7,363 open-source and SaaS tools, with GitHub stats refreshed every day.

12 alternatives ranked by real activity

Open-source Microsoft Entra ID alternatives

A curated, ranked list of the 12 best open-source alternatives to Microsoft Entra ID.

The best open-source alternative to Microsoft Entra ID is Keycloak. If that doesn't suit you, other good options are Authelia, Authentik, ZITADEL and Casdoor.

Microsoft Entra ID alternatives are mainly auth & identity tools. 12 of them shipped code in the last 30 days, 12 can be self-hosted, and 7 use a permissive licence.

Last updated October 2, 2026 · ranked by GitHub stars, growth and recent commits

Keycloak

Keycloak is an open-source identity and access management server that adds single sign-on, user management and authorization to applications.

GitHub stars
37k
Last commit
today
Latest release
26.8.0
Licence
Apache-2.0
Self-hosted
Yes
keycloak.orgKeycloak homepage screenshot

Keycloak is an open-source identity and access management server. It lets application teams add authentication and secure services without building their own login system, since Keycloak handles storing users and authenticating them. The project is written in Java, released under the Apache-2.0 license and governed under the Cloud Native Computing Foundation code of conduct.

Keycloak supports standard protocols such as OpenID Connect and SAML, and offers user federation, strong authentication, user management and fine-grained authorization. You can run it from the downloadable distribution using a start-dev command, or use the official Docker image published on Quay for containers and Kubernetes setups. The project provides documentation, a user mailing list and community channels for help, along with guidance for building and testing from source.

Key features

  • Single sign-on with OpenID Connect and SAML
  • User federation with external directories
  • Strong and multi-step authentication options
  • Central user and account management
  • Fine-grained authorization policies
  • Docker image and standalone distribution

Pricing: Free and open source under the Apache-2.0 license; you host and operate it yourself.

Read more about KeycloakWebsite GitHub

Authelia

A self-hosted single sign-on and multi-factor authentication portal that protects web applications, certified for OpenID Connect and ready for post-quantum cryptography.

GitHub stars
29k
Last commit
yesterday
Latest release
v4.39.28
Licence
Apache-2.0
Self-hosted
Yes
authelia.comAuthelia homepage screenshot

Authelia is an open-source authentication and authorization server that provides single sign-on and multi-factor authentication for web applications. It sits in front of your services, usually alongside a reverse proxy, so users sign in once at a portal and are checked against policies before reaching an app.

Supported factors and backends include TOTP, push notifications, two-factor methods and LDAP, according to its topics, and it is described as OpenID Certified and ready for post-quantum cryptography. It is written in Go and runs well as a small container, with documentation for Docker and Kubernetes deployments. Self-hosters often use it to add a consistent login and second factor to tools that have weak or no authentication of their own.

Authelia is licensed under Apache-2.0. As an authentication component, it is meant to be run on your own infrastructure, and it suits home labs, small organizations and teams wanting a lightweight identity layer without a heavier enterprise identity platform.

Key features

  • Single sign-on portal for web apps
  • Multi-factor authentication including TOTP
  • Push notification verification
  • LDAP user backend support
  • OpenID Connect support
  • Docker and Kubernetes deployment

Pricing: Free and open source under the Apache-2.0 license.

Read more about AutheliaWebsite GitHub

Authentik

An open-source identity provider for single sign-on that supports SAML, OAuth2 and OIDC, LDAP and RADIUS, built for self-hosting from home labs to large clusters.

GitHub stars
26k
Last commit
today
Latest release
version/2026.8.3
Self-hosted
Yes
goauthentik.ioAuthentik homepage screenshot

authentik is an open-source Identity Provider for modern single sign-on. It supports SAML, OAuth2 and OpenID Connect, LDAP, RADIUS and more, and is designed for self-hosting at any scale, from a small lab to production clusters. A reverse-proxy mode also lets it protect applications that lack native SSO support.

The project positions its enterprise offering as a way for organizations to replace incumbent identity providers (Okta, Auth0, Entra ID or Ping Identity) in large-scale identity management. For installation, Docker Compose is recommended for small and test setups, a Helm chart for Kubernetes suits larger setups, and official templates exist for AWS CloudFormation and a one-click DigitalOcean Marketplace app.

