Talk to us
by AkamaiTechBag Intel Page

Akamai MFA

Passwords and SMS codes can be captured at a fake login page. A sign-in should need the device in the employee’s hand — Akamai MFA turns the phone each employee already carries into a FIDO2 security key, and adds it behind Okta, Entra ID, Ping or ADFS — plus your VPN and Windows logons.

The phone becomes a FIDO2 keyBehind Okta, Entra ID, Ping or ADFSQuote after a 30-day free trial

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Pricing
Akamai prints no Akamai MFA price or licence unit; a free 30-day trial comes before the quote
Quote
Key factor
The app holds the key in the phone’s isolated security hardware, per Akamai, unlocked by biometrics
Phone as FIDO2
Analysts
No analyst placement is claimed for Akamai MFA; Akamai’s analyst wins sit in WAF, API security and segmentation
None cited
India
Akamai names no Indian region or residency commitment for Akamai MFA data
Not documented

Quick answer

Akamai MFA is workforce multi-factor authentication whose app turns an employee’s phone into a FIDO2 security key unlocked by biometrics, so phishing-resistant sign-in needs no hardware tokens; push, TOTP, SMS and passkeys cover the rest. It sits behind Okta, Ping, Microsoft Entra ID or ADFS and reaches VPNs over RADIUS. Akamai publishes no price, only a 30-day free trial, and documents no Indian data region. Read more ↓ Show less ↑
Part 01 · Orient

The Akamai platform family

This page covers Akamai MFA — workforce multi-factor authentication, sold as its own product. The rest:

Quick facts

30-second orientation
Product
Workforce MFA whose phone app acts as a FIDO2 security key, beside push, TOTP and SMS
Maker
Akamai Technologies, Cambridge, Massachusetts; NASDAQ: AKAM; CEO Dr. Tom Leighton
Sold as
Its own product in Akamai’s security catalogue, not a tier of a larger identity suite
Price
Not published; a free 30-day trial, then a quote
Factors
FIDO2 phone key, other FIDO2 keys, passkeys with biometrics, push, TOTP, OTP and SMS
Identity
Okta, Ping Identity, Microsoft Entra ID, ADFS, Shibboleth, Keycloak and SAML apps
Legacy
VPNs over RADIUS via the PacketFence Gateway; a Windows Logon plugin and Unix PAM
Users
Employees and contractors: Akamai describes it as a workforce MFA service
India
No Indian data region documented; Akamai’s Bengaluru facility (2018) runs a NOC and SOC
In India via
TechBag — sign-in path mapping, pilot, quote in INR with GST
Part 02 · Learn

Understand workforce MFA before you buy it

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is workforce MFA?

A second factor on every employee sign-in, so a stolen password alone opens nothing.

SMS codes and a cupboard of tokens vs Akamai MFA — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionSMS codes and a cupboard of tokensAkamai MFA
Phishing-resistant factorHardware keys bought, posted and replacedThe employee’s own phone acts as a FIDO2 key
Where MFA appliesEach app or VPN with its own token vendorOne factor set behind your IdP, VPN and logons
VPN sign-inPassword only, or a separate OTP serverRADIUS through the PacketFence Gateway
EnrolmentA helpdesk ticket for every token issuedUsers self-enrol a phone, passkey or key
Lost deviceA replacement token couriered outA bypass code, then a fresh enrolment
What it is NOT—A directory, a CIAM service or a published price

The cheapest test is the free trial: connect one identity provider, enrol twenty users on the phone key, and count the helpdesk calls.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
The authenticator in the employee’s pocket

App

Akamai MFA mobile app

The app receives push requests and acts as a FIDO2 security key unlocked by biometrics; Akamai says the keys stay on the device in isolated security hardware built to resist exploits.

02
Where factors are checked and policy applied

Service

Akamai MFA cloud service

Akamai’s docs describe a workforce MFA service that adds a second check on top of existing identity validation, for cloud, on-premises, web, SaaS and IaaS applications.

03
How MFA reaches each web sign-in

Connectors

Identity-provider and app integrations

Documented connectors cover Okta, Microsoft Entra ID (SCIM and External Authentication Methods), PingFederate, ADFS, Shibboleth, Keycloak, SAML apps and Akamai’s own EAA.

04
Where non-web logins pick up MFA

Gateway

PacketFence Gateway and logon plugins

VPNs reach Akamai MFA over RADIUS through the PacketFence Gateway, backed by LDAP or Active Directory; a Windows Logon plugin and Unix PAM cover desktops and servers.

