Directory Access

Adaptive, policy-based access control: enforce the right authentication level for every user, every application, every context

Overview

Adaptive access for Zero-Trust security

Eviden Directory Access is a policy-based access control and authentication platform that delivers risk-based authentication, FIDO support, and fine-grained authorisation for enterprise applications. It evaluates every access request against contextual signals: user identity, device posture, location, time, and behavioural patterns: and dynamically applies the appropriate authentication challenge. Low-risk requests proceed with minimal friction; high-risk requests trigger step-up authentication or are blocked entirely. Eviden Directory Access extends the Eviden Directory foundation with modern adaptive access governance, enabling organisations to move beyond static role-based access control to a continuous, context-aware security model.

Key features

What sets Directory Access apart

pqc risk

Risk-based authentication

Evaluate contextual risk signals at every access request and apply the appropriate authentication challenge dynamically.

IS icon Certified compliance

FIDO support

Standards-based passwordless authentication using FIDO2/WebAuthn: hardware security keys and platform authenticators.

IS icon Largest device integration

Fine-grained authorisation

Policy engine enforces access decisions at the application and resource level: not just at login.

pqc implementation icon

Step-up authentication

Automatically trigger stronger authentication when risk increases: without requiring re-login for low-risk operations.

Centralised policy management

Centralised policy management

Define and manage access policies for all connected applications from a single console.

IS icon Native Interoperability

Integration with Eviden Directory

Built on Eviden Directory as the identity data foundation: policies evaluate against authoritative, real-time identity attributes.

Defense operational readiness icon

Audit and reporting

Full log of every access decision: approved, denied, and step-up triggered: for compliance and investigation.

Benefits

Accelerate your journey towards identity-driven cloud security

R

Reduce friction for low-risk users

Context-aware policies mean trusted users on known devices in expected locations access applications without interruption.

B

Block high-risk access automatically

Unusual access patterns: unknown device, unexpected location, anomalous behaviour: trigger step-up or denial without manual intervention.

M

Move beyond static RBAC

Dynamic, context-aware access decisions adapt to real-world risk: not just role assignments made at provisioning time.

S

Support passwordless authentication

FIDO2 support enables hardware security key and platform authenticator-based login: eliminating passwords for high-security applications.

C

Centralise access policy governance

One policy engine for all applications: consistent enforcement, consistent audit trail, consistent compliance evidence.

Why Eviden

Why choose Directory Access

KuppingerCole recognised

The KuppingerCole Eviden Directory Access Executive View recognises the product's access governance and risk-based authentication capabilities.

 

FIDO2 ready

Full FIDO2/WebAuthn support positions Eviden Directory Access for passwordless enterprise deployments: aligned with the direction of modern authentication standards.

Native Eviden Directory integration

Eviden Directory Access is built on and integrated with Eviden Directory: access policies evaluate against the same authoritative identity data used by all other IAM components.

 

Zero Trust enablement

Risk-based authentication and continuous contextual evaluation are core Zero Trust capabilities: Eviden Directory Access is a key building block in a Zero Trust IAM architecture.

FAQ

Frequently asked questions

Authentication Manager manages MFA devices and policies for Windows workstation login within EAM. Eviden Directory Access provides policy-based, risk-aware access control for applications: with FIDO support and contextual evaluation at the access layer.

Device identity, network location, time of access, user behaviour patterns, and authentication method: configurable per policy.

Yes: FIDO2/WebAuthn support includes hardware security keys (YubiKey and others) as well as platform authenticators (Windows Hello, Touch ID).

Yes: policies are defined at the application level. Each application can have its own risk thresholds, required authentication methods, and step-up triggers.

Eviden Directory Access operates at the directory and application access layer. Contact our team for integration architecture guidance for your specific environment.

Interested in Directory Access

Talk to an expert