This page is for sysadmins and MSP technicians who look after accounts, groups and admin rights for a small or mid-sized organisation, often with no dedicated identity team. The short answer: pick one directory as the source of truth (Active Directory or Microsoft Entra ID for Windows shops, FreeIPA for Linux-heavy estates), put an SSO layer such as Keycloak or authentik in front of the web apps that the directory cannot reach, rotate local admin passwords with Windows LAPS, and feed account and group changes into a SIEM such as Wazuh so that every new admin or late offboarding shows up as an alert rather than an audit finding.
The short list
| Tool | Best for | Licence | Platforms | Status |
|---|---|---|---|---|
| Wazuh | Alerting on account creation, group changes, failed logons; FIM on sudoers and SSH keys | Free, open source (GPL-2.0, Apache-2.0) | Server on Linux; agents for Windows, Linux, macOS, Solaris, AIX, HP-UX | Active (4.14.8, Sept 2026) |
| Open-AudIT | Inventory of local users and groups across Windows and Linux hosts | Free edition up to 100 devices (AGPL-3.0 code); paid editions | Linux, Windows Server | Active (6.0.4) |
| Rudder | Enforcing users, sudoers and SSH settings on Linux fleets | Free, open source (GPL-3.0) for Linux; Windows agents in paid plans | Linux server and agents | Active (9.1.4) |
| Salt Minion for Windows | Managing local users and groups on Windows from a Salt master | Free, open source (Apache-2.0) | Windows minion; master on Linux/Unix | Active (3008.3) |
| GlassWire | Seeing which apps on an admin PC talk to the network | Shareware (conditionally free) | Windows 10/11 64-bit, Android | Active (3.10.1138) |
| SpyShelter Free | Anti-keylogger layer on a personal or home-lab admin machine | Free for non-commercial use | Windows 10/11 64-bit, Windows 11 ARM | Active, slow releases (last build Sept 2025) |
| Wayk Bastion | Nothing new: retire it | Commercial, no longer sold | Windows / Linux (Docker) | Discontinued July 2021; successor Devolutions Gateway |
| Keycloak | Self-hosted SSO (OIDC, SAML) with LDAP/AD federation | Free, open source (Apache-2.0) | Java server, container images | Active |
| authentik | Self-hosted IdP with LDAP, RADIUS, SCIM and proxy outposts | Free, open source (MIT core); paid Enterprise tiers | Docker Compose, Kubernetes | Active |
| FreeIPA | Central Linux users, Kerberos SSO, sudo and host access rules | Free, open source (GPL-3.0) | Linux (Fedora, RHEL family) | Active |
| Microsoft Entra ID | Cloud directory for Microsoft 365 and SaaS SSO | Shareware (conditionally free): Free edition; P1, P2 and ID Governance paid | Cloud service | Active |
| Windows LAPS | Unique, rotating local admin passwords | Free, built into Windows | Windows 10/11, Windows Server 2019 and later (April 2023 update or newer) | Active; legacy Microsoft LAPS deprecated |
Pick one source of truth for identities
Most access problems in small IT teams come from accounts living in several places: AD, a cloud tenant, local server accounts and SaaS apps with their own user lists. Access management gets manageable once one directory owns the person and everything else follows it.
- Windows-centric with Microsoft 365: on-premises Active Directory synchronised to Microsoft Entra ID with Entra Connect, which Microsoft lists as free. The Free edition of Entra ID comes with Microsoft cloud services such as Microsoft 365 and Azure; Conditional Access needs P1, and Privileged Identity Management needs P2 or ID Governance.
- Linux-heavy estate: FreeIPA combines 389 Directory Server, MIT Kerberos, the Dogtag certificate system, DNS and SSSD, and can set up a trust with Active Directory, so Windows users can log in to Linux hosts without duplicate accounts.
- Web apps that speak OIDC or SAML but not LDAP: Keycloak or authentik in front of them, federated to your directory. Keycloak connects to LDAP and AD and can broker other OIDC or SAML providers. authentik’s open source tier covers OIDC, SAML, LDAP, SCIM, RADIUS, Kerberos and a proxy for apps with no login integration.
A quick Keycloak lab for testing a realm and an app integration (dev mode has insecure defaults, so never expose it):
docker run --name kc -p 127.0.0.1:8080:8080
-e KC_BOOTSTRAP_ADMIN_USERNAME=admin -e KC_BOOTSTRAP_ADMIN_PASSWORD=change_me
quay.io/keycloak/keycloak:latest start-dev
Provision and deprovision users without missing a system
User provisioning is the joiner-mover-leaver process: the right groups on day one, group changes when someone moves team, and everything removed on the last day. The tool matters less than having it scripted.