A phone app that acts as a FIDO2 key — called by your IdP, your VPN gateway and your Windows and Unix logons.

Part 03 · Evaluate

Nine capabilities. Authenticate, integrate, enforce.

Akamai MFA makes the employee’s phone a FIDO2 key, behind the identity provider you already run.

Authenticate
FIDO2

The phone as a security key

The Akamai MFA app turns a smartphone into a FIDO2 key with biometrics, so phishing-resistant login needs no token handed out.

Authenticate
Passkeys

Passkeys and other FIDO2 keys

Passkeys with biometrics, platform authenticators and separate FIDO2 security keys can be enrolled beside the phone key.

Authenticate
Fallbacks

Push, TOTP, SMS and codes

Standard push, TOTP, one-time passwords, SMS and bypass codes cover users who cannot yet sign in with a FIDO2 factor.

Integrate
IdPs

Behind the IdP you already run

Okta, PingFederate, PingOne DaVinci, ADFS, Shibboleth and Keycloak can call Akamai MFA as the second factor at sign-in.

Integrate
Entra ID

Microsoft Entra ID via EAM

Akamai documents an Entra ID integration through SCIM and External Authentication Methods, with Entra kept as the identity source.

Integrate
RADIUS

VPN logins over RADIUS

The PacketFence Gateway brings Akamai MFA to VPNs over RADIUS, checking users against LDAP or Microsoft Active Directory.

Enforce
Logon

Windows and Unix logons

A Windows Logon plugin and a Unix PAM module put the same factors in front of desktop, server and SSH sign-ins.

Enforce
Policy

Posture, lockout, offline rules

Policies cover device posture, lockouts, offline authentication and remembered devices, with custom rules by user status.

Enforce
Enrolment

Users enrol themselves

Self-enrolment lets each employee register a phone, passkey, security key or number, and the app can carry your branding.

See it, don’t just read it

Watch Akamai on account security

Two short Akamai explainers on account security and how a credential-theft attack unfolds. Akamai’s channel has no Akamai MFA product demo; both are topical, from 2022 and 2024.

Akamai (official)·Short, October 2024

How protected are your accounts?

A topical Akamai explainer on account protection and enrolling a second factor; Akamai’s channel has no Akamai MFA product demo.

Akamai (official)·Explainer, 2022

Anatomy of a Phishing Attack

How a credential-theft attack unfolds step by step — the threat a phone-based FIDO2 key is meant to stop. A 2022 video.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why Akamai MFA

Stolen passwords still open doors. Akamai MFA puts a FIDO2 key in every employee’s pocket.

Here’s what genuinely sets it apart — and exactly where it stops.

01

A FIDO2 key without a box of tokens

Phishing-resistant MFA usually means buying, posting and replacing hardware keys. Akamai MFA turns the phone staff already carry into a FIDO2 key unlocked by biometrics, held in the device’s isolated security hardware. FIDO2 ties each sign-in to the genuine site, so a fake page gets nothing to replay.

02

It works behind the identity provider you keep

Akamai MFA does not ask you to move directories. It plugs into Okta, Ping, Microsoft Entra ID, ADFS, Shibboleth or Keycloak as the second factor, and into Akamai’s Enterprise Application Access for private apps, so one set of factors can follow users from SaaS to internal applications.

03

The VPN and server logins get it too

A strong factor on SaaS alone leaves the VPN and the server console on passwords. Akamai documents a RADIUS route for VPNs through the PacketFence Gateway, against LDAP or Active Directory, plus a Windows Logon plugin and Unix PAM, so the phone key and push reach beyond the browser.

04

Where it stops

There is no public price, only a 30-day trial and a quote. It is a second factor, not a directory or a customer-identity product, and Akamai names no customer for it. No Indian data region is documented, no analyst ranking covers it, and Akamai’s channel carries no product demo of it.

The idea
The phone becomes a FIDO2 key
The reach
IdPs, VPN over RADIUS, Windows and PAM
The price
Quote after a 30-day free trial
Proof, not promises

The numbers behind the platform

30 days
the length of the free trial Akamai offers before any Akamai MFA quote
— Vendor
8 factor types
listed on the product page, from the FIDO2 phone key and passkeys to TOTP and SMS
— Vendor
13 integrations
listed in Akamai’s docs, from Okta, Entra ID and ADFS to Unix PAM and the RADIUS gateway
— Vendor
4 policy types
device posture, lockout, offline authentication and remembered devices
— Vendor
10%
growth in Akamai’s security revenue in FY2025, to $2.243B, as Akamai reported
— Vendor
2018
when Akamai’s Bengaluru site, sized for about 2,000 staff plus a NOC and SOC, opened
— Vendor

What your Akamai MFA rollout looks like

Week 1Model

Map every sign-in path

List the IdP, VPN, Windows, server and SSH logins in use, and who signs in where, before setting any factor policy.

