner at Presto Ventures and cybersecurity expert – former Director in hugely successful Czech multinational cyber security firm Avast.

Eduard Kučera

Partner

Presto Ventures

One of the biggest challenges the world is facing today is securing our identity online. That’s why we were so keen to have Secfense in our portfolio. They make it possible to introduce strong authentication in an automated way. Until now, organizations had to selectively protect applications because the deployment of new technology was very hard, or even impossible. With Secfense, the implementation of multi-factor authentication is no longer a problem, and all organizations can use the highest standards of authentication security.

Stanislav Ivanov

Founding Partner

Tera Ventures

Two-factor authentication is known to be one of the best ways to protect against phishing; however, its implementation has always been difficult. Secfense helped us solve that problem. With their security broker, we were able to introduce various 2FA methods on our web applications at once.

Dariusz Pitala

Head of IT

MPEC S.A.