WALLIX Trustelem
WALLIX Trustelem: European IDaaS. Single Sign-On, Multi-Factor Authentication, Identity Federation. GDPR-compliant identity management.

Key Features
- Single Sign-On (SSO) for SaaS and on-prem apps
- Multi-Factor Authentication (MFA)
- Identity Federation (SAML, OIDC)
- Self-service password reset
- Directory synchronization (AD/LDAP)
Table of Contents
What is WALLIX Trustelem?
WALLIX Trustelem is a European Identity-as-a-Service (IDaaS) platform - Single Sign-On, Multi-Factor Authentication, and Identity Federation in the cloud. European vendor with data in EU = GDPR compliance.
Main functions:
- SSO - single login to all applications
- MFA - multi-factor authentication
- Identity Federation - SAML 2.0, OpenID Connect
- Directory Sync - synchronization with AD/LDAP
What Problem Does It Solve?
flowchart LR
subgraph Without SSO
A[User] --> B[Password 1 - Email]
A --> C[Password 2 - CRM]
A --> D[Password 3 - ERP]
A --> E[Password 4 - HR]
B --> F[Password fatigue]
F --> G[Weak passwords / post-it]
end
subgraph With Trustelem
H[User] --> I[SSO + MFA]
I --> J[Email]
I --> K[CRM]
I --> L[ERP]
I --> M[HR]
end
style A fill:#6366f1,stroke:#4f46e5,color:#fff
style F fill:#dc2626,stroke:#b91c1c,color:#fff
style G fill:#dc2626,stroke:#b91c1c,color:#fff
style H fill:#6366f1,stroke:#4f46e5,color:#fff
style I fill:#22c55e,stroke:#16a34a,color:#fff
Common problems:
- Users have dozens of passwords
- Password fatigue = weak passwords or post-it notes
- No MFA for SaaS applications
- Each application = separate user management
- US-based IDaaS vs European regulations (GDPR)
How Does Trustelem Work?
flowchart TD
A[User] --> B[Trustelem Portal]
B --> C[Authentication]
C --> D[Username/Password]
C --> E[MFA - TOTP/Push/SMS]
C --> F[Passwordless - FIDO2]
B --> G[SSO Federation]
G --> H[SAML 2.0 Apps]
G --> I[OIDC Apps]
G --> J[On-prem Apps]
K[Active Directory] --> L[Directory Sync]
L --> B
style A fill:#6366f1,stroke:#4f46e5,color:#fff
style B fill:#f59e0b,stroke:#d97706,color:#fff
style C fill:#8b5cf6,stroke:#7c3aed,color:#fff
style G fill:#22c55e,stroke:#16a34a,color:#fff
Key Features
Single Sign-On
Single login
- User portal
- SAML 2.0 federation
- OpenID Connect
- 1000+ pre-built connectors
Multi-Factor Auth
MFA
- TOTP (Google Authenticator)
- Push notifications
- SMS/Email OTP
- FIDO2/WebAuthn
Directory Sync
AD integration
- Active Directory sync
- LDAP directories
- Azure AD connector
- Real-time provisioning
Self-Service
User empowerment
- Password reset
- Profile management
- MFA enrollment
- App requests
Access Policies
Conditional access
- IP-based rules
- Device trust
- Time-based access
- Risk-based MFA
European Hosting
GDPR compliance
- Data hosted in EU
- French company
- GDPR by design
- No US data transfers
Supported Applications
| Category | Examples |
|---|---|
| Microsoft | Office 365, Azure, Dynamics |
| Workspace, Cloud Platform | |
| Salesforce | Sales Cloud, Service Cloud |
| HR | Workday, SAP SuccessFactors |
| Collaboration | Slack, Zoom, Teams |
| Dev tools | GitHub, GitLab, Jira, Confluence |
| Custom apps | SAML 2.0, OIDC |
Who Is It For?
