Passwords and SMS codes can be captured at a fake login page. A sign-in should need the device in the employee’s hand — Akamai MFA turns the phone each employee already carries into a FIDO2 security key, and adds it behind Okta, Entra ID, Ping or ADFS — plus your VPN and Windows logons.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers Akamai MFA — workforce multi-factor authentication, sold as its own product. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
A second factor on every employee sign-in, so a stolen password alone opens nothing.
What consolidation actually replaces, dimension by dimension.
| Dimension | SMS codes and a cupboard of tokens | Akamai MFA |
|---|---|---|
| Phishing-resistant factor | Hardware keys bought, posted and replaced | The employee’s own phone acts as a FIDO2 key |
| Where MFA applies | Each app or VPN with its own token vendor | One factor set behind your IdP, VPN and logons |
| VPN sign-in | Password only, or a separate OTP server | RADIUS through the PacketFence Gateway |
| Enrolment | A helpdesk ticket for every token issued | Users self-enrol a phone, passkey or key |
| Lost device | A replacement token couriered out | A bypass code, then a fresh enrolment |
| What it is NOT | — | A directory, a CIAM service or a published price |
The cheapest test is the free trial: connect one identity provider, enrol twenty users on the phone key, and count the helpdesk calls.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
The app receives push requests and acts as a FIDO2 security key unlocked by biometrics; Akamai says the keys stay on the device in isolated security hardware built to resist exploits.
Akamai’s docs describe a workforce MFA service that adds a second check on top of existing identity validation, for cloud, on-premises, web, SaaS and IaaS applications.
Documented connectors cover Okta, Microsoft Entra ID (SCIM and External Authentication Methods), PingFederate, ADFS, Shibboleth, Keycloak, SAML apps and Akamai’s own EAA.
VPNs reach Akamai MFA over RADIUS through the PacketFence Gateway, backed by LDAP or Active Directory; a Windows Logon plugin and Unix PAM cover desktops and servers.
A phone app that acts as a FIDO2 key — called by your IdP, your VPN gateway and your Windows and Unix logons.
Akamai MFA makes the employee’s phone a FIDO2 key, behind the identity provider you already run.
The Akamai MFA app turns a smartphone into a FIDO2 key with biometrics, so phishing-resistant login needs no token handed out.
Passkeys with biometrics, platform authenticators and separate FIDO2 security keys can be enrolled beside the phone key.
Standard push, TOTP, one-time passwords, SMS and bypass codes cover users who cannot yet sign in with a FIDO2 factor.
Okta, PingFederate, PingOne DaVinci, ADFS, Shibboleth and Keycloak can call Akamai MFA as the second factor at sign-in.
Akamai documents an Entra ID integration through SCIM and External Authentication Methods, with Entra kept as the identity source.
The PacketFence Gateway brings Akamai MFA to VPNs over RADIUS, checking users against LDAP or Microsoft Active Directory.
A Windows Logon plugin and a Unix PAM module put the same factors in front of desktop, server and SSH sign-ins.
Policies cover device posture, lockouts, offline authentication and remembered devices, with custom rules by user status.
Self-enrolment lets each employee register a phone, passkey, security key or number, and the app can carry your branding.
Two short Akamai explainers on account security and how a credential-theft attack unfolds. Akamai’s channel has no Akamai MFA product demo; both are topical, from 2022 and 2024.
A topical Akamai explainer on account protection and enrolling a second factor; Akamai’s channel has no Akamai MFA product demo.
How a credential-theft attack unfolds step by step — the threat a phone-based FIDO2 key is meant to stop. A 2022 video.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
Phishing-resistant MFA usually means buying, posting and replacing hardware keys. Akamai MFA turns the phone staff already carry into a FIDO2 key unlocked by biometrics, held in the device’s isolated security hardware. FIDO2 ties each sign-in to the genuine site, so a fake page gets nothing to replay.
Akamai MFA does not ask you to move directories. It plugs into Okta, Ping, Microsoft Entra ID, ADFS, Shibboleth or Keycloak as the second factor, and into Akamai’s Enterprise Application Access for private apps, so one set of factors can follow users from SaaS to internal applications.
A strong factor on SaaS alone leaves the VPN and the server console on passwords. Akamai documents a RADIUS route for VPNs through the PacketFence Gateway, against LDAP or Active Directory, plus a Windows Logon plugin and Unix PAM, so the phone key and push reach beyond the browser.
There is no public price, only a 30-day trial and a quote. It is a second factor, not a directory or a customer-identity product, and Akamai names no customer for it. No Indian data region is documented, no analyst ranking covers it, and Akamai’s channel carries no product demo of it.
List the IdP, VPN, Windows, server and SSH logins in use, and who signs in where, before setting any factor policy.
Connect Akamai MFA to your IdP in a test setup and enrol a pilot group on the phone key, push and one fallback.
Stand up the PacketFence Gateway for RADIUS and try the Windows Logon plugin on a few machines before going wide.
Decide who must use FIDO2, where push or TOTP is allowed, and set lockout, offline and remembered-device rules.
Open self-enrolment to all staff, issue bypass codes for recovery, and move SMS users onto the phone key in waves.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“We shelved the plan to courier hardware keys to field staff. The phone key gave us FIDO2 sign-in within the same quarter.”