The codebase is mostly Python with Kubernetes tooling, and the license is listed as 'Other' on GitHub because it mixes open-source and enterprise components, so check which features fall under which terms. authentik is a common choice for self-hosters and companies who want to centralize logins across internal tools without paying per-user fees to a hosted identity vendor.

Key features

  • SAML and OAuth2/OIDC provider
  • LDAP and RADIUS support
  • Reverse-proxy authentication for apps
  • Docker Compose and Helm chart installs
  • AWS CloudFormation and DigitalOcean templates
  • Enterprise edition for large deployments

Pricing: The open-source edition is free. Enterprise costs $5 per user per month billed annually, plus $0.02 per external user; Enterprise Plus starts at $20k per year. No hosted version is offered.

Read more about AuthentikWebsite GitHub

ZITADEL

An open-source identity and access management platform with SSO, MFA, passkeys, OIDC, SAML, SCIM and native multi-tenancy, available self-hosted or as a cloud service.

GitHub stars
15k
Last commit
today
Latest release
v4.19.4
Licence
AGPL-3.0
Self-hosted
Yes
Hosted version
Available
zitadel.comZITADEL homepage screenshot

ZITADEL is an identity and access management platform, open source, for teams that need more than basic login. It targets SaaS products, B2B platforms and self-hosted IAM stacks, and bundles single sign-on, multi-factor authentication, passkeys, OIDC, SAML and SCIM in an API-first design, with an emphasis on a mature multi-tenancy model.

A comparison table in the README sets it against FusionAuth, Keycloak and Auth0 or Okta on points such as open-source status, self-hosting, infrastructure-level tenants, native B2B organizations and a comprehensive event-stream audit trail. Topics list standards and features including OAuth 2, OpenID Connect, FIDO2, 2FA and passkeys. The positioning is that you can own the identity layer without vendor lock-in while still getting a polished product.

ZITADEL is written in Go and licensed under AGPL-3.0, with a website, chat, docs and blog. You can run it yourself or use the vendor's managed cloud. It suits developers and security teams building multi-tenant applications who want a self-hostable alternative to commercial identity providers.

Key features

  • Single sign-on with OIDC and SAML
  • Multi-factor authentication and passkeys
  • SCIM user provisioning support
  • Native multi-tenancy with B2B organizations
  • Event-stream audit trail
  • API-first, self-hostable design

Pricing: Free cloud plan for 100 daily active users. Pro costs $100 per month and includes 25,000 daily active users; Enterprise is custom and can run on your own infrastructure.

Read more about ZITADELWebsite GitHub

Casdoor

An open-source identity and access management platform written in Go, providing single sign-on, OAuth, OIDC, SAML, MFA and a web console for users and applications.

GitHub stars
15k
Last commit
today
Latest release
v4.13.0
Licence
Apache-2.0
Self-hosted
Yes
casdoor.aiCasdoor homepage screenshot

Casdoor is a self-hosted identity and access management platform with a web console. It acts as a single sign-on and authentication server, so applications can delegate login to it instead of implementing their own user management, sessions and password handling.

Supported protocols include OIDC, OAuth 2.0, SAML 2.0, LDAP, CAS and SCIM 2.0, alongside WebAuthn, TOTP and MCP, and it can connect to identity providers such as Google Workspace, Microsoft Entra ID and GitHub. Sign-in options include passwords, email or SMS codes, WebAuthn and Face ID, plus any social providers you enable. The admin console covers users, tokens, organizations, providers and applications, and settings change without a redeploy or config file.

Casdoor is written in Go and licensed under Apache-2.0. A quick trial runs on SQLite with sample data and needs no separate database or config file. Its newer positioning emphasizes AI agents, with an MCP and agent gateway for LLM tooling, and hosted demo instances are available for trying it before installing.

Key features

  • Single sign-on and authentication server
  • OIDC, OAuth 2.0 and SAML support
  • LDAP, CAS and SCIM integration
  • WebAuthn, TOTP and MFA
  • Social and enterprise identity providers
  • Web console for users and organizations
  • MCP and agent gateway features

Pricing: Free and open source under the Apache-2.0 licence.

Read more about CasdoorWebsite GitHub

LLDAP

lldap is a lightweight authentication server with a simplified LDAP interface and web UI, aimed at self-hosters who need LDAP for apps like Nextcloud.

