100% Open Source · Centralized Identity Management

Single sign-on (SSO) — Centralized security,
The cost is 0

Open source identity and access management (IAM) platform — allowing employees to sign on once to access all internal applications. Supports OpenID Connect, SAML 2.0, OAuth 2.0, MFA, Active Directory integration and dozens of international standard protocols — no monthly license fees.

✓ No license / user fees ·  ✓ Data stored in Vietnam ·  ✓ 24/7 Vietnamese support

0 ₫
License fee / user / month
Unlimited users
OIDC/SAML
International standard protocol
MFA
Integrated multi-factor authentication

The system is protecting identities at

Data Sovereignty

On-premise & Air-gapped — data is in the hands of the business

The entire solution is built entirely on the company's infrastructure (On-premise) and can operate with an independent storage system (Air-gapped). This is the optimal model to ensure data sovereignty, privacy and eliminate dependence on third-party Cloud providers thanks to 100% autonomy from hardware to software.

The real problem

Manual account management — hidden security risks in your business

Each employee has dozens of separate accounts for each application. Every time onboard or offboard takes hours of manual work — and security holes are always lurking.

🔑

Employees manage 10+ different passwords

Each application — ERP, email, HR, project management, cloud — has its own account. Employees reuse weak passwords or write them down. 81% of security incidents stem from exposed or too simple passwords.

⚠️

Offboard employee — forgot to revoke access

The employee quit but the accounts on 10 systems are still active. IT must recall each system one by one — easy to miss. According to IBM, "phantom" access is the leading cause of internal data leaks.

📋

No audit logs — cannot demonstrate compliance

Who logged in at what time? Who accesses which documents? When audited or something goes wrong, there is no centralized log evidence. The SSO system records all authentication events — transparently and with reportable output.

Core Features

Complete identity management system in one platform

From single sign-on to multi-factor authentication, granular authorization, and Active Directory synchronization — no need to pair multiple products from different vendors.

🔐

Single Sign-On (SSO)

Free

Sign in once, access all internal applications. Full support for OpenID Connect, OAuth 2.0, SAML 2.0 — compatible with most modern enterprise software.

  • OpenID Connect (OIDC) — modern standard for web/mobile apps
  • SAML 2.0 — enterprise legacy application integration
  • OAuth 2.0 — secure API authorization
  • Social login: Google, Microsoft, GitHub, Facebook
  • Centralized session management — log out all at once
📱

Multi-Factor Authentication (MFA)

Free

Built-in multi-factor authentication — protects your account even if your password is compromised. Supports many MFA methods according to the needs of each user group.

  • TOTP — Google Authenticator, Authy, Microsoft Authenticator
  • WebAuthn / FIDO2 — passkey, hardware key (YubiKey)
  • Email OTP and SMS OTP
  • Emergency backup codes
  • MFA policy by role — required for admins, optional for users
🏢

User Federation & Active Directory

Free

Connect and sync users from existing Active Directory or LDAP — employees use Windows accounts to sign in to all applications, no need to create them again.

  • LDAP / Active Directory sync real-time
  • Just-In-Time provisioning upon first login
  • Synchronize groups and attributes
  • Connect multiple identity sources at the same time
  • Identity brokering — federate with external IdP (Google Workspace, Azure AD)
🎯

Detailed authorization (RBAC / ABAC)

Free

Decentralize permissions by role, group and user attributes — detailed control of who can do what on each application and each specific resource.

  • Role-Based Access Control (RBAC) by role
  • Flexible Attribute-Based Access Control (ABAC).
  • Policy engine — complex conditions (time, IP, device)
  • Resource Server with OAuth 2.0 UMA 2.0
  • Custom claims and scope in the JWT token
🖥️

Admin Console & Self-Service Portal

Free

Full web admin interface and user self-service portal — reducing IT load, increasing employee experience.

  • Web admin console manages users, groups, roles, clients
  • Full REST API — DevOps/CI-CD pipeline integration
  • Self-service portal: change password, MFA settings
  • Import/export users in bulk (bulk CSV)
  • Custom theme — logo, colors, login page according to business brand
📋

Audit Log & Advanced Security

Free

Logs all authentication events — who logged in at what time, from what IP, how many times it failed. Detect and block attacks automatically.

