---
title: "Supported Ecosystem"
slug: "supported-ecosystem"
updated: 2026-06-11T10:55:33Z
published: 2026-06-11T10:55:33Z
canonical: "docs.axiad.com/supported-ecosystem"
---

> ## Documentation Index
> Fetch the complete documentation index at: https://docs.axiad.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Supported Ecosystem

A reference guide to the identity providers, hardware, certificate authorities, operating systems, and infrastructure that integrate with Axiad Conductor SaaS and Axiad Conductor for Airgap.

| **Axiad Conductor SaaS** Axiad's cloud-delivered Credential Management System (CMS) — a SaaS platform for unified credential lifecycle management, MFA orchestration, and certificate-based authentication. | **Axiad Conductor for Airgap** The on-premises edition of the Conductor platform, designed for air-gapped, classified, or regulated environments where a cloud-hosted CMS is not an option. |
| --- | --- |

**How to read this guide**

| **Both** Supported by Axiad Conductor SaaS and Conductor for Airgap | **Airgap only** Supported only by Conductor for Airgap (on-prem) | **Conductor SaaS only** Supported only by Axiad Conductor SaaS (cloud) |
| --- | --- | --- |

## **1. Identity Providers & User Sources**

| Axiad Conductor SaaS and Conductor for Airgap use **SCIM 2.0** for provisioning and **SAML / OIDC** for authentication with external Identity Providers. Standard configurations (included in setup) are Entra ID, Okta, and Ping Identity. Non-standard configurations (such as SailPoint, Active Directory via LDAP, or multiple AD forests) are supported via enablement packages. |
| --- |

| **Vendor** | **Product** | **Axiad Support** | **Availability** |
| --- | --- | --- | --- |
| **Microsoft** | Entra ID (Azure AD) | SCIM 2.0 + SAML / OIDC | **Both** |
| **Microsoft** | Entra ID GCC High | SCIM 2.0 + SAML / OIDC | **Both** |
| **Microsoft** | ADFS | SAML / OIDC federation, all actively supported Windows Server versions | **Both** |
| **Ping Identity** | PingFederate | SCIM 1.1 & 2.0; versions 11.0.1.1 → 12.2.0 | **Both** |
| **Microsoft** | Active Directory (LDAP) | All actively supported Windows Server versions | **Both** |
| **Okta** | Okta (incl. AD Agent) | All actively supported Okta agent versions | **Both** |
| **SailPoint** | SailPoint Identity Security Cloud | SCIM 2.0; non-standard configuration | **Both** |

## **2. Hardware Security Devices**

### **2a. Security Keys & Smart Cards**

| **Vendor** | **Product** | **Axiad Support** | **Availability** |
| --- | --- | --- | --- |
| **Yubico** | YubiKey 5 Series & YubiKey 5 FIPS Series (all models) | Firmware 5.3.x, 5.7.1, 5.7.4 | **Both** |
| **IDEMIA** | ID-One PIV | Versions 8.0, 8.1, 8.2 | **Both** |
| **Thales** | SafeNet IDPrime MD 930 | Current | **Both** |
| **Thales** | SafeNet eToken Fusion NFC PIV (NDA GP keys) | Supported on UCMS 4.22+ | **Both** |
| **Feitian** | BioPass FIDO2 | K26+, K27+, K45+ FIPS | **Both** |
| **Microsoft** | Virtual Smart Card | Same as Windows | **Both** |
| **Multiple** | HOTP / TOTP Hardware Tokens | Any HOTP/TOTP-compliant device with PSKC import (e.g., HID OTP tokens) | **Both** |

### **2b. Hardware Security Modules (HSMs)**

| **Vendor** | **Product** | **Axiad Support** | **Availability** |
| --- | --- | --- | --- |
| **Thales** | SafeNet Luna Network HSM | Commercial: K7 series (A700/750/790, S700/750/790); Government: T-2000 / T-5000; Backup: B700/750/790, T-30B | **Airgap only** |
| **Utimaco** | CryptoServer | Firmware 4.50.0.2 minimum (current: 6.3 / 6.4) | **Airgap only** |

## **3. Certificate Authorities (PKI)**

| **Vendor** | **Product** | **Axiad Support** | **Availability** |
| --- | --- | --- | --- |
| **Microsoft** | Certification Authority (MSCA / ADCS) | All actively supported Windows Server versions | **Both** |
| **IdenTrust** | Public PKI (TrustID, FBCA) | Current cloud version | **Conductor SaaS only** |
| **WidePoint** | Federal SSP PKI (EJBCA-based) | EJBCA Credential Provider, UCMS 4.27+ | **Conductor SaaS only** |
| **Mobile PKI** | iOS Secure Enclave & Android Secure Element | PIV Derived Credential issuance — UCMS 4.27+ | **Conductor SaaS only** |
| **PrimeKey / Keyfactor** | EJBCA | Community 9.3 Enterprise 9.5.1 | **Airgap only** |
| **Entrust** | Entrust CA Gateway | Latest version of Entrust CA Gateway | **Airgap only** |

## **4. Certificate Lifecycle Automation & Orchestration**

| **Vendor** | **Product** | **Axiad Support** | **Availability** |
| --- | --- | --- | --- |
| **AppViewX** | Certificate Lifecycle Automation | Working integration (current) | **Conductor SaaS only** |
| **Venafi** | Machine Identity Management | Working integration (current) | **Conductor SaaS only** |