GitHub stars
6.5k
Last commit
6 days ago
Latest release
v0.6.3
Licence
GPL-3.0
Self-hosted
Yes

lldap is a lightweight authentication server that exposes an opinionated, simplified LDAP interface. It is aimed mostly at self-hosting setups where open-source components such as Nextcloud only support LDAP as an external authentication source, and where running a full directory server would be more work than needed.

It comes with a web frontend for managing users, and also lets users update their own details and reset a forgotten password via email. By default data is stored in SQLite, with MySQL, MariaDB or PostgreSQL as alternative backends. It integrates with services such as Keycloak, Authelia and Nextcloud, and for features like OAuth or OpenID support you can add components such as Keycloak or Authelia that use lldap as the source of truth for users.

The project is written in Rust, licensed under GPL-3.0 and uses the OPAQUE protocol. The README states plainly that it is not meant to be a full LDAP server and points to OpenLDAP for that. It installs from OCI images, Kubernetes, TrueNAS or distribution packages.

Key features

  • Simplified LDAP interface for authentication
  • Web UI for user management
  • Self-service password reset by email
  • SQLite, MySQL, MariaDB and PostgreSQL backends
  • Works with Keycloak, Authelia and Nextcloud
  • Install from OCI images or distro packages

Pricing: Free and open source under the GPL-3.0 licence.

Read more about LLDAPGitHub

Kanidm

Kanidm is a Rust identity management server offering OIDC, LDAP, RADIUS, WebAuthn and SSH key authentication for home labs through organizations.

GitHub stars
5.4k
Last commit
yesterday
Latest release
v1.11.2
Licence
MPL-2.0
Self-hosted
Yes
kanidm.comKanidm homepage screenshot

Kanidm is an identity management platform written in Rust. Other applications and services can offload authentication and identity storage to it, and the project aims to be a complete identity provider so that you should not need to add components such as Keycloak next to it.

It covers a broad set of protocols and features: OpenID Connect, LDAP, RADIUS, SCIM, WebAuthn passkeys and SSH key authentication, according to the repository topics. To keep it manageable, the design favors secure defaults, minimal configuration and components that repair themselves, so the same system can serve small home labs, families and small businesses as well as larger deployments.

Kanidm is licensed under MPL-2.0 and runs on your own servers, with documentation and a community around the project. It suits administrators who want a single, secure place to manage users, groups and logins for their services without operating a heavyweight identity stack.

Key features

  • OpenID Connect identity provider
  • LDAP and RADIUS interfaces
  • WebAuthn and passkey authentication
  • SSH key authentication support
  • SCIM user provisioning support
  • Strict secure defaults, simple configuration

Pricing: Free and open source under the MPL-2.0 license.

Read more about KanidmWebsite GitHub

MaxKey

Java identity and access management product offering single sign-on with OAuth 2, OpenID Connect, SAML, CAS, JWT, and SCIM, plus RBAC and user lifecycle management.

GitHub stars
2k
Last commit
9 days ago
Latest release
4.1.12
Licence
Apache-2.0
Self-hosted
Yes
maxkey.topMaxKey homepage screenshot

MaxKey, from the Dromara community, is an IAM and IDaaS product written in Java and released under the Apache-2.0 license. It provides single sign-on, identity management, access management, RBAC-based permission control, and resource management. The name is a homophone of a phrase about a master key that unlocks enterprise security needs, according to the README.

It supports standard protocols including OAuth 2.x and OpenID Connect, SAML 2.0, CAS, JWT, and SCIM, and its topics also list LDAP, Active Directory, Kerberos, multi-factor authentication, TOTP, and multi-tenancy. Features focus on user lifecycle management and compliance, and the project presents itself as open, secure, and self-controlled. Documentation is in English and Chinese.

MaxKey is aimed at enterprises, particularly in Chinese-speaking markets, that need a self-hosted alternative to commercial identity platforms. Teams should confirm industry claims in the README against their own requirements.

Key features

  • Single sign-on across applications
  • OAuth 2.x, OpenID Connect, SAML 2.0, and CAS
  • SCIM provisioning and user lifecycle management
  • RBAC permission management
  • LDAP, Active Directory, and MFA integration
  • Multi-tenancy support

Pricing: Free and open source under the Apache-2.0 license.