WALLIX Trustelem MAKES sense when:
- • You use many SaaS applications
- • You need MFA for users
- • GDPR compliance is a requirement
- • You want European IDaaS (data in EU)
- • Integration with WALLIX Bastion (PAM)
Trustelem DOESN'T make sense when:
- • You already have Azure AD Premium with SSO/MFA
- • Only Microsoft ecosystem (M365 is enough)
- • Small company with few applications
Trustelem vs Competition
| Aspect | WALLIX Trustelem | Okta | Azure AD |
|---|---|---|---|
| Origin | Europe (France) | USA | USA |
| Data residency | EU only | Global (US primary) | Global |
| GDPR native | Yes | Requires configuration | Depends on tenant |
| PAM integration | Native (Bastion) | Via SCIM | Via SCIM |
| Pricing | Per-user, competitive | Per-user, premium | Part of M365 |
| App catalog | 1000+ | 7000+ | 3000+ |
WALLIX Trustelem advantages:
- European vendor = data never leaves EU
- Native integration with WALLIX Bastion (PAM + IAM in one)
- Simpler deployment for mid-market
- Competitive pricing vs Okta
Specifications
| Parameter | Value |
|---|---|
| Deployment | SaaS (European cloud) |
| Protocols | SAML 2.0, OpenID Connect, OAuth 2.0 |
| MFA methods | TOTP, Push, SMS, FIDO2 |
| Directory | AD, LDAP, Azure AD, Google Directory |
| API | REST API for provisioning |
| SLA | 99.9% uptime |
FAQ
How does it differ from Azure AD? Azure AD is part of Microsoft ecosystem. Trustelem is independent European IDaaS. For organizations with multi-vendor environment or GDPR requirements - Trustelem may be a better choice.
Can I use it with WALLIX Bastion? Yes. Trustelem + Bastion = complete IAM + PAM solution. Users log in through Trustelem SSO, admins additionally through Bastion with session recording.
What MFA methods are available? TOTP (authenticator app), Push notifications, SMS, Email OTP, FIDO2/WebAuthn (passwordless).
How many apps are in the catalog? 1000+ pre-built connectors. For apps without connector - custom SAML/OIDC setup possible.
Does nFlo deploy Trustelem? Yes. SSO deployments, MFA configuration, AD integration, SaaS app onboarding. Often combined with WALLIX Bastion.
Inquire about WALLIX Trustelem
Contact your product specialist and get a custom quote.

Related Services
Our services supporting the implementation and management of this solution
Active Directory Security Audit
Cybersecurity
We find paths to Domain Admin before attackers do.
CIS Security Audit
Cybersecurity
Harden system configurations with CIS Benchmarks. Block 85% of common attacks.
Cloud Security Audit and Protection
Cybersecurity
Check AWS/Azure/GCP security before attackers find misconfigurations. CSPM + manual review.
Web Application Penetration Testing
Cybersecurity
One SQL injection = access to entire database. Find vulnerabilities before hackers do.
From Our Knowledge Base
Articles related to this solution
Blocking the Device Code Flow in Microsoft Entra ID with Conditional Access
How to reduce the risk of Device Code Phishing? A practical guide to blocking the Device Code Flow in Microsoft Entra ID with Conditional Access — step by step, with pitfalls and validation.
Cyber threat landscape 2026: a report for Polish companies in the NIS2 era
Poland is the most digitally attacked EU country. Explore the 2026 cyber threat landscape in numbers, the three most dangerous attack vectors and the NIS2/KSC obligations for Polish companies.
Deepfake, vishing and CEO fraud: how to protect your company from AI-powered scams
A deepfake on a video call, voice cloning and AI-powered CEO fraud mean real losses in the millions. Learn how these scams work and the proven defenses, including second-channel verification.
Related Products
Other solutions you might be interested in
Aruba ClearPass
Aruba Networks
Aruba ClearPass: NAC platform with profiling of 70+ thousand device types. Zero Trust access control for users, BYOD, and IoT.
Barracuda CloudGen Firewall
Barracuda Networks
Barracuda CloudGen Firewall: next-gen firewall with SD-WAN. IPS, application control, VPN, threat protection. Appliance, virtual, cloud.
Barracuda Email Protection
Barracuda Networks
Barracuda Email Protection: AI-powered email security against phishing, ransomware, BEC and account takeover. Gateway + API for Microsoft 365 and Google.
Barracuda SecureEdge
Barracuda Networks
Barracuda SecureEdge: SASE platform combining SD-WAN with cloud security. Zero Trust, SWG, CASB, FWaaS. Protection for distributed workforce.
Want to Reduce IT Risk and Costs?
Book a free consultation - we respond within 24h
Or download free guide:
Download NIS2 Checklist