Active Directory with PowerShell
New-ADUser -Name "Jane Doe" -SamAccountName jdoe -UserPrincipalName jdoe@corp.example `
-Path "OU=Staff,DC=corp,DC=example" -Enabled $false
Add-ADGroupMember -Identity "Finance-RW" -Members jdoe
# leaver: record groups for the ticket, then disable and move
Get-ADPrincipalGroupMembership jdoe | Select-Object Name
Disable-ADAccount -Identity jdoe
Grant access through role groups such as “Finance-RW”, never directly to users.
FreeIPA
ipa user-add jdoe --first=Jane --last=Doe --email=jdoe@corp.example
ipa group-add-member devops --users=jdoe
ipa user-disable jdoe # leaver; keeps the record for audit
On clients, ipa-client-install --mkhomedir joins the host, and host-based access control (HBAC) and sudo rules then decide who may log in where, instead of local accounts on each server.
Keycloak and SaaS apps
Keycloak has an admin CLI for scripting: kcadm.sh create users -r corp -s username=jdoe -s enabled=true, and setting enabled=false on the leaver. For SaaS apps, prefer SCIM provisioning from your IdP. In Entra ID, automated user provisioning to gallery SaaS apps is available in the Free edition, while group provisioning and provisioning to on-premises apps need P1. authentik supports SCIM as well.
A leaver checklist that holds up in an audit: disable the directory account, revoke IdP sessions and tokens, remove privileged groups, transfer mailbox and file ownership, and close the ticket with the exported group list. To turn this into a runbook, see our sysadmin automation tools hub; StackStorm (free, Apache-2.0) logs every execution with its inputs and the user who started it.
Enforce local accounts, sudo and SSH keys on servers
Even with a central directory, servers collect local accounts, stray authorized_keys entries and sudo rules added “temporarily”. Configuration management fixes that by declaring the allowed state and reverting drift.
- Rudder ships techniques for users, SSH and sudoers. Start a rule (say, no root login and no password authentication over SSH) in audit mode to see non-compliant nodes before it changes anything.
- Salt Minion for Windows applies states for local users and groups, so the local Administrators group holds only the accounts you expect.
Quick manual checks on a Linux host before you automate:
awk -F: '$3 == 0 {print $1}' /etc/passwd # every UID 0 account
getent group sudo wheel # who can elevate
find / -name authorized_keys -path '*/.ssh/*' 2>/dev/null
To see local users across many machines at once, Open-AudIT audits Windows over WMI and Linux over SSH and records users along with hardware and software. Its free edition covers up to 100 devices. Inventory and ticketing are covered in more depth in our IT asset management and help desk tools hub.
Rotate local administrator passwords with Windows LAPS
A shared local admin password across all PCs is the classic path for lateral movement. Windows LAPS is built into Windows 10 and 11 and Windows Server 2019 and later once the April 2023 update or newer is installed. It is free, needs no separate install, and backs passwords up either to Active Directory or to Entra ID (Entra ID Free is enough), but not both at once. The legacy Microsoft LAPS MSI is deprecated, and Windows 11 23H2 and later block its installer.
Update-LapsADSchema
Set-LapsADComputerSelfPermission -Identity "OU=Workstations,DC=corp,DC=example"
# after the GPO "Configure password backup directory" applies:
Get-LapsADPassword -Identity PC042 -AsPlainText
Native Windows LAPS can encrypt passwords in AD and keep history; legacy emulation mode stores them in clear text, so use it only during migration. On domain controllers it can also manage the DSRM password.
Run access reviews that actually remove access
An access review checks that each person still needs each group, role and app. Done properly, it ends with access removed, not a spreadsheet nobody reads.
- Entra ID: access reviews cover group membership, enterprise app assignments, access packages and, through PIM, Entra and Azure roles. They need Microsoft Entra ID Governance licences, with some capabilities available under P2, and the licences cover both reviewers and the users being reviewed.
- Active Directory on a budget: export privileged groups and stale accounts every quarter, send each list to the group owner and record the answer in a ticket:
Get-ADGroupMember "Domain Admins" -Recursive | Select-Object SamAccountName
Search-ADAccount -AccountInactive -TimeSpan 90.00:00:00 -UsersOnly |
Where-Object Enabled | Select-Object SamAccountName, LastLogonDate
Review admin roles more often than ordinary groups, and give every guest and service account a named owner. In FreeIPA, review ipa group-show admins and the HBAC and sudo rules.
