An overview of Identity Access

As work moves to the cloud, identity has become both the main line of defense and the main target of attackers.

ManageEngine Identity Access is a cloud-native, directory-agnostic access management platform that secures an organization's most critical resources, including devices, VPN and RADIUS-based endpoints, cloud applications, and Outlook on the web mailboxes. It protects them with phishing-resistant, passwordless authentication, context-aware conditional access, and MFA, and can enroll devices directly even where no directory exists.

The result is centralized, adaptive access control that tightens as risk rises without disrupting everyday sign-ins. This guide covers the platform's features, configuration, and best practices.

Feature overview

Identity Access brings together a broad set of access management and authentication capabilities. Here are its key features:

Conditional access policy: Evaluates each access attempt against conditions such as the IP address, geolocation, business hours, and device operating system, then dynamically governs access to sensitive organizational resources.

Device authentication: Enrolls Windows, macOS, and Linux devices directly into Identity Access, with no separate directory or domain controller, and secures their logins with phishing-resistant, passwordless authentication.

Passwordless authentication: Lets users sign in without a password using secure methods such as FIDO2 passkeys and smart cards, including Personal Identity Verification (PIV) and Common Access Card (CAC) cards , across device, cloud application, VPN, and product logins.

MFA for applications: Applies a chosen combination of MFA factors and conditions to applications enabled for SSO , so the same user can face different requirements for different applications.

MFA for Outlook on the web: Adds an MFA verification step to employees' Outlook on the web mailboxes, protecting the sensitive internal data they hold rather than relying on a password alone.

MFA for CLI: Extends MFA to command-line access, including SSH sessions and privilege elevation with sudo or su.

MFA for sensitive actions: Requires MFA verification before disruptive operations proceed, such as deleting users, groups, or directories, or disenrolling users' enrolled data in bulk.

Offline MFA: Secures devices that have no internet connection through the IDSecurity Agent, and issues single-use emergency access codes as a backup when a user's configured MFA method is unavailable.

MFA frequency: Controls how often users are reprompted for MFA, enabling administrators to balance security against day-to-day convenience.

Active Directory synchronization: Imports users directly from Active Directory and centralizes access management in the Identity Access portal.

Business benefits

Adopting Identity Access delivers benefits that reach across security, operations, and the user experience.

  • Securing air-gapped and offline systems: Offline MFA secures devices in air-gapped or isolated networks through the IDSecurity Agent, verifying users locally with single-use emergency access codes as a fallback.
  • Securing BYOD and unmanaged devices: Device authentication enrolls BYOD, contractor-owned, and other unmanaged endpoints directly, bringing phishing-resistant, passwordless sign-in to Windows, macOS, and Linux without a domain controller or directory.
  • Preventing business email compromise: MFA for Outlook on the web adds a verification step to high-value executive and administrator mailboxes, so a stolen password alone cannot open them.
  • Meeting phishing-resistant MFA requirements: To satisfy NIST and CISA guidance and government smart card mandates, Identity Access provides FIDO2 passkeys and smart cards, including PIV and CAC cards.
  • Securing privileged server and administrative access: MFA for CLI verifies command-line access, while MFA for sensitive actions and step-up authentication add a check before high-impact operations such as deleting users, groups, or directories.