
Modern networks face increasingly complex threats, making traditional defences insufficient. Remote work blurs network boundaries, prompting organisations to adopt secure, intelligent identity verification systems. Relying solely on perimeter security is inadequate against today’s cyber risks. Instead, many implement Zero Trust Architecture (ZTNA), based on “never trust, always verify.” As threats grow more frequent, advanced, and automated, traditional security often falls short. Malware spreads sideways, ransomware targets east-west traffic, and phishing remains a common breach method. The outdated notion that “inside the LAN is safe” is no longer valid, highlighting the need for updated security strategies.
What is DrayTek Identity and Access Management (IAM)?
Identity and Access Management (IAM) is a security framework that controls how users and devices access digital resources. Instead of relying solely on static firewall rules, IAM assesses identity, authentication levels, device characteristics, and contextual information before granting access.
Traditional router firewalls work at the physical or logical network layer, protecting your network by filtering traffic based on static IP addresses, subnets, or MAC addresses. If an unauthorised person managed to breach a VLAN or guess a password, they could often move freely across the entire segment, posing a security risk.
DrayTek IAM shifts the security approach from location-based to identity-based. Built into DrayOS 5 routers such as the Vigor2136, Vigor2767, and Vigor2928 series routers, it provides a comprehensive framework that governs how users access digital resources, determining permitted actions independently of connection location.
DrayOS 5 Routers
IAM elevates the DrayTek router from a basic gateway to a robust Zero Trust enforcement point, allowing administrators detailed control over access permissions, timing, and methods. Instead of relying on IP address controls, network administrators can now manage security through roles and user privileges.

DrayTek IAM enhances security by implementing identity-based access, multi-factor authentication, conditional policies, and micro-segmentation.
Core Components of DrayTek IAM
The DrayTek IAM framework consists of several manageable components designed to comprehensively secure your internal infrastructure. These are:

1. Identity Management (Users & Groups)
Administrators can set up individual profiles with specific credentials (Username/Password) for features such as single sign-on, activity monitoring, and user notifications. In larger organisations, users can be organised into large-scale User Groups to efficiently apply broad permissions.

2. Built-In Multi-Factor Authentication (MFA)
Passwords alone are vulnerable to phishing and brute-force attacks. DrayOS 5 enhances security by supporting multi-factor authentication, including TOTP (Time-Based One-Time Password) through authenticator apps, as well as Email and SMS tokens.

3. Resource Mapping
You can explicitly identify and categorise critical infrastructure in your local network as “Resource Objects.” Resources can be mapped using IP addresses, MAC addresses, specific service ports, or service types. This allows you to securely restrict access to:
- Business operation systems (ERP, CRM, SCM)
- Local workstations or central file servers
- Security arrays like NVR and PBX systems

4. Advanced Access & Conditional Access Policies
Access policies define how users authenticate, such as Guest Hotspot or built-in login options. Conditional Access Policies add an extra verification step, requiring users to fulfil specific conditions to proceed, for example:
- Satisfying an MFA challenge
- Restricting access to precise source IP ranges
- Enforcing a time schedule (e.g. office hours)
- Restricting access to specific VLANs

5. Group Policies & Traffic Governance
After configuring identities and resources, Group Policies unify them. This feature combines traditional firewall filtering, IP and content filters, with traffic-shaping settings. Administrators can specify session durations, dictating how frequently users need to re-authenticate.
IAM Configuration Process
The process of using IAM to secure network resources is outlined in this example, which demonstrates how IAM secures access to an internal server:
- Create IAM User
- Add username/password
- Enable MFA (TOTP)
- Validate token
- Create Access Policy
- Require login
- Enforce MFA
- Apply to LAN segment
- Define Resource
- Example: ACS3 server at 192.168.36.100
- Create Conditional Access Policy
- Require MFA when accessing the resource
- Optional: restrict by IP or schedule
- Create Group Policy
- Apply resource access
- Restrict access to office hours
- Optional: custom firewall rules
- Apply Policies to LAN
- Bind Access + Group Policies to LAN2
Outcome: Privileged users must authenticate with MFA before accessing the internal server, and their access is limited to approved times and conditions.
This is Zero Trust in practice, with identity, context, and resource sensitivity working together.


Why Migrate to a DrayOS 5 IAM Solution?
DrayTek IAM represents a significant shift in network security. Instead of relying on static firewall rules, IAM assesses identity, authentication robustness, device details, and contextual information before granting access.
This aligns well with modern Zero Trust architecture, where each access request requires verification, authorisation, and ongoing monitoring.
For MSPs, SMEs, and security-focused organisations, IAM offers a robust, integrated solution to safeguard essential resources without depending on external identity platforms.
Integrating Identity and Access Management directly into the hardware gateway provides key advantages, including:
Enhanced Security
- Strong MFA enforcement
- Identity-driven access
- Brute-force protection
- Conditional access verification
Better Compliance
- Role-based access control
- User activity tracking
- Resource-specific access logs
Operational Efficiency
- Automated user provisioning
- Reduced help desk load
- Centralised identity management
Improved User Experience
- Single Sign-On (SSO)
- Streamlined authentication
- Managed access across cloud and on-premises applications (on-prem apps)
MSP Advantage
- Scalable group policies
- Easy multi-site configuration
- Stronger security posture for clients
Conclusion
The DrayTek IAM framework in DrayOS 5 represents a big step forward in security for small and medium-sized businesses and managed service providers. It combines identity, authentication, conditional access, and resource-based control, turning the router into a powerful Zero Trust enforcement point. By bringing together identity, authentication, conditional access, and resource control, IAM offers enterprise-level security in a simple, router-integrated solution that’s easy to use.
If you’re deploying new DrayTek Vigor routers or planning a network upgrade, IAM should be a priority on your security checklist. It represents the most substantial security improvement DrayTek has made in years and is a key step toward establishing a fully Zero Trust network.
More Information
Documentation
Identity and Access Management (IAM)
https://www.draytek.com.au/solutions/iam/
Introduction of IAM
https://www.draytek.com/support/knowledge-base/11950