Detect account changes and suspicious logons
Security admin work is mostly about noticing identity changes you did not make. Wazuh is the free option that covers this well: its agents collect the Windows Security log and Linux auth logs, and its built-in rules flag account and group changes. Windows Security events worth a dashboard of their own:
- 4720 (account created), 4722 (enabled), 4725 (disabled), 4726 (deleted), 4724 (password reset attempt);
- 4728, 4732, 4756 (member added to a security-enabled global, local or universal group);
- 4625 (failed logon) and 4740 (account locked out).
Add file integrity monitoring for the files that grant privilege on Linux, in the agent’s ossec.conf:
<syscheck>
<directories realtime="yes" report_changes="yes">/etc/sudoers,/etc/sudoers.d</directories>
<directories realtime="yes">/root/.ssh</directories>
</syscheck>
Active response can block a brute-forcing IP on the host firewall; enable it after tuning, because Wazuh is noisy out of the box. The server is Linux-only, so Windows-only networks use the official OVA or Docker.
Harden the machines admins work from
Admin credentials are only as safe as the workstation that types them. Use a separate admin account, MFA on the IdP and a clean machine for privileged work. Two per-PC tools show what that machine is doing:
- GlassWire (shareware, conditionally free) graphs which applications connect where on 64-bit Windows 10/11. The free version keeps 24 hours of history and has no firewall control, which is Premium. No Windows Server support and no fleet management.
- SpyShelter Free adds anti-keylogger, anti-screenshot and mic/camera alerts on top of your antivirus. It is licensed for non-commercial use only, so it fits a personal or home-lab admin box; company machines need Pro or Ultimate.
Retire legacy remote access gateways
Remote access brokers are identity infrastructure too: whoever controls them reaches every endpoint. Wayk Bastion was discontinued in July 2021, with no support since the end of 2021. If one still runs, export its logs, stop it with Stop-WaykBastion, and remove its service, firewall rules and DNS record. The official successor is Devolutions Gateway (source under Apache-2.0 and MIT), managed from Devolutions Server or Devolutions Cloud. It listens on 7171/TCP for web sessions and 8181/TCP for native clients, and needs a trusted TLS certificate.
How to choose
- Map where accounts live today. List directories, cloud tenants, local server accounts and SaaS apps with their own users. Each one needs either federation or a documented manual process.
- Choose the directory by platform mix. AD plus Entra ID if you already pay for Microsoft 365, FreeIPA if most hosts are Linux, and an AD trust if you run both.
- Add SSO only where the directory cannot reach. Keycloak if you want a mature standards-based server; authentik if you also need LDAP, RADIUS or a proxy for legacy apps from the same product.
- Fix the cheap, high-impact gaps first. Windows LAPS and MFA for admins cost nothing extra and close the most common attack paths.
- Automate leavers before joiners. A late account creation annoys one person; a missed deprovisioning is a security incident.
- Monitor before you trust. Send identity events to Wazuh and check Entra ID tiers against the exact feature you need, since Conditional Access, PIM and access reviews sit in different paid tiers.
FAQ
What is the difference between identity management and access management?
Identity management covers the account lifecycle: creation, attributes, groups and removal. Access management decides what that identity may use and how it authenticates: SSO, MFA and group-based permissions. A directory is mainly identity; an IdP such as Keycloak is mainly access.
Is there a free identity and access management tool?
Yes. Keycloak (Apache-2.0), FreeIPA (GPL-3.0) and the open source tier of authentik (MIT core) are free and self-hosted. Microsoft Entra ID has a Free edition included with Microsoft cloud services, but Conditional Access, PIM and access reviews need paid tiers.
Keycloak or authentik: which should a small team pick?
Keycloak is the established choice for OIDC and SAML with LDAP or AD federation. authentik’s free tier adds LDAP and RADIUS outposts and an application proxy for older apps without SSO; privileged access management is in its paid Enterprise tier.
What is user provisioning and how does SCIM help?
User provisioning creates, updates and removes accounts in target systems when a person joins, moves or leaves. SCIM is the standard API that lets an IdP push those changes to SaaS apps automatically, so a disabled directory account is disabled in the app too.
Is Microsoft LAPS still supported?
Legacy Microsoft LAPS is deprecated, and its installer is blocked on Windows 11 23H2 and later. Use the built-in Windows LAPS, which adds encryption, history and Entra ID backup.
Can Wazuh alert when someone is added to Domain Admins?
Yes. With agents on domain controllers collecting the Security log, Wazuh’s built-in rules flag group membership changes such as event 4728. Raise the alert level for privileged groups so they stand out.
Last updated: 1 October 2026 · AdminHub Plus editorial team. Licence, version and platform details are checked against each developer's official documentation.