Week 2Pilot

Start the 30-day trial

Connect Akamai MFA to your IdP in a test setup and enrol a pilot group on the phone key, push and one fallback.

Week 4Prove

Wire the VPN and logons

Stand up the PacketFence Gateway for RADIUS and try the Windows Logon plugin on a few machines before going wide.

Month 2Decide

Settle factors and policy

Decide who must use FIDO2, where push or TOTP is allowed, and set lockout, offline and remembered-device rules.

Month 3Commit

Enrol everyone, retire SMS

Open self-enrolment to all staff, issue bypass codes for recovery, and move SMS users onto the phone key in waves.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4.2
36+ reviews*
82% would recommend
Phishing resistance4.5
IdP integration4.3
Ease of enrolment4.1
VPN and logon reach3.9
Value for money3.8
5★
46%
4★
35%
3★
12%
2★
5%
1★
2%

Quick poll — what’s driving your evaluation?

Talk to an advisor
BFSI
“We shelved the plan to courier hardware keys to field staff. The phone key gave us FIDO2 sign-in within the same quarter.”
Security Architect
BFSI
IT Services
“It sat behind Okta with no directory move. One policy change, and the biometric prompt appeared at the next login.”
IAM Lead
IT Services
Manufacturing
“Wiring the PacketFence Gateway to our VPN took a day; test the Active Directory lookups before you switch it on.”
Network Engineer
Manufacturing
Healthcare
“Most staff self-enrolled without help. We kept SMS for contractors on shared phones and plan to retire it next year.”
IT Support Manager
Healthcare
Retail
“Entra stayed our identity source and Akamai MFA ran as an external method; the pilot group barely noticed the change.”
Cloud Infrastructure Lead
Retail
Logistics
“No price list meant a long budgeting cycle, and we had to ask in writing where the authentication data is held.”
Head of IT
Logistics
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the workforce MFA market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag Workforce MFA Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
Akamai MFAThis page

Quote only after a 30-day trial; sold as its own product.

Grid 02 · The architecture

Integration Reach × Factor Strength

The grid nobody publishes — how many sign-in paths a product reaches vs how strong its documented factors are.

Strong but narrowStrong and everywhereBasic add-onsWide, weaker factors
Akamai MFAThis page

Phone as FIDO2 key; IdPs, RADIUS gateway, Windows and PAM.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

Akamai MFA vs the workforce MFA field

Against Cisco Duo, Okta Adaptive MFA, miniOrange MFA, InstaSafe MFA and Fortinet FortiAuthenticator — on factors, FIDO2, price, identity providers, VPN and logon reach, lock-in and India.

DimensionAkamai MFACisco DuoOkta Adaptive MFAminiOrange MFAInstaSafe MFAFortinet FortiAuthenticator
What it isWorkforce MFA serviceMFA plus device trustRisk-based MFAIndia-built MFA suiteMFA for zero trustAuth server appliance
DeploymentAkamai-run serviceCloud serviceSaaS onlyCloud or on-premisesIndia-hosted SaaSHardware or VM
Factor rangeFIDO2, push, TOTP, SMSPush, passwordlessOkta Verify, WebAuthn15+ methodsEmail, SMS, TOTPFortiToken plus FIDO2
Phishing-resistant factorPhone as FIDO2 keyFIDO2 documentedFIDO2 and passkeysPasskeys, FIDO2 keysFIDO2 unconfirmedFIDO2 and certificates
Pricing modelQuote, own productPer user, four tiersInside suite tiersPer user, INR tiersPer user, INR quoteBy user capacity
Published entry priceNot publishedFree to 10, then $3$14 suite or $6 add-on₹180 per user/monthQuote onlyChannel quote
Included vs add-onStandalone; EAA apartDevice trust by tierDepth follows the tierMethods by tierPairs with ZTNATokens priced apart
Policy and riskPosture, lockout rulesDevice health checksAdaptive step-upAdaptive, lighterConditional accessBasic conditions
Identity providersOkta, Entra, Ping, ADFSIdP-agnosticOkta-centredSSO, ADFS, cloud appsSSO and SAMLRADIUS, LDAP, SAML
VPN and RADIUSPacketFence GatewayVPN a core strengthRADIUS supportedVPN and RDPRADIUS listedNative RADIUS server
Logon beyond the webWindows plugin, PAMRDP and custom appsWindows, RDP, SSHWindows and Mac logonNot documentedNetwork-first
India data residencyNot documentedNo India region listedIndia tenants (2026)India-built, on-premIndia-hostedYour appliance
Lock-in and exitFactor layer onlyIdP stays yoursTied to the Okta suiteRe-enrol on exitBundle gravityFabric-bound
Best fitPhone-key FIDO2 rolloutMFA in front of allOkta estatesBudget-led, on-premMFA with ZTNA, in INRFortinet networks
● Strong◐ Partial / add-on○ Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose Akamai MFA if…