Read more about MaxKeyWebsite GitHub

Rauthy

Rauthy is a lightweight single sign-on identity provider written in Rust, supporting OpenID Connect, OAuth 2, PAM and passkey-first logins.

GitHub stars
1.4k
Last commit
today
Latest release
v0.36.2
Licence
Apache-2.0
Self-hosted
Yes
sebadob.github.ioRauthy homepage screenshot

Rauthy is an identity and access management server written in Rust. It acts as a single sign-on identity provider supporting OpenID Connect, OAuth 2 and PAM, and it aims to be simple to set up and run while keeping secure defaults. The project received an independent security audit as part of its funding, and the findings were addressed in a later release.

It puts heavy emphasis on passkeys and strong security, with FIDO2 and WebAuthn login options, MFA and passwordless flows. Defaults include ed25519 token signing and S256 PKCE for new OIDC clients, though these can be relaxed for older systems. Other features include high availability, client branding, UI translation, an admin UI, events and auditing, SCIM, and support for IoT and headless CLI tools.

By default Rauthy runs on top of Hiqlite, so it needs no external database, with Postgres available as an alternative. It is licensed under Apache-2.0, can run on modest hardware, and is self-hosted. Its topics reference Keycloak as the kind of software it can replace, so it suits small teams and homelabs that want a compact SSO server.

Key features

  • OpenID Connect and OAuth 2 provider
  • PAM integration for Linux logins
  • Passkeys, FIDO2, and WebAuthn
  • Admin UI with events and auditing
  • Built-in database with optional Postgres
  • SCIM and client branding support

Pricing: Free and open source under the Apache-2.0 licence.

Read more about RauthyWebsite GitHub

FreeIPA

FreeIPA is an integrated identity, authentication and access control system for Linux and UNIX networks, built on LDAP, Kerberos and PKI.

GitHub stars
1.3k
Last commit
today
Licence
GPL-3.0
Self-hosted
Yes
freeipa.orgFreeIPA homepage screenshot

FreeIPA lets Linux administrators centrally manage identity, authentication and access control for Linux and UNIX systems. It provides command-line and web-based management tools that are simple to install and use, and it focuses on ease of management and automation of installation and configuration. The repository is a mirror of the upstream project and is written mostly in Python.

The README lists benefits such as letting users access every machine with the same credentials and security settings, transparent access to personal files from any machine, grouping to restrict services and files to specific users, central management of passwords, SSH public keys, sudo rules, keytabs and access control rules, and delegation of selected administrative tasks to other power users.

FreeIPA bundles well-known open-source components with unified tools: an LDAP server based on the 389 project, a Kerberos KDC based on MIT Kerberos, a public key infrastructure based on Dogtag, Samba libraries for Active Directory integration and a DNS server based on BIND. It can integrate into Active Directory environments through cross-realm Kerberos trust or user synchronization. The code is licensed under GPL-3.0.

Key features

  • Central identity and authentication management
  • LDAP and Kerberos services
  • Certificate authority based on Dogtag
  • Integrated DNS server
  • Sudo rules and SSH key management
  • Active Directory trust and synchronization

Pricing: Free and open source under the GPL-3.0 license.

Read more about FreeIPAWebsite GitHub

2 more Microsoft Entra ID alternatives

Microsoft Entra ID alternatives: questions

What is the best open-source alternative to Microsoft Entra ID?
Keycloak is the top-ranked open-source alternative to Microsoft Entra ID on Enlisted: Keycloak is an open-source identity and access management server that adds single sign-on, user management and authorization to applications. Other strong options are Authelia, Authentik, ZITADEL and Casdoor.
Are these Microsoft Entra ID alternatives free?
All 12 are open source, so the code is free to use under its licence, and all of them can be self-hosted on your own server or computer. 2 also offer a paid or managed cloud version if you'd rather not host it yourself.
How is this list of Microsoft Entra ID alternatives ranked?
By a score built from GitHub stars, star growth over the last 30 days and how recently the code changed. 12 of these projects shipped code in the last 30 days. Data is refreshed daily, and nobody can pay to move up.

People also look for alternatives to…

View all