JustADC

Authentication

Authentication Offload and Single Sign-On

Zero Trust access – without ripping out what already works.

Users work from anywhere, applications run everywhere, and the perimeter VPN that once connected them has become the weakest link. F5 BIG-IP APM has grown into a Zero Trust access platform: an identity-aware proxy that checks user, device and context on every request, federates with Microsoft Entra ID, Okta and Ping, and still integrates with the Kerberos, RADIUS and legacy applications you cannot replace.

JustADC designs and builds access policies that are secure by default and simple to operate.

Every login page an application exposes is an attack surface and an operational burden. Moving authentication to APM means attackers never reach the application’s login, users sign in once, and the application team stops maintaining authentication code.

How it works

  • APM authenticates the user against Active Directory, LDAP, RADIUS, your identity provider or a certificate, applies MFA and posture checks, and only then forwards the request.
  • Single sign-on to the application uses the method it already supports: Kerberos constrained delegation, NTLM, HTTP header injection, form-based SSO, OAuth bearer tokens or SAML.
  • Session management, timeouts, concurrent-login limits and logout are handled centrally and consistently.

Applications we offload most

  • Exchange Outlook on the web, Exchange Web Services, ActiveSync and Outlook Anywhere.
  • SharePoint, intranet portals and line-of-business web applications.
  • Vendor appliances and applications with weak or unmaintained login pages.
  • APIs that need token validation before requests reach the service.

Paired with Advanced WAF

Offloading authentication removes credential stuffing and brute force from the application; pairing APM with Advanced WAF login-page protection and bot defense removes it from the proxy too.

Learn How to Partner with Us.

Schedule an Expert resource for your requirements on any F5 technology.