AUTHENTICATION AND MFA · ON-PREMISE

Imago

Centralized identity management, for every access point in your company.

The on-premise authentication and MFA server: passwords verified against your corporate directory or IdP (any LDAP server, Active Directory, OIDC, SAML, RADIUS), second factor with TOTP/FIDO2 and with the Imago BioCard biometric card. Modern SSO and legacy protocols, all under the same policies.

Download the brochure (PDF)Let's talk
MULTIPLE PROTOCOLSMFAFIDO2 BIOMETRIC CARDLEGACY APPLICATIONSPROTECTED BOOT WITH PBAANTI-COERCIONON-PREMISE
WHY IMAGO

What Trantor® Imago solves

Imago exists to unify access and authentication policies, bring MFA to every application, and harden the most vulnerable part of the perimeter, such as the workstations.

Passwords everywhere

Users hate memorizing long passwords, let alone changing them every 90 days. With Imago you bring passwordless authentication to the whole company, using FIDO2 technology or client certificates.

Fragmented policies and audit

Each application enforces its own access rules and keeps its own logs, hoping that record even exists. You need a single place to define all the rules and see all the logs.

Inconsistent MFA, not always available

Some applications support MFA, others don’t; some reuse the MFA you already use elsewhere, others don’t. Users end up juggling several different 2FA channels, and on some applications cannot use it at all.

Legacy that holds modernization back

Maintenance-only apps won’t risk breaking their code for new login methods. Imago solves this in two ways: it exposes protocols such as LDAP and RADIUS, and with Imago 4Legacy it authenticates on a modern portal before landing users on the app.

Authentication doesn’t happen in your company

Many solutions force authentication through the vendor’s cloud: lock-in (FIDO2 at Windows logon requires the Microsoft Entra ID cloud, with no alternative) and no way to unify online and isolated departments.

Your fingerprint, without giving up the data

Many biometric systems store the fingerprint on a server or on the computer: a privacy nightmare. With Imago BioCard cards the fingerprint stays on the card, always with you, and you use it to authenticate everywhere.

WHAT TRANTOR® IMAGO IS

“A server appliance to manage passwords, second factors, policies and logs in a centralized, uniform way. Imago brings modern authentication to every application, works even fully on-premise, and plugs into a system you already run, such as Active Directory.”

HOW IT WORKS

The components of the solution

A central appliance on AlmaLinux 10, plus the components that bring Imago where it is needed: onto Windows workstations, in front of legacy apps, at computer boot, and onto the card you carry with you.

THE CENTRAL SERVER

Trantor® Imago Appliance

Central server based on AlmaLinux 10, on-premise on bare metal or virtual machines, x86 or ARM. Two or more appliances unlock load balancing and high availability.

WINDOWS CREDENTIAL PROVIDER

Trantor® Imago CP

The credential provider for Windows 10/11 and Server 2019/2022/2025, x64 and ARM64: passwords, TOTP, FIDO2, OIDC device-code, passwordless and anti-coercion on Microsoft workstations. It does SSO with Imago PBA, works temporarily offline and over RDP too.

PROXY FOR LEGACY

Trantor® Imago 4Legacy

The identity-aware proxy puts FIDO2/TOTP in front of legacy apps: the portal authenticates, the proxy lets users in with ephemeral one-time credentials. The legacy application never sees the user’s real password.

PRE-BOOT AUTHENTICATION

Trantor® Imago PBA

A small AlmaLinux 10 system installed alongside Windows: it authenticates at boot through Imago and unlocks the BitLocker of the Windows partition. Signed immutable images, data with LUKS2+TPM, installed by the Imago PBA Manager program with no ISO boot. With Intel Boot Guard or AMD PSB it also protects against firmware tampering.

FIDO2 BIOMETRIC CARD

Trantor® Imago BioCard

FIDO2 cards with on-board biometrics, natively integrated with Imago: the fingerprint stays on the card and is never transmitted to computers or servers.

