Open source identity and access management (IAM) platform — allowing employees to sign on once to access all internal applications. Supports OpenID Connect, SAML 2.0, OAuth 2.0, MFA, Active Directory integration and dozens of international standard protocols — no monthly license fees.
✓ No license / user fees · ✓ Data stored in Vietnam · ✓ 24/7 Vietnamese support
The system is protecting identities at
The entire solution is built entirely on the company's infrastructure (On-premise) and can operate with an independent storage system (Air-gapped). This is the optimal model to ensure data sovereignty, privacy and eliminate dependence on third-party Cloud providers thanks to 100% autonomy from hardware to software.
Each employee has dozens of separate accounts for each application. Every time onboard or offboard takes hours of manual work — and security holes are always lurking.
Each application — ERP, email, HR, project management, cloud — has its own account. Employees reuse weak passwords or write them down. 81% of security incidents stem from exposed or too simple passwords.
The employee quit but the accounts on 10 systems are still active. IT must recall each system one by one — easy to miss. According to IBM, "phantom" access is the leading cause of internal data leaks.
Who logged in at what time? Who accesses which documents? When audited or something goes wrong, there is no centralized log evidence. The SSO system records all authentication events — transparently and with reportable output.
From single sign-on to multi-factor authentication, granular authorization, and Active Directory synchronization — no need to pair multiple products from different vendors.
Sign in once, access all internal applications. Full support for OpenID Connect, OAuth 2.0, SAML 2.0 — compatible with most modern enterprise software.
Built-in multi-factor authentication — protects your account even if your password is compromised. Supports many MFA methods according to the needs of each user group.
Connect and sync users from existing Active Directory or LDAP — employees use Windows accounts to sign in to all applications, no need to create them again.
Decentralize permissions by role, group and user attributes — detailed control of who can do what on each application and each specific resource.
Full web admin interface and user self-service portal — reducing IT load, increasing employee experience.
Logs all authentication events — who logged in at what time, from what IP, how many times it failed. Detect and block attacks automatically.
All the power of an enterprise identity management platform — no add-ons, no separate subscriptions to features.
Same features — cost difference of hundreds of millions each year as the business grows. The data is here for you to judge for yourself.
| Comparison criteria | 🟦 NAD SSO ✦ Our recommendation | Okta | Azure AD / Entra | Auth0 | OneLogin |
|---|---|---|---|---|---|
| 💰 License fee (50 users / month) | 0 ₫ | ~8.750.000 ₫ ~$7/user/month | ~11.250.000 ₫ ~$9/user/month (P2) | ~8.750.000 ₫ ~$7/user/month | ~6.250.000 ₫ ~$5/user/month |
| 💰 Cost / year (50 users) | ~0 ₫ ✦ Free license | ~105 million VND | ~135 million VND | ~105 million VND | ~75 million VND |
| 📍 Self-hosted / On-premise | ✓ Completely self-hosted | ✗ SaaS only | ◐ Hybrid (complex) | ✗ SaaS only | ◐ Hybrid costs |
| 🔒 Identity data stored at the enterprise | ✓ 100% on your server | ✗ Okta Server (USA) | ✗ Datacenter Microsoft | ✗ Server Auth0 (USA) | ✗ Server OneLogin |
| 🔐 OpenID Connect / OAuth 2.0 | ✓ Full | ✓ Full | ✓ Full | ✓ Full | ✓ Full |
| 📋 SAML 2.0 | ✓ Full | ✓ Full | ✓ Full | ✓ Full | ✓ Full |
| 📱 Multi-Factor Authentication | ✓ TOTP, WebAuthn, SMS, Email | ✓ Full | ✓ Full (P1 or higher) | ✓ Full | ✓ Full |
| 🗝️ WebAuthn / Passkeys | ✓ Built-in, free | ✓ Have | ✓ Have | ✓ Have | ◐ Limitations |
| 🏢 LDAP / Active Directory Sync | ✓ Built-in, free | ✓ There is (private agent) | ✓ Built-in | ✓ Have | ✓ Have |
| 🌍 Social Login (Google, GitHub...) | ✓ Free, unlimited | ✓ Yes (additional charge) | ◐ Limitations | ✓ Have | ◐ Limitations |
