The password was right and the login came from a real browser. It still was not the account’s owner — Akamai Account Protector scores every sign-up, login, password reset and post-login request against that user’s behavioural profile at Akamai’s edge — with all of Bot Manager included.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers Akamai Account Protector — account-lifecycle abuse protection, Bot Manager included. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
Scoring every account action — sign-up, login, reset, session — for whether the real owner is behind it.
What consolidation actually replaces, dimension by dimension.
| Dimension | A password check at the login form | Akamai Account Protector |
|---|---|---|
| What is checked | The password, once, at the login form | Sign-up, login, reset and the session after |
| A human with stolen credentials | Passes, since the password is right | Scored against the owner’s usual device and network |
| Scripted sign-ups | A CAPTCHA every bot farm has solved | Registration requests scored before accounts exist |
| Where the decision runs | In the app, after the origin takes the load | On Akamai’s edge, before traffic reaches you |
| Bot defence | A second product and a second contract | Bot Manager’s capabilities included |
| What it is NOT | — | MFA, identity proofing, or a published price |
The cheapest test is alert-only mode: score real logins and sign-ups for a few weeks, count who would have been blocked, then set policy.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
Requests to sign-up, login, reset and account pages are evaluated on Akamai’s edge before they reach your origin, so a bad attempt can be stopped in transit.
Each request first gets the bot scoring Bot Manager provides, from human to bot, and that result becomes one of the inputs to the account-level risk decision.
Akamai builds a profile of how each user normally arrives — device, network, place and time — and flags requests that do not fit, even from a real human.
User, device, IP, network, bot and reputation indicators combine into a risk score; your policy maps it to block, alert or allow, and accepted traffic updates the profile.
One risk score per request at the edge — bot verdict, device and network signals, and the owner’s own behavioural profile.
Akamai Account Protector asks whether the real owner is behind each account action, from sign-up to the session after login.
Registration requests are scored, so scripted or abusive account opening is caught before the new account can claim offers.
Credential stuffing and logins that do not match the owner’s usual device or network are scored on the login endpoint itself.
Reset flows are a stage of their own, because taking over the reset is a quieter route into an account than guessing the password.
Activity after a successful login is still scored, so a session hijacked after authentication is not trusted for the rest of its life.
Your own rules decide what each risk band triggers, so a bank can block where a retailer would rather alert and watch.
With Bot Manager inside, automation can be throttled or answered silently instead of meeting a refusal it can learn from.
Requests that pass are folded back into the user’s behavioural profile, so the baseline follows real customers as their habits change.
Akamai lists fraud-investigation tools and per-organisation tuning, so analysts can see why an account action was scored as risky.
Risk events can be sent to a SIEM, letting the security team match account abuse against what else it sees across the estate.
BMO’s 2026 digital-banking story, where Akamai lists Account Protector among BMO’s products, and a 2020 primer on credential stuffing.
BMO’s US digital banking story; Akamai’s description names Account Protector, Bot Manager and App & API Protector.
A 2020 primer on the reused-password attack that login-stage scoring is built to catch.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
Most login defences watch one moment, the password form. Account Protector scores four — creation, login, password reset and post-login activity — with one behavioural profile per user across them. A takeover missed at login can still be caught when the session starts changing payout details.
Bot detection answers whether a script sent the request. Account Protector also asks whether this is the account’s real owner, comparing device, IP, network, location and timing against that user’s history. That closes the gap when a person types stolen credentials by hand.
Akamai bundles the whole of Bot Manager into Account Protector, so there is no second bot licence for the same properties. The bot result is one input to the account risk score, and Bot Manager’s slow-down and stealth responses stay available for automation.
No public price, licensing unit, trial or named customer on the product page, no documented Indian location for its risk data, and no analyst report on this product alone. It is not identity verification, not customer IAM and not MFA; it scores requests and leaves step-up to your login stack.
List sign-up, login, reset and high-value account pages on web and mobile, and note which ones Akamai already fronts.
Ask Akamai for both quotes; if bot defence is already planned, the superset may cost little more than the bot licence.
Score real traffic without blocking, then read which customers would have been stopped after app updates or travel.
Move the highest-risk bands to block, keep the middle on alert, and route those events to your SIEM for review.
Agree who tunes thresholds, how support handles a blocked customer, and which losses you will track each quarter.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“Wallet balances were being drained from logins that looked perfect. Post-login scoring flagged the payee changes, not the passwords.”
“Our referral bonus drew thousands of scripted sign-ups a week. Scoring the registration form cut that before any payout went out.”
“We dropped the separate bot licence at renewal because Account Protector already carried it. Procurement noticed first.”