## **5. MDM / UEM Integrations**

| **Vendor** | **Product** | **Axiad Support** | **Availability** |
| --- | --- | --- | --- |
| **Microsoft** | Intune | SCEP certificate distribution for NHI; Mobile PKI device eligibility (UCMS 4.27+) | **Conductor SaaS only** |
| **Jamf** | Jamf Pro | SCEP integration for macOS; Jamf Connect compatibility documented | **Conductor SaaS only** |

## **6. Operating Systems (Client & Server)**

| Axiad Conductor SaaS and Conductor for Airgap client agents and end-user experiences are supported on the operating system versions listed below. |
| --- |

| **Vendor** | **Product** | **Axiad Support** | **Availability** |
| --- | --- | --- | --- |
| **Microsoft** | Windows 11 Enterprise / Pro | All actively supported (22H2, 23H2, 24H2) | **Both** |
| **Microsoft** | Windows 10 Enterprise / Pro | 22H2 | **Both** |
| **Apple** | macOS | Current: Tahoe (26); Previous: Sequoia (15); Legacy: Sonoma (14) | **Both** |
| **Apple** | iOS | iOS 18 and later | **Both** |
| **Google** | Android | Android 14 and later | **Both** |
| **Microsoft** | Windows Server | All actively supported (2019, 2022, 2025) | **Airgap only** |

## **7. Browsers**

| **Vendor** | **Product** | **Axiad Support** | **Availability** |
| --- | --- | --- | --- |
| **Google** | Chrome | Stable channel | **Both** |
| **Microsoft** | Edge | Stable channel | **Both** |

## **8. Server-Side Infrastructure**

| Customers deploying **Conductor for Airgap** on-premises operate the application stack themselves. The following components and versions are supported. (Axiad Conductor SaaS customers don’t manage this stack — Axiad operates it as part of the cloud service.) |
| --- |

### **8a. Application Server & Runtime**

| **Vendor** | **Product** | **Axiad Support** | **Availability** |
| --- | --- | --- | --- |
| **Apache** | Tomcat | 10.1.45 (UCMS 4.25 – 4.28) | **Both** |
| **Oracle** | Java (Oracle JDK) | Version 17 LTS | **Airgap only** |
| **Red Hat** | OpenJDK | Version 17 LTS | **Airgap only** |

| **Important:** UCMS 4.17 and 4.19 used Tomcat 9 with Java/OpenJDK 11. From UCMS 4.20 onward, Tomcat 10 with OpenJDK 17 is required. |
| --- |

### **8b. Databases**

| **Vendor** | **Product** | **Axiad Support** | **Availability** |
| --- | --- | --- | --- |
| **Open Source** | PostgreSQL | Versions 12 → 17 | **Both** |
| **Microsoft** | SQL Server | 2019, 2022 | **Airgap only** |
| **Oracle** | Oracle Database | 19c | **Airgap only** |
| **Oracle** | MySQL | 5.x (5.7 minimum with strict SQL), 8.x | **Airgap only** |

### **8c. JDBC Drivers**

| **Vendor** | **Product** | **Axiad Support** | **Availability** |
| --- | --- | --- | --- |
| **Open Source** | PostgreSQL JDBC | postgresql-42.7.5.jar (UCMS 4.20+) | **Both** |
| **Microsoft** | MSSQL JDBC | mssql-jdbc-12.8.1.jre11.jar (UCMS 4.20+) | **Airgap only** |
| **Oracle** | Oracle JDBC | ojdbc10.jar 19.25.0.0 (UCMS 4.20+) | **Airgap only** |
| **Oracle** | MySQL Connector/J | mysql-connector-j-9.2.0.jar (UCMS 4.20+) | **Airgap only** |

## **9. Authentication Protocols & Standards**

| The following protocols and authentication standards are supported across **both** Axiad Conductor SaaS and Axiad Conductor for Airgap. |
| --- |

| **Protocol / Standard** | **Description** | **Availability** |
| --- | --- | --- |
| **FIDO2 / WebAuthn** | Passkey enrollment and management with Enterprise Attestation support | **Both** |
| **CBA / PKI** | Certificate-based authentication via smart cards, YubiKeys, and virtual smart cards | **Both** |
| **SAML 2.0** | SSO and federation with IdPs (Entra ID, Okta, Ping, etc.) | **Both** |
| **OAuth 2.0 / OIDC** | SSO and federation | **Both** |
| **SCIM 2.0** | User provisioning and deprovisioning (Entra ID, Okta, Ping, SailPoint) | **Both** |
| **SCEP** | Certificate enrollment for MDM (Intune, Jamf) | **Both** |
| **Syslog** | SIEM integration (Splunk, IBM QRadar, any syslog receiver) | **Both** |
| **RADIUS** | Authentication for VPN, Wi-Fi, and network access (legacy / limited) | **Both** |
| **Windows Hello for Business** | Platform credential management (legacy / limited) | **Both** |
| **OTP (HOTP / TOTP)** | Legacy authentication — sunset planned | **Both** |
| **Push Notification** | Via the Axiad ID mobile app — sunset planned | **Both** |

For Axiad software version support (UCMS / Conductor releases), see

[docs.axiad.com/docs/version-support](https://docs.axiad.com/docs/version-support)

Have questions about an integration not listed here? Contact your Axiad account team or open a request through the Axiad Support Portal.