  • Full event log: login, logout, failure, permission change
  • Brute force protection — automatically locks account after N wrong times
  • Detect unusual login (strange IP, different time zone)
  • Export logs to SIEM system (Elasticsearch, Splunk)
  • Real-time warnings when detecting security incidents
Feature ecosystem

35+ IAM features completely free

All the power of an enterprise identity management platform — no add-ons, no separate subscriptions to features.

AllAuthenticationMFAIntegrationDecentralizationAdministrationSecurity
🔐
OpenID Connect
Authentication
🔑
OAuth 2.0
Authentication
📋
SAML 2.0
Authentication
🎫
JWT Tokens
Authentication
🔄
Session Manager
Authentication
🛡️
Password Policy
Authentication
🔁
Token Refresh
Authentication
🌐
Login Flow Builder
Authentication
📱
TOTP Authenticator
MFA
📧
Email OTP
MFA
💬
SMS OTP
MFA
🗝️
WebAuthn / FIDO2
MFA
🔖
Backup Codes
MFA
📊
MFA Policy Engine
MFA
🏢
LDAP Sync
Integration
🪟
Active Directory
Integration
🌍
Social Login
Integration
🔗
External IdP Bridge
Integration
📡
SCIM Provisioning
Integration
🔌
REST Admin API
Integration
📦
Client Libraries
Integration
👥
RBAC
Decentralization
🎯
ABAC Policy
Decentralization
🏷️
Group Manager
Decentralization
🗺️
Role Mapping
Decentralization
📏
Resource Auth (UMA)
Decentralization
🔍
Scope Manager
Decentralization
🖥️
Admin Console
Administration
👤
User Self-Service
Administration
🏛️
Realm Manager
Administration
🎨
Login Theme Builder
Administration
📈
Analytics Dashboard
Administration
🚫
Brute Force Guard
Security
📝
Audit Event Log
Security
🔔
Security Alerts
Security
Compare solutions

NAD SSO vs Paid SSO Solutions

Same features — cost difference of hundreds of millions each year as the business grows. The data is here for you to judge for yourself.

Comparison criteria 🟦 NAD SSO
✦ Our recommendation
OktaAzure AD / EntraAuth0OneLogin
💰 License fee (50 users / month)0 ₫~8.750.000 ₫
~$7/user/month
~11.250.000 ₫
~$9/user/month (P2)
~8.750.000 ₫
~$7/user/month
~6.250.000 ₫
~$5/user/month
💰 Cost / year (50 users)~0 ₫
✦ Free license
~105 million VND~135 million VND~105 million VND~75 million VND
📍 Self-hosted / On-premise Completely self-hosted SaaS only◐ Hybrid (complex) SaaS only◐ Hybrid costs
🔒 Identity data stored at the enterprise 100% on your server Okta Server (USA) Datacenter Microsoft Server Auth0 (USA) Server OneLogin
🔐 OpenID Connect / OAuth 2.0 Full Full Full Full Full
📋 SAML 2.0 Full Full Full Full Full
📱 Multi-Factor Authentication TOTP, WebAuthn, SMS, Email Full Full (P1 or higher) Full Full
🗝️ WebAuthn / Passkeys Built-in, free Have Have Have◐ Limitations
🏢 LDAP / Active Directory Sync Built-in, free There is (private agent) Built-in Have Have
🌍 Social Login (Google, GitHub...) Free, unlimited Yes (additional charge)◐ Limitations Have◐ Limitations
🎯 Fine-grained RBAC / ABAC Complete, free Full◐ Basic Full◐ Basic
🎨 Custom Login Branding Fully customizable◐ Limitations◐ Limitations Have◐ Limitations
∞ Unlimited number of users Unlimited, free Charge per user Charge per user Charge per user Charge per user
🔓 Open source / No vendor lock-in Apache 2.0, completely self-hosted Proprietary Proprietary (Microsoft) Proprietary (Okta) Proprietary
🏆 Total rating for Vietnamese SME
★★★★★
Most optimal for SMEs
★★★☆☆
Powerful but expensive, SaaS only
★★★☆☆
Good in the Microsoft ecosystem
★★★☆☆
Good for developers, expensive per user
★★☆☆☆
Few features, price not cheaper
Why save more?

Cost model
completely different

Our IAM platform is Apache 2.0 licensed — completely free for commercial use by businesses. You only pay for implementation and support — once.

1

Apache 2.0 license — free for commercial use

Open source, Apache license allows businesses to use and customize completely free of charge — unlimited number of users, unlimited number of integrated applications.