“Password-reset abuse was our blind spot. Treating the reset flow as its own stage closed a route our login rules never saw.”
“Start in alert mode. Our first block policy caught customers who log in from new phones after every festive sale.”
“Detection is strong, but the quote arrived as a bundle with no unit price, and tuning needed weeks of Akamai’s time.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the account-takeover protection market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Quote only; bundles all of Bot Manager.
The grid nobody publishes — how many account stages a product scores vs how many kinds of signal it scores them on.
Four lifecycle stages; six signal families plus per-user profiles.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against Cloudflare Bot Management, HUMAN Account Takeover Defense, Imperva Account Takeover Protection, DataDome Account Protect and Arkose Labs — on stages, signals, responses, price and India.
| Dimension | Akamai Account Protector | Cloudflare Bot Management | HUMAN Account Takeover Defense | Imperva Account Takeover Protection | DataDome Account Protect | Arkose Labs Bot Manager |
|---|---|---|---|---|---|---|
| What it is | Lifecycle defence | Edge bot scoring | Login ATO defence | Login-traffic defence | Login + sign-up module | Bots with challenges |
| Account stages covered | Sign-up to post-login | Login; sign-up preview | Login perimeter | Login flows | Sign-up to checkout | Sign-up, login, more |
| Detection signals | 6 families + profiles | ML, heuristics, JS | 2,500+ per interaction | Login behaviour | App and user data | 225+ signals |
| Leaked-credential checks | Reputation, not a list | On every plan | Dark-web collection | Zero-day leak detection | Not named | $1M warranty instead |
| Response options | Block, alert, allow+ | Rules act on score | Honeypots, misdirection | Block, fewer CAPTCHAs | Reset or MFA trigger | Adaptive challenges |
| Bot defence relationship | Bot Manager included | It is the bot product | One suite, one console | Separate bot product | Own product, own module | Same platform |
| Deployment | On Akamai’s edge | Cloudflare proxy | Edge or app connectors | Imperva cloud WAF | Integrations, auto-pilot | Platform integration |
| Pricing model | Quote, unit unknown | Enterprise add-on | Not published | Not published | Not published | Not published |
| Trial or free entry | No trial listed | Free leaked-cred check | Simulation, demo | Free trial | Demo | Demo |
| Analyst investigation | Fraud tools, SIEM | Bot Analytics | Login + Analyzer views | Login dashboards | Explained decisions | 24/7 SOC + ACTIR |
| Published scale | 40B bots a day | 6.9B logins flagged/day | 20T interactions/week | Thousands of logins | 5T data points/day | Dropbox, 300M users |
| India data location | Not documented | Localisation suite | Not documented | Not documented | Not documented | Not documented |
| Proof published | BMO, by video | 41% leaked logins | FanDuel quote | Award, no case | 75% sign-ups fake | 99% loyalty ATO cut |
| Best fit | Full lifecycle on Akamai | Cloudflare-proxied apps | High-volume logins | Imperva WAF estates | Sign-up-heavy apps | Bot farms, human solvers |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
TechBag has no account protection guide yet, so Akamai Account Protector sits outside the category guides. Browse all products to compare it with the rest of the catalogue. →
Drag the sliders (account-abuse cases a year; analyst-hour cost). Estimates model fraud and support time spent on each takeover, fake sign-up or wrongly locked customer at an assumed 1.5 hours per case, with 70% of it removed by scoring abuse at the edge before it lands. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Not published: Account Protector has no public price, no stated licensing unit and no self-serve trial; Akamai quotes it. Since the whole Bot Manager toolset comes inside it, price it against the bot licence you would otherwise buy. TechBag gets both quotes itemised, then converts to INR with GST.
Best when bots, not accounts, are the problem
Best for a broader rollout
Best when sign-ups, logins and sessions are abused
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Which sign-up, login, reset and post-login pages are in scope, and do the mobile app’s APIs pass through Akamai too?
What is the quote counted on — requests, endpoints, properties or accounts — and what happens when traffic spikes?
If you already hold Bot Manager, will Akamai credit it, given that Account Protector carries the full bot toolset?
Must the protected hostnames run on Akamai delivery, or can Account Protector front a site served elsewhere?
Where are user profiles and risk scores stored and processed, and will Akamai commit to an Indian location in writing?
When a login scores risky, which MFA or verification step will your identity stack apply, and who owns it?
How long will you run alert-only mode, and what support script handles a genuine customer who gets blocked?
Which risk events go to the SIEM, and who in fraud or security reviews them each week? Ask for INR with GST.
Map your sign-up, login and reset endpoints first, or let a TechBag advisor scope an alert-only pilot on live account traffic.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.