“It sat behind Okta with no directory move. One policy change, and the biometric prompt appeared at the next login.”
“Wiring the PacketFence Gateway to our VPN took a day; test the Active Directory lookups before you switch it on.”
“Most staff self-enrolled without help. We kept SMS for contractors on shared phones and plan to retire it next year.”
“Entra stayed our identity source and Akamai MFA ran as an external method; the pilot group barely noticed the change.”
“No price list meant a long budgeting cycle, and we had to ask in writing where the authentication data is held.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the workforce MFA market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Quote only after a 30-day trial; sold as its own product.
The grid nobody publishes — how many sign-in paths a product reaches vs how strong its documented factors are.
Phone as FIDO2 key; IdPs, RADIUS gateway, Windows and PAM.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against Cisco Duo, Okta Adaptive MFA, miniOrange MFA, InstaSafe MFA and Fortinet FortiAuthenticator — on factors, FIDO2, price, identity providers, VPN and logon reach, lock-in and India.
| Dimension | Akamai MFA | Cisco Duo | Okta Adaptive MFA | miniOrange MFA | InstaSafe MFA | Fortinet FortiAuthenticator |
|---|---|---|---|---|---|---|
| What it is | Workforce MFA service | MFA plus device trust | Risk-based MFA | India-built MFA suite | MFA for zero trust | Auth server appliance |
| Deployment | Akamai-run service | Cloud service | SaaS only | Cloud or on-premises | India-hosted SaaS | Hardware or VM |
| Factor range | FIDO2, push, TOTP, SMS | Push, passwordless | Okta Verify, WebAuthn | 15+ methods | Email, SMS, TOTP | FortiToken plus FIDO2 |
| Phishing-resistant factor | Phone as FIDO2 key | FIDO2 documented | FIDO2 and passkeys | Passkeys, FIDO2 keys | FIDO2 unconfirmed | FIDO2 and certificates |
| Pricing model | Quote, own product | Per user, four tiers | Inside suite tiers | Per user, INR tiers | Per user, INR quote | By user capacity |
| Published entry price | Not published | Free to 10, then $3 | $14 suite or $6 add-on | ₹180 per user/month | Quote only | Channel quote |
| Included vs add-on | Standalone; EAA apart | Device trust by tier | Depth follows the tier | Methods by tier | Pairs with ZTNA | Tokens priced apart |
| Policy and risk | Posture, lockout rules | Device health checks | Adaptive step-up | Adaptive, lighter | Conditional access | Basic conditions |
| Identity providers | Okta, Entra, Ping, ADFS | IdP-agnostic | Okta-centred | SSO, ADFS, cloud apps | SSO and SAML | RADIUS, LDAP, SAML |
| VPN and RADIUS | PacketFence Gateway | VPN a core strength | RADIUS supported | VPN and RDP | RADIUS listed | Native RADIUS server |
| Logon beyond the web | Windows plugin, PAM | RDP and custom apps | Windows, RDP, SSH | Windows and Mac logon | Not documented | Network-first |
| India data residency | Not documented | No India region listed | India tenants (2026) | India-built, on-prem | India-hosted | Your appliance |
| Lock-in and exit | Factor layer only | IdP stays yours | Tied to the Okta suite | Re-enrol on exit | Bundle gravity | Fabric-bound |
| Best fit | Phone-key FIDO2 rollout | MFA in front of all | Okta estates | Budget-led, on-prem | MFA with ZTNA, in INR | Fortinet networks |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
Akamai MFA is one of 26 IAM, SSO & MFA products TechBag carries. The IAM, SSO & MFA guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (employees enrolled; IT-hour cost). Estimates model helpdesk and security time spent on password resets, token issue and account-compromise clean-up at an assumed 1.5 hours per employee a year, with 70% of it removed by self-enrolled, phone-based FIDO2 sign-in. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Quote only. Akamai publishes no price or licence unit for Akamai MFA; a free 30-day trial comes first. It is its own product in Akamai’s security catalogue, so Enterprise Application Access and Secure Internet Access are quoted separately if you want them. TechBag maps your sign-in paths first, then quotes in INR with GST.
Best for proving the phone key on a pilot group
Best for a broader rollout
Best for a workforce-wide rollout
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Which IdP will call Akamai MFA — Okta, Entra ID, Ping, ADFS, Shibboleth or Keycloak — and is its connector documented?
Who must use the FIDO2 phone key or a passkey, and who may fall back to push, TOTP or SMS for now?
Does every user have a smartphone to enrol, and what will shared-device and phoneless staff use instead?
Will your VPN reach MFA over RADIUS through the PacketFence Gateway, checking LDAP or Active Directory?
Do Windows desktops, Linux servers or SSH need MFA, and has the Windows Logon plugin or Unix PAM been piloted?
What happens when a phone is lost: bypass codes, a helpdesk identity check, or a second enrolled key?
Akamai documents no Indian region for MFA data; does your DPDP or sector regulator need a written commitment?
What licence unit and term does the quote use? Ask for INR with GST and the price that applies after the trial.
Map your IdP, VPN and logon paths first, or let a TechBag advisor run the 30-day trial with a pilot group on the phone key.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.