PROTOCOLS EXPOSED TO APPS

LDAP/LDAPS (password or password+TOTP), RADIUS (password, password+TOTP, challenge-response or 802.1X with EAP-TLS/TTLS-PAP/TTLS-GTC/PWD/PEAP-GTC), OpenID Connect (PKCE, CIBA, device-code) and SAML 2.0. For user and group enumeration: LDAP/LDAPS and SCIM 2.0.

BACKENDS IT RELIES ON

As an authentication source: LDAP/LDAPS, RADIUS (802.1X and challenge too), OpenID Connect (device-code, PKCE, CIBA) and SAML 2.0. For user and group enumeration: LDAP/LDAPS, SCIM 2.0 or file import.

MFA and passwordless

Second factor managed locally with TOTP or FIDO2, or through an external MFA server via API. FIDO2 can be the only factor for passwordless access, handy with BioCards that unlock by fingerprint. MFA reaches legacy apps that speak LDAP or RADIUS, too.

Anti-coercion system

A user can discreetly signal a login performed under duress: Imago immediately alerts the configured administrators. On Windows (with PBA or CP) it can also run a script that unmounts confidential drives and mounts decoy ones, for a realistic but harmless environment.

WiFi authentication with SecureWiFi

If you also run Trantor® SecureWiFi, you use Imago as the WiFi network backend: SecureWiFi configures Imago’s RADIUS/802.1X connector on its own and generates WiFi profiles for Windows, macOS, Linux, Android and iOS, so users configure nothing by hand.

Protocol and SSO proxy

Imago combines exposed protocols and protocols used towards realms, acting as a converter: an app connects in RADIUS+challenge and Imago talks OIDC+device-code to the realm; a passwordless FIDO2 app, and Imago queries Active Directory for the access token.

THE CARD

Imago BioCard

Full product name: Trantor® Imago BioCard. The biometric FIDO2 card of the range: NFC and smartcard readers, the credential is released at the touch of a fingerprint.

Trantor Imago BioCard
Card specifications
Form factor

Standard-size card, perfect to carry with you at all times.

Technology

FIDO2 / WebAuthn: public-key credential, phishing-resistant.

Biometrics

On-board fingerprint sensor: the card unlocks at a touch and the biometric data never leaves it.

Interfaces

Contactless NFC and smartcard readers.

Where it works

Web applications with native WebAuthn, Windows/Linux/macOS workstation logon, and even legacy applications thanks to Trantor® Imago 4Legacy.

Enrollment

From the Imago self-service portal, independently.

If lost

The card is revoked centrally; TOTP remains as a fallback on the channels that use it.

THE FINGERPRINT STAYS ON THE CARD

The sensor verifies the fingerprint on board: no biometric data travels over the network or ends up on a server. The card unlocks itself; Imago verifies the credential.

POSITIONING

Trantor® Imago and the alternatives

Every alternative below is a serious product with real strengths. The useful comparison is not the feature list: it is where identities live, whether legacy is included or left out, and what happens when the link to the cloud goes down.

