Skip to content
Notifications
Clear all

Banyan alternatives that work well with Okta and Azure AD?

4 Posts
4 Users
0 Reactions
24 Views
(@gregm)
Honorable Member
Joined: 3 months ago
Posts: 424
Topic starter   [#27169]

Banyan's getting a lot of buzz lately as the "modern" zero trust overlay, especially for legacy apps. But let's be honest, it's not the only player that can integrate with your existing IdP. If you're already invested in Okta or Azure AD, you're probably looking to extend that investment, not create another siloed policy engine.

I've been auditing access patterns for a few mid-sized enterprises, and the friction often comes from solutions that promise simplicity but add configuration complexity elsewhere. What are people actually using that provides a clean, auditable bridge from a strong identity provider (like Okta/Azure AD) to the actual resources, without inventing a new universe of policies? I'm particularly interested in alternatives that maintain clear, immutable audit logs back to the IdP event, and don't treat encryption as an afterthought.

The usual suspects like Zscaler and Palo Alto Prisma Access come up, but they feel like bringing a tank to a knife fight for some use cases. Are there lighter-weight, API-driven approaches—maybe even a couple of open-source components wired together—that handle the device trust and conditional access piece reliably, letting Okta or Azure AD be the true source of identity? Bonus points for anything with a sane story for GDPR compliance in the data plane, not just the control plane.

—Greg


Trust but verify


   
Quote
(@cloud_ops_learner_3)
Honorable Member
Joined: 5 months ago
Posts: 479
 

I ran into this same issue last month when we were trying to avoid vendor lock-in. Have you looked at OpenZiti? It's an open-source overlay you can self-host, and it has built-in connectors for Okta and Azure AD.

The policy engine lives in the controller, so you can define access rules directly from your IdP groups. It keeps a unified audit log that ties session start/stop events back to the original authentication event in Okta, which was a big deal for our compliance checks.

For a lighter-weight approach, have you considered Tailscale with OIDC? I've heard it does a pretty good job with device posture checks and conditional access, letting Okta handle the heavy lifting on identity.



   
ReplyQuote
(@daisym)
Reputable Member
Joined: 3 months ago
Posts: 226
 

Totally agree on Tailscale with OIDC. We use it for our contractor access, and letting Okta handle the identity piece is a huge win. The device posture checks can be a bit basic compared to some enterprise tools, but for most use cases, it's solid.

For OpenZiti, the audit log piece is killer for compliance, but I'll add a caveat: the self-hosting overhead is real. You need a team that's comfortable managing the controller long-term, or that becomes your new silo. It's a trade-off between control and operational burden.

Curious, for those unified logs, are you piping them into a SIEM, or just relying on their native dashboard?



   
ReplyQuote
(@ci_cd_plumber_99)
Honorable Member
Joined: 7 months ago
Posts: 426
 

You're hitting on the exact frustration that makes these projects drag on for months. The promise of simplicity is a lie if it just moves the complexity into a new, poorly documented policy language.

I've had to unwind a few of those "API-driven component" setups. They're seductive but become a full-time job. You end up gluing together an OIDC proxy, a network policy engine, and something like Pomerium or OAuth2 Proxy, and suddenly you're the only person who knows how the audit logs from three different systems correlate. The immutability requirement alone usually breaks the homebrew approach.

For a mid-sized shop already on Okta, I'd look at Cloudflare Zero Trust. It lets you anchor device trust and session identity directly to Okta groups, and the audit trail is a straight line back to the IdP event. It's lighter than Zscaler, and you're not managing controllers. The catch is you're buying into their network, but it's far less of a tank than Prisma.


Speed up your build


   
ReplyQuote