See how organisations across regulated industries eliminated credential phishing, simplified MFA rollout, and kept their workforce protected. While eliminating the need for a second device.
Customer Stories
Select a case study to read in full
Pharmaceutical Manufacturing~5,000 UsersGlobal
Read full story →
Aenova Group Secures Its Global Workforce with Passwordless Same-Device MFA
Eliminating Business Email Compromise & Phishing Risks for Microsoft 365 — 3 Years of Proven Protection, Renewed for 5 More.
About Aenova. Aenova Group is a leading global contract manufacturer and development service provider for the pharmaceutical and healthcare industries, with nearly 5,000 employees across manufacturing sites worldwide. In an industry where a single breach can result in contaminated drugs, regulatory sanctions, and risks to patient lives, enterprise-grade security that works for every worker — including shift staff on shared kiosks — is non-negotiable.
AuthN by IDEE delivers exactly what we needed — phishing-proof authentication on any device without the need of an additional device. User adoption is seamless, support tickets are minimal, and the solution has performed flawlessly. That's why we recently signed a five-year renewal.
Elena Zerner-Kaening — Head of IT Infrastructure, Aenova Group
Financial ServicesInstitutional BankingGermany
Read full story →
DekaBank Secures Institutional & Cryptocurrency Transactions with Zero-Trust Ultra
Zero Knowledge. Zero Trust. Zero Compromise — A 5-year partnership securing digital identity for Germany's largest asset manager of the Sparkassen-Finanzgruppe.
About DekaBank. DekaBank is one of Germany's largest securities institutions and the central asset manager of the Sparkassen-Finanzgruppe — Europe's largest financial association. It serves roughly 340 Sparkassen partner banks, whose group employs more than 280,000 people, and manages around €452 billion in assets. To expand its digital offering, DekaBank built Deka Easy Access — an online platform for institutional users, making the security of their digital identities the defining requirement of the entire project.
IDEE GmbH offers a new way of thinking for securing and leveraging digital identities with best-in-class security, privacy and usability. This was instrumental in enabling the digital transformation of the Capital Markets' new products and meeting the stringent regulatory expectations.
Stephan Hachmeister — Managing Director, Capital Markets, DekaBank
Want results like these for your organisation?
Book a 30-minute call — no pressure, just a clear look at what AuthN can do for your team.
Aenova Group Secures Its Global Workforce with Passwordless Same-Device MFA
Eliminating Business Email Compromise & Phishing Risks for Microsoft 365 — 3 Years of Proven Protection, Renewed for 5 More
Aenova Group, a leading global contract manufacturer and development service provider for the pharmaceutical and healthcare industries, has strengthened its security posture with IDEE's AuthN passwordless same-device MFA solution.
In an industry where a single breach can result in contaminated drugs, regulatory sanctions, billions in losses, and even risks to patient lives, Aenova required enterprise-grade protection that was practical for its global workforce — nearly 5,000 users who rely primarily on their PCs without company-issued smartphones or hardware tokens for MFA.
The Challenge: Rising Phishing Threats Demand Immediate, Practical MFA
Aenova had suffered multiple phishing attempts targeting Microsoft 365 credentials. With cyber insurance requirements tightening, NIS2 designating the healthcare and pharmaceutical sectors as critical infrastructure requiring robust cybersecurity measures, and the pharmaceutical sector facing heightened attacks, deploying strong MFA across its nearly 5,000 users became urgent.
Traditional MFA solutions were ruled out because they demanded second devices (phones, USB keys, or cards) — impractical for a global organization where most employees work exclusively on PCs. Moreover, typical deployments require extensive time, dedicated security staff, and significant change management — resources Aenova did not want to expend.
"We couldn't rely on employees using personal devices for authentication — especially in production environments — and we didn't want the logistics of distributing USB keys. AuthN by IDEE solved both problems elegantly."
— Joel Knecht, Team Lead IT Cloud Services, Aenova Group
Existing Microsoft Tools Were Not Enough
Although Aenova already had Conditional Access enabled and Microsoft Authenticator included in its Microsoft 365 licensing tier, these native capabilities fell short of the organization's security requirements for three key reasons:
Phishing resistant vs. phishing proof: Microsoft Authenticator provides phishing resistance, but not true phishing-proof protection — a critical distinction when safeguarding high-stakes pharmaceutical operations and intellectual property.
Second device requirement: Setting up a new device or registering for the 1st time on M365 requires a second device, which is not practical given not all employees have a company device and not all employees are willing to use their private devices for work.
BYOD limitations: With widespread Bring Your Own Device (BYOD) usage, phishable factors such as push notifications and one-time passwords (OTPs) can not be fully eliminated, leaving phishing attacks a daily risk.