SOLUTIONWHERE CONTROL LIVESMFA AND PROTOCOLSWORTH CONSIDERING
Trantor® Imago
Trantor® · Italy
On-premise server, in your network: no mandatory cloud, works in isolated environments tooTOTP and biometric FIDO2 card; passwords on your directory (any LDAP, Active Directory included) or via OIDC/SAML; modern SSO, proxy for legacy and secure boot with Imago PBAOne policy engine and one audit trail for every access point; credentials never leave the company; direct support from the development team
Microsoft Entra ID
Microsoft · non-EU
Microsoft cloud, not optional: even hybrid goes through Microsoft’s serversMFA with Authenticator, FIDO2 and Windows Hello; OIDC/SAML SSO; legacy stays on the on-premise ADThe default choice in Microsoft shops, with MFA in the per-user P1/P2 plans; management, policies and identities live in the vendor’s cloud; no PBA; no proxy for legacy apps
Okta Workforce Identity
Okta · non-EU
Vendor cloud, not optionalBroad MFA catalog (push, FIDO2, TOTP); SSO across thousands of catalog apps; agents for AD and LDAPThe reference cloud IdP, with the widest ecosystem; per-user, per-module pricing; no PBA; no proxy for legacy apps
Cisco Duo
Cisco · non-EU
Cisco cloud, not optionalOne of the easiest push MFAs to adopt; SSO in the higher editions; directories, RADIUS and LDAP require the Authentication ProxyFast adoption and a good user experience; per-user monthly fee, and the service depends on cloud reachability; no PBA; no proxy for legacy apps
Keycloak
open source · Red Hat
On-premise or in the cloudFull OIDC and SAML, TOTP and WebAuthn/FIDO2 included; federation with LDAP and Active DirectoryMaximum freedom and a huge community; hardening, updates and high availability remain the customer’s job, with commercial support only via Red Hat; no PBA; no Windows Credential Provider; no proxy for legacy apps
privacyIDEA
NetKnights · Germany
On-premiseMulti-token MFA server (TOTP, WebAuthn, smartcards); for SSO and access it relies on an IdP or on the PAM/RADIUS modulesThe other European alternative, open source; a somewhat dated management UI; it covers the second factor more than the whole: SSO, self-service and legacy must be assembled piece by piece; no PBA; limited legacy support (e.g. TOTP as a password suffix)

Positioning summary as of August 2026, from public sources. Every platform cited is a valid product in its own context of use; trademarks belong to their respective owners.

MODEL

Trantor® Imago at a glance

What it offers your company

Modern SSO

OIDC and SAML for modern web applications and, through the proxy, for legacy ones.

Extended MFA

Offline TOTP, FIDO2 cards and tokens, and integration with external MFA services (for example SMS push).

Workstation access with MFA

Windows, Linux and macOS; TOTP or FIDO2, even on-premise and without any cloud.

Self-service portal

FIDO2/TOTP enrollment, password change and reset, second-factor reset.

Proxy for legacy

FIDO2 in front of apps that only speak LDAP or RADIUS.

Centralized log and policies

Every application, every authentication method, all with unified policies and audit.

How it ensures high security standards

Hardened appliance

The central server uses digitally signed immutable Linux images, LUKS2+TPM disk encryption, and root access disabled, allowed only through an emergency key kept in a safe.

FIDO2/WebAuthn authentication

A phishing-proof system with strong cryptographic properties.

Biometric cards

Imago BioCards keep the fingerprint on the card itself, and protect FIDO2 authentication using biometry in place of a PIN.

Modern protocols everywhere

Imago 4Legacy and Imago’s proxy features let you adopt modern technologies (like OpenID Connect with PKCE, SCIM 2.0 and FIDO2) everywhere.

Anti-coercion system

Because cybersecurity is strictly linked to physical security.

OPEN STANDARDS, NO RANSOM

Imago speaks OIDC, SAML, RADIUS, LDAP, SCIM and WebAuthn: open standards at every level. Your authentication stays readable and verifiable, even without us.

TOGETHER

Works with the rest of the ecosystem

Imago + SecureWiFi

SecureWiFi configures Imago’s RADIUS/802.1X connector on its own and generates WiFi profiles for every system.

Discover SecureWiFi >
Imago + TVirt

The Imago appliance runs as a dedicated machine, or as a VM on TVirt, with snapshots and high availability.

Discover TVirt >

Explore the whole ecosystem >

Last updated: 10 August 2026. The contents of this page follow the brochure of that revision.

THE NEXT MOVE

Let’s give your access a face.

Book a consultation now to map your company’s access: modern apps, legacy, VPN and workstations. And we’ll tell you what Imago can do for you.

e-mailAll contacts