2

Runs on your server — pay once, use forever

There are no monthly SaaS bills per user. When headcount increases from 50 to 500, the license cost remains $0 — just upgrade the hardware if needed.

3

Identity data stays within the enterprise

Names, passwords, and employee information do not leave your server. Do not depend on foreign vendors' uptime - you control 100% of the system.

4

Not locked to one vendor

OIDC/SAML/OAuth standard protocol — application integrated once, compatible forever. NAD implements and supports, but the system is entirely yours.

How much do you save compared to paid SSO?

Compare license costs for 50 employees / year

Azure AD Premium P2 (~$9/user/month)~135.000.000 ₫
Okta Workforce Identity (~$7/user/month)~105.000.000 ₫
Auth0 Business (~$7/user/month)~105.000.000 ₫
OneLogin Professional (~$5/user/month)~75.000.000 ₫
Average of paid solutions~75–135 million VND/year
NAD SSO — License fee0 ₫
🎉 Save on licenses every year75–135 million VND

* Calculated for 50 users, exchange rate ~25,000 VND/USD. One-time implementation costs are calculated separately and are typically paid back in 6–12 months.

What customers say

The business has successfully centralized its identity

"Previously, every time an employee quit, IT had to revoke accounts on more than 12 different systems — which took 2–3 hours and often missed 1–2 systems. After implementing SSO, simply disabling one account cut off all access in 30 seconds."

H
Tran Minh Hung
IT Manager — Financial company · 120 employees

"We need mandatory MFA for all employees to access the ERP system and file server remotely according to internal audit requirements. NAD deployed SSO with MFA TOTP in 3 days, integrating with existing Active Directory - employees do not need to change passwords, just install an additional authentication app."

L
Nguyen Thu Linh
CISO — Manufacturing Group · 300 employees

"Our startup has 8 internal SaaS applications. Initially we used Okta, but the fee increased too quickly when the team grew large - peak month was up to 15 million for 50 people. Switching to the open source SSO solution deployed by NAD, the cost is about 0 VND/month, the features are enough and much better."

T
Pham Van Thanh
CTO — SaaS Startup · 55 employees
Deployment process

From 0 to complete SSO in 4 steps

Standardized, transparent process — no disruption to staff work, integrating each application in a controlled manner.

1

System analysis & application listing

Survey the entire application that needs SSO integration, the existing Active Directory / LDAP system, the number of employees and specific security requirements.

2

Install & configure Identity Provider

Deploy IAM system, configure realm, connect LDAP/AD, set up password policy, MFA and brute force protection.

3

Integrate SSO for each application

Integrate each application (OIDC or SAML) in turn, configure role mapping, test login and authorization for each user group.

4

Employee training & Go-live

Train staff to register for MFA, instruct IT on system administration, set up alerts and hand over full operating documents.

Service package

Clear implementation costs, no hidden fees

Pay once for deployment & integration services. After that, the entire SSO system is yours — no subscriptions, no monthly licenses.

Starter
SSO Starter
8M
one-time deployment · all included

Suitable for businesses with up to 100 employees, up to 5 integrated applications. Ideal to start your SSO journey.

  • Install & configure Identity Provider
  • SSO for up to 5 applications (OIDC/SAML)
  • MFA (TOTP + Email OTP)
  • Connect 1 LDAP/AD source
  • Admin console & user self-service
  • IT admin training 4 hours
  • 3 months support
  • WebAuthn / Passkeys
  • Fine-grained ABAC policy
Consult this package
Enterprise
SSO Enterprise
Contact
Quote according to specific requirements

Multi-region deployment, high availability, complex system integration and long-term managed operations.

  • All features Business
  • High Availability cluster
  • Multi-realm — partitioning by department
  • SIEM / Splunk / Elasticsearch integration
  • SCIM automatic provisioning
  • Custom authentication flow
  • Unlimited training
  • 12 month SLA managed
  • On-call support 24/7
Contact for consultation

✦ Committed to transparency: No hidden license fees. No monthly subscription. No annual renewal. Once deployed, the entire SSO system belongs to you — royalty-free forever.

Free consultation — No obligations

Security Ready
corporate identity?

Get free SSO implementation consultation for your business. We analyze your existing application, recommend an integration roadmap, and provide a detailed quote — completely free, with no obligations.

✓ Response within 2 working hours  ·  ✓ Actual system demo  ·  ✓ No immediate commitment