The Solution: AuthN by IDEE — Same-Device MFA Deployed in Record Time
Ease of deployment was a key deciding factor. After evaluating several MFA solutions, Aenova selected AuthN by IDEE for its true phishing-proof protection and native support for shared kiosk environments without requiring additional hardware or personal devices.
The solution did not require additional software installation or changes to Aenova's existing IT infrastructure, and it does not store personally identifiable information (PII).
The rollout to nearly 5,000 users was completed within a short timeframe, with relatively low effort from IT and minimal training required. Users authenticate by unlocking their device.
Six Week Deployment Across All Knowledge Workers
3 WEEKS
All knowledge workers were asked to register their devices.
15 MINUTES
It took just 15 minutes to federate (integrate) the various domains.
SECONDS
It took just a few seconds for each user to register their device(s).
3 WEEKS
Monitoring to ensure all use cases were covered with active support from IDEE.
Kiosk & Shared Workstation Support: MFA for Multi-User Environments
Aenova's manufacturing and production environments rely heavily on shared kiosk PCs and shift-based workstations. Supporting these scenarios securely was a key requirement. AuthN by IDEE enables secure authentication on shared devices without requiring users to carry a second device such as a smartphone or hardware token. This allows every login—whether on a personal PC or shared workstation—to be protected while maintaining operational efficiency for factory floor staff and rotating shifts.
AuthN by IDEE turns any device into a phishing-resistant authenticator using the device's TPM chip and biometrics/PIN.
About the Solution
AuthN by IDEE provides a streamlined authentication experience while removing reliance on passwords. By leveraging device-based security, it helps protect against common attack vectors such as credential phishing, password spraying, and business email compromise.
Users authenticate simply by unlocking their device — no codes, no apps, no friction.
How it works.
User unlocks their device to register for the first time.
Device's cryptographic private key is bound to the user identity & web app/app.
1. Register any device once (in just a few seconds).
Device is now an authenticator.
2. User unlocks device to login with MFA.
The Results: 3 Years of Strong Protection & a 5-Year Renewal
Deployed May 1, 2023 — Now entering its fourth year with a new 5-year renewal signed in 2026.
Since going live in May 2023, Aenova has not experienced a successful password-based, credential phishing, or MFA bypass attack affecting its Microsoft 365 environment.
Key Outcomes
Eliminated BEC & Phishing Risk: No successful password-based, credential phishing, or MFA bypass attacks on M365 infrastructure have been recorded since deployment.
Manufacturing Kiosk Support: Extended full phishing-proof MFA protection to more than 100 shared production kiosks and multi-user devices protecting more than 1,000 shift-based and temporary workers without requiring personal hardware tokens or creating security workarounds.
Frictionless Adoption: Users quickly adapted to the experience - authenticating by unlocking their device (personal or shared kiosk) to login.
Operational Efficiency: 70%+ reduction in password/MFA-related helpdesk tickets since deployment (per internal IT metrics), eliminated hardware token logistics, and freed IT teams to focus on strategic projects and patch management.
Regulatory & Insurance Compliance: Met and exceeded cyber insurance MFA mandates while supporting strict pharmaceutical industry security and data protection requirements for NIS2, KRITIS requirements (BSI), GDPR, and DORA. It delivers phishing-proof authentication that aligns with BSI recommendations for critical infrastructure operators and exceeds traditional MFA approaches still accepted under many existing frameworks.
"When I joined Aenova last year, one of the first things that stood out was how solid our MFA posture already was. We had evaluated Microsoft's native tools, but they fell short on true phishing-proof protection and struggled with our extensive shared kiosk environment and BYOD workforce.
AuthN by IDEE delivers exactly what we needed — phishing-proof authentication on any device without the need of an additional device such as a smartphone or Yubikey. User adoption is seamless, support tickets are minimal, and the solution has performed flawlessly. That's why we recently signed a five-year renewal. It's been a standout security investment."
Elena Zerner-Kaening — Head of IT Infrastructure, Aenova Group
Aenova Group has proven that enterprise-grade, phishing-proof security doesn't have to come at the cost of operational complexity. By deploying AuthN by IDEE, they protected nearly 5,000 users — including over 1,000 shift workers on shared kiosks — achieving zero successful attacks over three years, a significant reduction in helpdesk burden, and full regulatory alignment under NIS2 and KRITIS. The result is a scalable, user-friendly MFA solution that earned a five-year renewal and is now setting a new standard for secure authentication in pharmaceutical manufacturing.
Want results like Aenova's?
Book a short call — we'll show you exactly how it works for your environment.
