Going Passwordless Without the Cloud: Deploying an On-Premise FIDO2 Authentication Server
Date: 2026-08-20
Author: Versasec

The push toward passwordless security is universal, but the path to get there isn’t always straightforward. For many, FIDO2 device-bound passkeys represent a modern movement towards passwordless MFA. However, a significant roadblock exists for highly regulated industries like defense, healthcare, and finance: the reliance on cloud identity providers (IdPs). Many organizations require absolute data sovereignty. Outsourcing authentication trust to an external cloud IdP is simply not an option due to compliance frameworks, privacy regulations, or the necessity of operating in air-gapped environments.
So, how do you achieve FIDO2 device-bound passkeys authentication without the cloud? The answer lies in deploying an on-premise FIDO2 authentication server.
The Challenge of Cloud-Mandated Passkeys
While major cloud providers have made significant strides in passkey adoption, their models often force organizations to move their entire identity infrastructure off-site. For enterprises that manage sensitive IP or critical infrastructure, this creates friction:
- Loss of Data Sovereignty: Security teams lose direct control over where authentication data is stored and processed.
- Compliance Roadblocks: Air-gapped networks cannot connect to external endpoints.
- Vendor Lock-In: Migrating away from a massive cloud IdP later becomes a monumental, costly task.
To close exposed security gaps without compromising infrastructure control, organizations need a self-managed solution.
Enter vSEC:CMS Identity: Your Self-Managed MFA Server
With the release of vSEC:CMS 7.4, Versasec introduced vSEC:CMS Identity, an advanced multi-factor authentication server designed specifically to be deployed within an organization’s own environment.
Whether deployed on-premises, air-gapped, or within a private cloud, vSEC:CMS Identity acts as a centralized authentication hub for all protected web applications, REST APIs, and corporate web services.
How It Works
vSEC:CMS Identity is not a standalone identity provider; rather, it natively integrates into your existing vSEC:CMS deployment.
- Instant Issuance: During the initial credential issuance process, administrators (or users via self-service) generates a device-bound FIDO2 passkey bound to vSEC:CMS Identity on their hardware token.
- Standards-Based Authentication: When a user attempts to access a protected web application, vSEC:CMS Identity securely authenticates them using WebAuthn and FIDO2 protocols via OIDC.
- Absolute Control: All cryptographic keys, user mappings, and audit logs remain strictly within your local, controlled environment.
Bridging the Gap Between Legacy and Modern Security
By utilizing an on-premise FIDO2 server, organizations don’t have to choose between strict data governance and modern security. You can extend your trusted credential management system to provide a frictionless login experience, eliminate vulnerable passwords, and actively prevent phishing attacks, all while keeping your authentication infrastructure strictly in-house.
Ready to take control of your authentication infrastructure? Whether you require the absolute sovereignty of an on-premise installation or prefer the streamlined, managed experience of vSEC:CLOUD, our FIDO2 solutions adapt to your specific compliance and operational needs. vSEC:CMS Identity is included for customers utilizing vSEC:CMS Premium and vSEC:CLOUD. Read the full press release or schedule a call with a Versasec Identity Expert today.
vSEC:CMS
Our product suite provides all the software tools to administrate and manage credentials in a secure and convenient way.
Schedule a Strategic Call
Versasec provides enterprise credential management to accelerate phishing-resistant MFA. Our solutions enable customers to securely authenticate, issue and manage user credentials more cost effectively. Schedule a 1:1 Strategic Call With Our Identity Experts.
Job Openings
We are always looking for new exceptional persons to join our team! Find out more about our job openings.