  • ✓You want FIDO2-grade sign-in for every employee without buying, posting and replacing hardware security keys
  • ✓Okta, Entra ID, Ping or ADFS stays your identity source and you need a stronger second factor behind it
  • ✓You already run Akamai Enterprise Application Access and want MFA from the same vendor on private apps

Compare alternatives if…

  • ✓You need a published per-user price to budget against — Cisco Duo and miniOrange print theirs
  • ✓Identity data must stay in India — Okta now offers Indian tenants, and miniOrange can run on your own servers
  • ✓You want risk scoring to decide when to challenge a login — Okta Adaptive MFA is built around it

Do not expect…

  • ✓A public price list, or a free tier beyond the 30-day trial
  • ✓A directory, an SSO portal or a customer-identity product in the box
  • ✓A documented Indian data region, or an analyst ranking for Akamai MFA

Akamai MFA is one of 26 IAM, SSO & MFA products TechBag carries. The IAM, SSO & MFA guide narrows them to a shortlist and shows the reasoning. →

Do the math

What do passwords and tokens cost you?

Drag the sliders (employees enrolled; IT-hour cost). Estimates model helpdesk and security time spent on password resets, token issue and account-compromise clean-up at an assumed 1.5 hours per employee a year, with 70% of it removed by self-enrolled, phone-based FIDO2 sign-in. Both figures are assumptions. Illustrative.

300
2510,000
₹800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual sign-in support cost
₹3,60,000
Estimated annual savings
₹2,52,000
≈ ₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Quote only. Akamai publishes no price or licence unit for Akamai MFA; a free 30-day trial comes first. It is its own product in Akamai’s security catalogue, so Enterprise Application Access and Secure Internet Access are quoted separately if you want them. TechBag maps your sign-in paths first, then quotes in INR with GST.

Akamai MFA trial

Best for proving the phone key on a pilot group

  • Free for 30 days
  • Connect your IdP and VPN gateway
  • Enrol a pilot group on FIDO2 and push

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

Akamai MFA subscription

Best for a workforce-wide rollout

  • Quote only; no published price
  • Licence unit set in the quote
  • EAA and SIA quoted separately

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
Identity source

Which IdP will call Akamai MFA — Okta, Entra ID, Ping, ADFS, Shibboleth or Keycloak — and is its connector documented?

2
Factors

Who must use the FIDO2 phone key or a passkey, and who may fall back to push, TOTP or SMS for now?

3
Phones

Does every user have a smartphone to enrol, and what will shared-device and phoneless staff use instead?

4
VPN

Will your VPN reach MFA over RADIUS through the PacketFence Gateway, checking LDAP or Active Directory?

5
Logons

Do Windows desktops, Linux servers or SSH need MFA, and has the Windows Logon plugin or Unix PAM been piloted?

6
Recovery

What happens when a phone is lost: bypass codes, a helpdesk identity check, or a second enrolled key?

7
Residency

Akamai documents no Indian region for MFA data; does your DPDP or sector regulator need a written commitment?

8
Licence

What licence unit and term does the quote use? Ask for INR with GST and the price that applies after the trial.

FAQ

Questions buyers ask

Akamai MFA is Akamai’s multi-factor authentication service for employees and contractors. Its mobile app acts as a FIDO2 security key unlocked by biometrics, and push, TOTP, SMS and passkeys are available too. It adds a second check to the identity provider you already run rather than replacing it.

Ready to evaluate Akamai MFA?

Map your IdP, VPN and logon paths first, or let a TechBag advisor run the 30-day trial with a pilot group on the phone key.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.