Securing Institutional and Cryptocurrency Transactions on Deka Easy Access with Zero-Trust Ultra
~340
Sparkassen partner banks
280,000+
employees across the Sparkassen-Finanzgruppe
€452 Bn
assets managed for Sparkassen & their customers
About the Customer
DekaBank — Frankfurt, Germany
DekaBank is one of Germany's largest securities institutions and the central asset manager of the Sparkassen-Finanzgruppe — the savings-bank network that is the largest financial association in Europe. It serves roughly 340 Sparkassen partner banks, whose group employs more than 280,000 people, and manages around €452 billion in assets for those banks and their customers.
To open new business for itself and the Sparkassen it serves, DekaBank built Deka Easy Access — a digital product that lets institutional users transact online, on the web and in-app. The users of that platform are the employees of DekaBank and of the Sparkassen it serves, which made the security and privacy of their digital identities the defining requirement of the entire project.
The Challenge
Security That Could Not Be Compromised
High-value institutional transactions and strict financial-services regulation meant DekaBank could accept no weak link in identity. Passwords and app- or token-based MFA carry well-documented vulnerabilities, and every conventional alternative introduced the same fundamental problem: a central credential database is a target, and a party you have to trust.
Any solution storing credentials centrally could neither guarantee the privacy of end users nor rule out insider threats — whether at DekaBank or at a vendor. For a platform authenticating institutional and, later, cryptocurrency transactions, that residual trust was itself an unacceptable risk. DekaBank did not need a faster way to deploy authentication. It needed authentication that removed trust from the equation entirely.
Why DekaBank Chose IDEE
Two Pillars of Uncompromising Security
01
Zero Knowledge, Zero PII
AuthN by IDEE is fully decentralized and zero-knowledge. IDEE holds no central credential database and no personally identifiable information about the end users of Deka Easy Access. There is nothing for an attacker or an insider to steal, because IDEE never has it in the first place.
02
Zero-Trust Ultra
IDEE goes beyond conventional zero-trust. With Zero-Trust Ultra, DekaBank does not need to trust IDEE itself. The bank's security posture never depends on a third party behaving correctly because the architecture guarantees it, removing the vendor as a point of failure.
Regulatory Milestone
It was precisely this Zero-Trust Ultra design that convinced Germany's Federal Financial Supervisory Authority. BaFin granted the special permission required for IDEE to run AuthN on AWS infrastructure in Frankfurt. This approval reflects confidence in the IDEE architecture because a regulated bank's security no longer needs to trust its authentication provider.
The Solution
What AuthN Delivered
Zero-Trust Ultra
Zero-Trust Ultra satisfied DekaBank's internal and external security assessments, earning particular praise for insider-threat protection on both IDEE's side and DekaBank's.
No Credentials to Breach
Fully decentralized and zero-knowledge: no central store of credentials or PII, satisfying DekaBank's privacy requirements in full.
Enterprise Compliance
APIs for users, devices and logging via a GUI dashboard. Built on AWS, always SaaS, with ISO 27001 and SOC II certification and AWS Financial Services audit rights under European law.
Privacy & EU Sovereignty
Because AuthN is zero-knowledge, no personally identifiable information about end users ever resides on AWS — or anywhere else. There is no personal data to expose, transfer or place under foreign jurisdiction, keeping data sovereignty firmly in DekaBank's hands.
IDEE GmbH offers a new way of thinking for securing and leveraging digital identities with best-in-class security, privacy and usability.
This was instrumental in enabling the digital transformation of the Capital Markets' new products and meeting the stringent regulatory expectations. We are looking forward to our continued partnership to leverage IDEE's extendable solution within DEKA.
Stephan HachmeisterManaging Director, Capital Markets · DekaBank
The Partnership
Five Years of Deepening Trust
Year 1
Deka Easy Access goes live
IDEE integrates AuthN with DekaBank's core open-source IAM, securing institutional portfolio and asset transactions with zero-knowledge, Zero-Trust Ultra authentication.
Year 5 — Today
Cryptocurrency transaction authorization
DekaBank adds authorization of cryptocurrency transactions to Deka Easy Access. IDEE built the app and serves as its security architect, applying the same trust-free authentication model to one of the highest-stakes transaction types a bank can offer.
“
AuthN is an essential part of our security concept for safeguarding the will of the customer in our crypto business.
Sascha Bach · IT Manager, DekaBank
When the Best Security Is Needed, Banks Turn to IDEE
Five years and expanding — now to cryptocurrency authorization — DekaBank's partnership with IDEE shows what becomes possible when zero-knowledge architecture and Zero-Trust Ultra remove the trade-off between security, privacy and trust. Where authentication failure is not an option, IDEE is the standard.
Want results like DekaBank's?
Book a short call — we'll show you exactly how it works for your environment.