| 🎯 Fine-grained RBAC / ABAC | ✓ Complete, free | ✓ Full | ◐ Basic | ✓ Full | ◐ Basic |
| 🎨 Custom Login Branding | ✓ Fully customizable | ◐ Limitations | ◐ Limitations | ✓ Have | ◐ Limitations |
| ∞ Unlimited number of users | ✓ Unlimited, free | ✗ Charge per user | ✗ Charge per user | ✗ Charge per user | ✗ Charge per user |
| 🔓 Open source / No vendor lock-in | ✓ Apache 2.0, completely self-hosted | ✗ Proprietary | ✗ Proprietary (Microsoft) | ✗ Proprietary (Okta) | ✗ Proprietary |
| 🏆 Total rating for Vietnamese SME | ★★★★★ Most optimal for SMEs | ★★★☆☆ Powerful but expensive, SaaS only | ★★★☆☆ Good in the Microsoft ecosystem | ★★★☆☆ Good for developers, expensive per user | ★★☆☆☆ Few features, price not cheaper |
Our IAM platform is Apache 2.0 licensed — completely free for commercial use by businesses. You only pay for implementation and support — once.
Open source, Apache license allows businesses to use and customize completely free of charge — unlimited number of users, unlimited number of integrated applications.
There are no monthly SaaS bills per user. When headcount increases from 50 to 500, the license cost remains $0 — just upgrade the hardware if needed.
Names, passwords, and employee information do not leave your server. Do not depend on foreign vendors' uptime - you control 100% of the system.
OIDC/SAML/OAuth standard protocol — application integrated once, compatible forever. NAD implements and supports, but the system is entirely yours.
Compare license costs for 50 employees / year
* Calculated for 50 users, exchange rate ~25,000 VND/USD. One-time implementation costs are calculated separately and are typically paid back in 6–12 months.
"Previously, every time an employee quit, IT had to revoke accounts on more than 12 different systems — which took 2–3 hours and often missed 1–2 systems. After implementing SSO, simply disabling one account cut off all access in 30 seconds."
"We need mandatory MFA for all employees to access the ERP system and file server remotely according to internal audit requirements. NAD deployed SSO with MFA TOTP in 3 days, integrating with existing Active Directory - employees do not need to change passwords, just install an additional authentication app."
"Our startup has 8 internal SaaS applications. Initially we used Okta, but the fee increased too quickly when the team grew large - peak month was up to 15 million for 50 people. Switching to the open source SSO solution deployed by NAD, the cost is about 0 VND/month, the features are enough and much better."
Standardized, transparent process — no disruption to staff work, integrating each application in a controlled manner.
Survey the entire application that needs SSO integration, the existing Active Directory / LDAP system, the number of employees and specific security requirements.
Deploy IAM system, configure realm, connect LDAP/AD, set up password policy, MFA and brute force protection.
Integrate each application (OIDC or SAML) in turn, configure role mapping, test login and authorization for each user group.
Train staff to register for MFA, instruct IT on system administration, set up alerts and hand over full operating documents.
Pay once for deployment & integration services. After that, the entire SSO system is yours — no subscriptions, no monthly licenses.
Suitable for businesses with up to 100 employees, up to 5 integrated applications. Ideal to start your SSO journey.
Complete enterprise IAM features — unlimited users, unlimited application integrations, full MFA and granular permissions.
Multi-region deployment, high availability, complex system integration and long-term managed operations.
✦ Committed to transparency: No hidden license fees. No monthly subscription. No annual renewal. Once deployed, the entire SSO system belongs to you — royalty-free forever.
Get free SSO implementation consultation for your business. We analyze your existing application, recommend an integration roadmap, and provide a detailed quote — completely free, with no obligations.